From 4b2c1e78b5d4ea88565936e7867925a4411de81e Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 2 Sep 2026 18:47:04 +0100 Subject: [PATCH 1/2] chore(ci): repoint push-email-notify to smtp-notify-action Replaces dawidd6/action-send-mail with hyperpolymath/smtp-notify-action v0.1.0 (1b3b752d39a4fe4c0f28f10905e4608789d3e050) per the 2026-09-02 ruling; file is the rsr-template-repo canonical (dormant gating on vars.PUSH_EMAIL_ENABLED unchanged). regime=lock pristine=valid post=valid changed=.github/workflows/actions.lock,.github/workflows/push-email-notify.yml, Co-Authored-By: Claude Fable 5.1 --- .github/workflows/actions.lock | 26 ++++++++++++------------- .github/workflows/push-email-notify.yml | 14 +++++++++---- 2 files changed, 23 insertions(+), 17 deletions(-) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index d351879f..7d688abd 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -3,13 +3,6 @@ # Docs: https://gh.io/actions-lockfile version: 'v0.0.2' workflows: - '.github/workflows/governance.yml': [] - '.github/workflows/label-triage.yml': [] - '.github/workflows/labels.yml': [] - '.github/workflows/mirror.yml': [] - '.github/workflows/readme-derive.yml': [] - '.github/workflows/scorecard.yml': [] - '.github/workflows/secret-scanner.yml': [] '.github/workflows/abi-drift.yml': - 'actions/cache@v4.2.2' - 'actions/checkout@v6.0.2' @@ -41,6 +34,7 @@ workflows: '.github/workflows/fuzz.yml': - 'actions/checkout@v6.0.2' - 'mlugg/setup-zig@v2.2.1' + '.github/workflows/governance.yml': [] '.github/workflows/hcg-surface-drift.yml': - 'actions/checkout@v6.0.2' '.github/workflows/hypatia-scan.yml': @@ -51,9 +45,12 @@ workflows: - 'github/codeql-action@v4.32.6' '.github/workflows/instant-sync.yml': - 'peter-evans/repository-dispatch@v3.0.0' + '.github/workflows/label-triage.yml': [] + '.github/workflows/labels.yml': [] '.github/workflows/lsp-dap-bsp.yml': - 'actions/checkout@v6.0.2' - 'mlugg/setup-zig@v2.2.1' + '.github/workflows/mirror.yml': [] '.github/workflows/pages-deploy.yml': - 'actions/checkout@v4.4.0' '.github/workflows/pages.yml': @@ -68,13 +65,16 @@ workflows: - 'actions/setup-node@v4.4.0' - 'denoland/setup-deno@v2.0.4' '.github/workflows/push-email-notify.yml': - - 'dawidd6/action-send-mail@v3.12.0' + - 'hyperpolymath/smtp-notify-action@v0.1.0' + '.github/workflows/readme-derive.yml': [] '.github/workflows/release.yml': - 'actions/checkout@v6.0.2' - 'actions/download-artifact@v4.2.1' - 'actions/upload-artifact@v4.6.2' - 'mlugg/setup-zig@v2.2.1' - 'softprops/action-gh-release@v2.6.2' + '.github/workflows/scorecard.yml': [] + '.github/workflows/secret-scanner.yml': [] '.github/workflows/truthfulness.yml': - 'actions/checkout@v6.0.2' - 'mlugg/setup-zig@v2.2.1' @@ -157,11 +157,6 @@ dependencies: repo_id: 496012378 uses: - 'actions/upload-artifact@v4' - 'dawidd6/action-send-mail@v3.12.0': - ref: 'v3.12.0' - commit: 'sha1-2cea9617b09d79a095af21254fbcb7ae95903dde' - owner_id: 9713907 - repo_id: 222439721 'denoland/setup-deno@v2.0.4': ref: 'v2.0.4' commit: 'sha1-667a34cdef165d8d2b2e98dde39547c9daac7282' @@ -187,6 +182,11 @@ dependencies: commit: 'sha1-c6f931105cb2c34c8f901cc885ba1e2e259cf745' owner_id: 9919 repo_id: 259445878 + 'hyperpolymath/smtp-notify-action@v0.1.0': + ref: 'v0.1.0' + commit: 'sha1-1b3b752d39a4fe4c0f28f10905e4608789d3e050' + owner_id: 6759885 + repo_id: 1352485172 'mlugg/setup-zig@v2.2.1': ref: 'v2.2.1' commit: 'sha1-d1434d08867e3ee9daa34448df10607b98908d29' diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml index 02d48506..ece395bc 100644 --- a/.github/workflows/push-email-notify.yml +++ b/.github/workflows/push-email-notify.yml @@ -1,24 +1,30 @@ # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. -# This workflow is managed by gh actions-lock. # Dormant push-email notification. ARMED by setting the repo variable # PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled; # sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by # new repos from the template; placed on existing repos by the farm sweep. +# +# Re-landed after the 2026-07-20 notification-storm freeze (removed in +# 09f94c5), now on hyperpolymath/smtp-notify-action: Node-free, the SMTP +# session is Idris2-specified and machine-checked, the binary is Zig-built, +# byte-reproducible, and SHA-256-pinned inside the action itself. name: Push email notification on: - push: {} + push: + # Branch pushes only: tag and deletion payloads mislabel Branch:/head_commit. + branches: ['**'] permissions: - actions: read contents: read jobs: notify: name: Email on push if: ${{ vars.PUSH_EMAIL_ENABLED == 'true' }} runs-on: ubuntu-latest + timeout-minutes: 5 steps: - name: Send push notification email - uses: dawidd6/action-send-mail@v3.12.0 + uses: hyperpolymath/smtp-notify-action@v0.1.0 # NOSONAR — pin authority is actions.lock (sha1-1b3b752d39a4fe4c0f28f10905e4608789d3e050) with: server_address: ${{ secrets.SMTP_HOST }} server_port: ${{ secrets.SMTP_PORT }} From 86c2f18e14615c3420704a9c9879895755e02056 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 3 Sep 2026 19:43:35 +0100 Subject: [PATCH 2/2] chore(ci): repoint push-email-notify to smtp-notify-action Replaces dawidd6/action-send-mail with hyperpolymath/smtp-notify-action v0.2.0 (ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7) per the 2026-09-02 ruling; file is the rsr-template-repo canonical (dormant gating on vars.PUSH_EMAIL_ENABLED unchanged). regime=lock pristine=valid post=valid changed=.github/workflows/actions.lock,.github/workflows/push-email-notify.yml, Co-Authored-By: Claude Fable 5.1 --- .github/workflows/actions.lock | 8 ++++---- .github/workflows/push-email-notify.yml | 18 +++++++++++++++++- 2 files changed, 21 insertions(+), 5 deletions(-) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index 7d688abd..67bc8bac 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -65,7 +65,7 @@ workflows: - 'actions/setup-node@v4.4.0' - 'denoland/setup-deno@v2.0.4' '.github/workflows/push-email-notify.yml': - - 'hyperpolymath/smtp-notify-action@v0.1.0' + - 'hyperpolymath/smtp-notify-action@v0.2.0' '.github/workflows/readme-derive.yml': [] '.github/workflows/release.yml': - 'actions/checkout@v6.0.2' @@ -182,9 +182,9 @@ dependencies: commit: 'sha1-c6f931105cb2c34c8f901cc885ba1e2e259cf745' owner_id: 9919 repo_id: 259445878 - 'hyperpolymath/smtp-notify-action@v0.1.0': - ref: 'v0.1.0' - commit: 'sha1-1b3b752d39a4fe4c0f28f10905e4608789d3e050' + 'hyperpolymath/smtp-notify-action@v0.2.0': + ref: 'v0.2.0' + commit: 'sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7' owner_id: 6759885 repo_id: 1352485172 'mlugg/setup-zig@v2.2.1': diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml index ece395bc..9e133d7c 100644 --- a/.github/workflows/push-email-notify.yml +++ b/.github/workflows/push-email-notify.yml @@ -14,6 +14,22 @@ on: push: # Branch pushes only: tag and deletion payloads mislabel Branch:/head_commit. branches: ['**'] +concurrency: + # Deliberately per-RUN, so no run is ever queued behind another and none is + # ever cancelled. Do NOT "tidy" this into a shared group such as + # ${{ github.workflow }}-${{ github.ref }}. GitHub's workflow-syntax docs: + # "By default, any existing pending job or workflow in the same concurrency + # group will be canceled and the new queued job or workflow will take its + # place." That happens regardless of cancel-in-progress, which governs only + # the RUNNING job. On this workflow it silently loses a notification email, + # with no error anywhere. Every run here reports a DISTINCT commit, so there + # is no redundant work for a concurrency limit to remove. + # The docs also offer `queue: max` (up to 100 pending); not used, because 100 + # is still a cap whereas a per-run group needs none. + # Verified with zizmor 1.30.0: deleting this block raises concurrency-limits; + # this form silences it exactly as a shared group would. + group: push-email-${{ github.run_id }} + cancel-in-progress: false permissions: contents: read jobs: @@ -24,7 +40,7 @@ jobs: timeout-minutes: 5 steps: - name: Send push notification email - uses: hyperpolymath/smtp-notify-action@v0.1.0 # NOSONAR — pin authority is actions.lock (sha1-1b3b752d39a4fe4c0f28f10905e4608789d3e050) + uses: hyperpolymath/smtp-notify-action@v0.2.0 # NOSONAR — pin authority is actions.lock (sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7) with: server_address: ${{ secrets.SMTP_HOST }} server_port: ${{ secrets.SMTP_PORT }}