Repository navigation
feat: add pagerduty-webhooks skill - #210
Merged
Merged
Conversation
Adds the README row, providers.yaml entry (the research brief, verbatim)
and marketplace.json registration the generator staged but never wrote,
so validate-provider.sh passes.
Also softens six places that called the pagey.ping test delivery
"signed". POST /webhook_subscriptions/{id}/ping and the pagey.ping event
are both confirmed against PagerDuty's own OpenAPI schema, but neither
the docs nor the schema say the ping carries X-PagerDuty-Signature, so
the skill no longer asserts it.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a
pagerduty-webhooksskill for PagerDuty V3 webhook subscriptions — SKILL.md, three reference docs, and working Express / Next.js / FastAPI receivers with tests.Scheme (and the two things a reviewer will want to check)
HMAC-SHA256 over the raw body, lowercase hex, in
X-PagerDuty-Signature.v1=-prefixed, for zero-downtime secret rotation. All three examples accept a match against anyv1=entry and ignore unknown-version entries rather than failing. Comparing the whole header string, or only the first entry, works right up until someone rotates the secret.X-Webhook-Idheader. An added tolerance check here would be a bug, not a hardening.Also: no handshake (the secret comes back in the create-subscription API response); 400 for a malformed header or empty body vs 403 for a mismatch, mirroring PagerDuty's Go client — both 4xx, which PagerDuty treats as permanent, so a forged request is never retried; fail-closed when the secret is unset.
Sources: the Verifying Signatures pseudo-algorithm and
go-pagerduty/webhookv3/webhookv3.go, which is the only official verifier (neither@pagerduty/pdjsnorpdpyrasships one).Identity
V3 subscriptions only. Not V1 extensions (EOL Oct 2022), not V2 extensions (end-of-support Oct 2022,
messages[]payload, different event names likeincident.trigger), and not the Events API v1/v2, which is inbound to PagerDuty. Hookdeck'ssourceTypeSchemas.tshas noPAGERDUTYsource type yet, so the variant was resolved from the docs rather than from Hookdeck's own source config.All 30 event types come from the docs' Event Types table with their
data.typevalues, including the naming traps:incident.service_updated(underscore) vsservice.updated,incident.role.assignedcovering unassignment,incident.annotatedrather thanincident.note.created. Every framework has a default branch — PagerDuty says more types may be added and also ships undocumented Early Access events.Hedged on purpose
POST /webhook_subscriptions/{id}/pingand thepagey.pingevent it delivers are confirmed verbatim against PagerDuty's OpenAPI schema (operationId: testWebhookSubscription), and the same schema confirms there is no customer-facing secret-rotate endpoint. But nothing documents whether the ping carriesX-PagerDuty-Signature, so the skill says so instead of asserting it.pagey.pingis not subscribable, so it lands in the default branch.Source IPs are the published per-region safelists, with the advice to fetch the JSON at runtime rather than hardcode — defence in depth, not verification.
Testing
validate-provider.sh pagerduty-webhooks— PASSEDNo live PagerDuty account was available, so the digest has not been checked against a real delivery.
🤖 Generated with Claude Code