Skip to content

Commit 2b7202d

Browse files
chore(ci): repoint push-email-notify to smtp-notify-action (#192)
Replaces `dawidd6/action-send-mail` with `hyperpolymath/smtp-notify-action` v0.2.0 (tag commit `ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7`), per the 2026-09-02 ruling (standards spec §5.5/§9, PR hyperpolymath/standards#725). The whole file is replaced with the `rsr-template-repo` canonical, which — besides the `uses:` line — restricts the trigger to branch pushes (tag and deletion payloads mislabel `Branch:`/`head_commit`), sets `timeout-minutes: 5`, carries a deliberately per-run `concurrency` group, and grants only `contents: read`. **How many of those are actual changes here depends on how far this repo's copy had drifted — read the diff, not this list.** Dormant gating on `vars.PUSH_EMAIL_ENABLED == 'true'` is unchanged. Line 1 SPDX header kept as it was. Engine: `.git-private-farm/scripts/smtp-notify-sweep.sh`. Verification for this repo: `regime=lock pristine=valid post=valid changed=.github/workflows/actions.lock,.github/workflows/push-email-notify.yml, sig=G 4a107ec canon=543fc1474b54 base=main` (`pristine`/`post` = `gh actions-lock --no-fix` validity before/after; `repair` = the lock was already invalid before this change and is valid after it.) 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
1 parent 3634182 commit 2b7202d

2 files changed

Lines changed: 40 additions & 17 deletions

File tree

‎.github/workflows/actions.lock‎

Lines changed: 14 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,6 @@
33
# Docs: https://gh.io/actions-lockfile
44
version: 'v0.0.2'
55
workflows:
6-
'.github/workflows/governance.yml': []
7-
'.github/workflows/hypatia-scan.yml': []
8-
'.github/workflows/label-triage.yml': []
9-
'.github/workflows/labels.yml': []
10-
'.github/workflows/mirror.yml': []
11-
'.github/workflows/rust-ci.yml': []
12-
'.github/workflows/scorecard.yml': []
13-
'.github/workflows/secret-scanner.yml': []
146
'.github/workflows/boj-build.yml':
157
- 'actions/checkout@v4.1.7'
168
'.github/workflows/bridge-gate.yml':
@@ -48,25 +40,33 @@ workflows:
4840
- 'actions/upload-artifact@v4.6.2'
4941
- 'dtolnay/rust-toolchain@v1'
5042
- 'swatinem/rust-cache@v2.8.2'
43+
'.github/workflows/governance.yml': []
44+
'.github/workflows/hypatia-scan.yml': []
5145
'.github/workflows/instant-sync.yml':
5246
- 'peter-evans/repository-dispatch@v4.0.1'
47+
'.github/workflows/label-triage.yml': []
48+
'.github/workflows/labels.yml': []
49+
'.github/workflows/mirror.yml': []
5350
'.github/workflows/pages.yml':
5451
- 'actions/checkout@v4.4.0'
5552
- 'actions/deploy-pages@v4.0.5'
5653
- 'actions/upload-pages-artifact@v3.0.1'
5754
'.github/workflows/push-email-notify.yml':
58-
- 'dawidd6/action-send-mail@v3.12.0'
55+
- 'hyperpolymath/smtp-notify-action@v0.2.0'
5956
'.github/workflows/release.yml':
6057
- 'actions/checkout@v5.0.1'
6158
- 'actions/download-artifact@v4.1.8'
6259
- 'actions/upload-artifact@v4.6.2'
6360
- 'dtolnay/rust-toolchain@v1'
6461
- 'softprops/action-gh-release@v2.5.0'
6562
- 'swatinem/rust-cache@v2.8.2'
63+
'.github/workflows/rust-ci.yml': []
6664
'.github/workflows/scan-and-report.yml':
6765
- 'actions/checkout@v4.3.1'
6866
- 'dtolnay/rust-toolchain@v1'
6967
- 'swatinem/rust-cache@v2.8.2'
68+
'.github/workflows/scorecard.yml': []
69+
'.github/workflows/secret-scanner.yml': []
7070
dependencies:
7171
'actions/cache@v4.3.0':
7272
ref: 'v4.3.0'
@@ -152,11 +152,6 @@ dependencies:
152152
repo_id: 200299178
153153
uses:
154154
- 'actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea'
155-
'dawidd6/action-send-mail@v3.12.0':
156-
ref: 'v3.12.0'
157-
commit: 'sha1-6e502825a508b867ab2954ad6343b68787624c01'
158-
owner_id: 9713907
159-
repo_id: 222439721
160155
'dtolnay/rust-toolchain@v1':
161156
ref: 'v1'
162157
commit: 'sha1-6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772'
@@ -172,6 +167,11 @@ dependencies:
172167
commit: 'sha1-ec49483bfc012387b227434aba94f59a6ecd0900'
173168
owner_id: 75048950
174169
repo_id: 623796603
170+
'hyperpolymath/smtp-notify-action@v0.2.0':
171+
ref: 'v0.2.0'
172+
commit: 'sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7'
173+
owner_id: 6759885
174+
repo_id: 1352485172
175175
'peter-evans/repository-dispatch@v4.0.1':
176176
ref: 'v4.0.1'
177177
commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697'

‎.github/workflows/push-email-notify.yml‎

Lines changed: 26 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,23 +1,46 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3-
# This workflow is managed by gh actions-lock.
43
# Dormant push-email notification. ARMED by setting the repo variable
54
# PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled;
65
# sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by
76
# new repos from the template; placed on existing repos by the farm sweep.
7+
#
8+
# Re-landed after the 2026-07-20 notification-storm freeze (removed in
9+
# 09f94c5), now on hyperpolymath/smtp-notify-action: Node-free, the SMTP
10+
# session is Idris2-specified and machine-checked, the binary is Zig-built,
11+
# byte-reproducible, and SHA-256-pinned inside the action itself.
812
name: Push email notification
913
on:
10-
push: {}
14+
push:
15+
# Branch pushes only: tag and deletion payloads mislabel Branch:/head_commit.
16+
branches: ['**']
17+
concurrency:
18+
# Deliberately per-RUN, so no run is ever queued behind another and none is
19+
# ever cancelled. Do NOT "tidy" this into a shared group such as
20+
# ${{ github.workflow }}-${{ github.ref }}. GitHub's workflow-syntax docs:
21+
# "By default, any existing pending job or workflow in the same concurrency
22+
# group will be canceled and the new queued job or workflow will take its
23+
# place." That happens regardless of cancel-in-progress, which governs only
24+
# the RUNNING job. On this workflow it silently loses a notification email,
25+
# with no error anywhere. Every run here reports a DISTINCT commit, so there
26+
# is no redundant work for a concurrency limit to remove.
27+
# The docs also offer `queue: max` (up to 100 pending); not used, because 100
28+
# is still a cap whereas a per-run group needs none.
29+
# Verified with zizmor 1.30.0: deleting this block raises concurrency-limits;
30+
# this form silences it exactly as a shared group would.
31+
group: push-email-${{ github.run_id }}
32+
cancel-in-progress: false
1133
permissions:
1234
contents: read
1335
jobs:
1436
notify:
1537
name: Email on push
1638
if: ${{ vars.PUSH_EMAIL_ENABLED == 'true' }}
1739
runs-on: ubuntu-latest
40+
timeout-minutes: 5
1841
steps:
1942
- name: Send push notification email
20-
uses: dawidd6/action-send-mail@v3.12.0
43+
uses: hyperpolymath/smtp-notify-action@v0.2.0 # NOSONAR — pin authority is actions.lock (sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7)
2144
with:
2245
server_address: ${{ secrets.SMTP_HOST }}
2346
server_port: ${{ secrets.SMTP_PORT }}

0 commit comments

Comments
 (0)