diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index d536b9e..bdc0806 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -3,30 +3,30 @@ # Docs: https://gh.io/actions-lockfile version: 'v0.0.2' workflows: - '.github/workflows/governance.yml': [] - '.github/workflows/label-triage.yml': [] - '.github/workflows/labels.yml': [] - '.github/workflows/mirror.yml': [] - '.github/workflows/scorecard.yml': [] - '.github/workflows/secret-scanner.yml': [] '.github/workflows/agda.yml': - 'actions/cache@v6.1.0' - 'actions/checkout@v7.0.1' '.github/workflows/codeql.yml': - 'actions/checkout@v7.0.1' - - 'github/codeql-action@v4.37.7' + - 'github/codeql-action@v4.37.9' + '.github/workflows/governance.yml': [] '.github/workflows/hypatia-scan.yml': - 'actions/checkout@v7.0.1' - 'actions/github-script@v9.0.0' - 'actions/upload-artifact@v7.0.1' - 'erlef/setup-beam@v1.24.1' - - 'github/codeql-action@v4.37.7' + - 'github/codeql-action@v4.37.9' + '.github/workflows/label-triage.yml': [] + '.github/workflows/labels.yml': [] + '.github/workflows/mirror.yml': [] '.github/workflows/pages.yml': - 'actions/checkout@v7.0.1' - 'actions/deploy-pages@v5.0.0' - 'actions/upload-pages-artifact@v5.0.0' '.github/workflows/push-email-notify.yml': - - 'dawidd6/action-send-mail@v3.12.0' + - 'hyperpolymath/smtp-notify-action@v0.1.0' + '.github/workflows/scorecard.yml': [] + '.github/workflows/secret-scanner.yml': [] dependencies: 'actions/cache@v6.1.0': ref: 'v6.1.0' @@ -65,18 +65,18 @@ dependencies: repo_id: 496012378 uses: - 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f' - 'dawidd6/action-send-mail@v3.12.0': - ref: 'v3.12.0' - commit: 'sha1-94de994a9f6fffee200243214e17002e2920bb59' - owner_id: 9713907 - repo_id: 222439721 'erlef/setup-beam@v1.24.1': ref: 'v1.24.1' commit: 'sha1-54075bcc5e249e4758d363f27d099f55d843f124' owner_id: 47606891 repo_id: 331103973 - 'github/codeql-action@v4.37.7': - ref: 'v4.37.7' - commit: 'sha1-ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd' + 'github/codeql-action@v4.37.9': + ref: 'v4.37.9' + commit: 'sha1-cdf488f595d80d6e07e03d4674febd5ab45fa938' owner_id: 9919 repo_id: 259445878 + 'hyperpolymath/smtp-notify-action@v0.1.0': + ref: 'v0.1.0' + commit: 'sha1-1b3b752d39a4fe4c0f28f10905e4608789d3e050' + owner_id: 6759885 + repo_id: 1352485172 diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml index 4ee4d49..ece395b 100644 --- a/.github/workflows/push-email-notify.yml +++ b/.github/workflows/push-email-notify.yml @@ -1,13 +1,19 @@ # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. -# This workflow is managed by gh actions-lock. # Dormant push-email notification. ARMED by setting the repo variable # PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled; # sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by # new repos from the template; placed on existing repos by the farm sweep. +# +# Re-landed after the 2026-07-20 notification-storm freeze (removed in +# 09f94c5), now on hyperpolymath/smtp-notify-action: Node-free, the SMTP +# session is Idris2-specified and machine-checked, the binary is Zig-built, +# byte-reproducible, and SHA-256-pinned inside the action itself. name: Push email notification on: - push: {} + push: + # Branch pushes only: tag and deletion payloads mislabel Branch:/head_commit. + branches: ['**'] permissions: contents: read jobs: @@ -15,9 +21,10 @@ jobs: name: Email on push if: ${{ vars.PUSH_EMAIL_ENABLED == 'true' }} runs-on: ubuntu-latest + timeout-minutes: 5 steps: - name: Send push notification email - uses: dawidd6/action-send-mail@v18 + uses: hyperpolymath/smtp-notify-action@v0.1.0 # NOSONAR — pin authority is actions.lock (sha1-1b3b752d39a4fe4c0f28f10905e4608789d3e050) with: server_address: ${{ secrets.SMTP_HOST }} server_port: ${{ secrets.SMTP_PORT }}