Add changelog-driven releases and App Home tab (#112)
* Add changelog-driven releases and App Home tab
Version the bot continuously from CHANGELOG.md (the single source of
truth for both the version and the staff-readable notes) and surface
changes to users in two ways:
- A new afterhours-release-notifier Lambda posts a "What's New" message
to the shift channel on minor/major releases (patches stay silent).
- The bot gains an App Home "About" tab showing what it does, the
command list, and the current version's notes.
release.yaml runs on Deploy success (not release:published — GITHUB_TOKEN
events don't start downstream workflows), checks out the deployed commit,
and tags + publishes a GitHub Release + invokes the notifier. It assumes a
dedicated, boundary-carrying OIDC role scoped to InvokeFunction on the
notifier; the account's cfn role gates role creation on that boundary.
The manual Version Bump workflow is retired. A CI guard enforces that a
CHANGELOG edit is a clean SemVer bump and that the in-package copy matches.
* Harden release workflow and regex against CodeQL findings
Address three code-scanning alerts on the PR:
- Critical (actions/untrusted-checkout): split release.yaml into a
read-only `prepare` job that checks out and runs repo code, and a
privileged `publish` job (contents:write + OIDC) that never checks out
repo code — it tags, releases, and invokes purely through the GitHub
and AWS APIs. Also assert head_branch == main.
- High x2 (py/polynomial-redos): rewrite the italic and link regexes in
markdown_to_mrkdwn with possessive quantifiers and exclusive character
classes so they run in linear time on adversarial input. Adds a
regression test.
* Move release/announce into Deploy workflow to clear CodeQL
The workflow_run-triggered release.yaml kept tripping CodeQL's
privileged-context rules (untrusted-checkout, then cache-poisoning) —
CodeQL distrusts any workflow_run that checks out a ref, regardless of
the main-only guarantee, and there is no autofix.
Fold the release job into deploy.yaml gated on `needs: deploy`. A
push-to-main run is a trusted context, so checking out and running repo
code with write/OIDC is safe there. This still gates on deploy success
and serializes via the deploy concurrency group, and removes the
separate workflow entirely.
2026-06-11 19:41:31 -04:00
|
|
|
# Slack app manifest — After-Hours Shift Manager
|
|
|
|
|
#
|
|
|
|
|
# Version-controlled source of truth for the Slack app configuration. The app
|
|
|
|
|
# predates this file, so before applying it wholesale via the Slack manifest API,
|
|
|
|
|
# reconcile it against the live app config (App settings → App Manifest) so no
|
|
|
|
|
# existing scope or setting is dropped.
|
|
|
|
|
#
|
2026-06-27 15:45:01 -04:00
|
|
|
# This release adds the `channels:history` bot scope and the `message.channels`
|
|
|
|
|
# bot event so the slack-bot Lambda can keep the two-week schedule post stuck to
|
|
|
|
|
# the bottom of the channel: on new activity it deletes and re-posts the tracked
|
|
|
|
|
# message (debounced). The new scope + event require a one-time reinstall to take
|
|
|
|
|
# effect. Replace <API_URL> with the SlackBotApiUrl stack output.
|
|
|
|
|
#
|
|
|
|
|
# A prior release added the App Home tab (no new scope):
|
Add changelog-driven releases and App Home tab (#112)
* Add changelog-driven releases and App Home tab
Version the bot continuously from CHANGELOG.md (the single source of
truth for both the version and the staff-readable notes) and surface
changes to users in two ways:
- A new afterhours-release-notifier Lambda posts a "What's New" message
to the shift channel on minor/major releases (patches stay silent).
- The bot gains an App Home "About" tab showing what it does, the
command list, and the current version's notes.
release.yaml runs on Deploy success (not release:published — GITHUB_TOKEN
events don't start downstream workflows), checks out the deployed commit,
and tags + publishes a GitHub Release + invokes the notifier. It assumes a
dedicated, boundary-carrying OIDC role scoped to InvokeFunction on the
notifier; the account's cfn role gates role creation on that boundary.
The manual Version Bump workflow is retired. A CI guard enforces that a
CHANGELOG edit is a clean SemVer bump and that the in-package copy matches.
* Harden release workflow and regex against CodeQL findings
Address three code-scanning alerts on the PR:
- Critical (actions/untrusted-checkout): split release.yaml into a
read-only `prepare` job that checks out and runs repo code, and a
privileged `publish` job (contents:write + OIDC) that never checks out
repo code — it tags, releases, and invokes purely through the GitHub
and AWS APIs. Also assert head_branch == main.
- High x2 (py/polynomial-redos): rewrite the italic and link regexes in
markdown_to_mrkdwn with possessive quantifiers and exclusive character
classes so they run in linear time on adversarial input. Adds a
regression test.
* Move release/announce into Deploy workflow to clear CodeQL
The workflow_run-triggered release.yaml kept tripping CodeQL's
privileged-context rules (untrusted-checkout, then cache-poisoning) —
CodeQL distrusts any workflow_run that checks out a ref, regardless of
the main-only guarantee, and there is no autofix.
Fold the release job into deploy.yaml gated on `needs: deploy`. A
push-to-main run is a trusted context, so checking out and running repo
code with write/OIDC is safe there. This still gates on deploy success
and serializes via the deploy concurrency group, and removes the
separate workflow entirely.
2026-06-11 19:41:31 -04:00
|
|
|
# - settings.event_subscriptions.bot_events: + app_home_opened
|
|
|
|
|
# - features.app_home.home_tab_enabled: true
|
|
|
|
|
display_information:
|
|
|
|
|
name: After-Hours Shift Manager
|
|
|
|
|
description: Manage after-hours on-call phone duty from Slack.
|
|
|
|
|
|
|
|
|
|
features:
|
|
|
|
|
bot_user:
|
|
|
|
|
display_name: oncall
|
|
|
|
|
always_online: true
|
|
|
|
|
slash_commands:
|
|
|
|
|
- command: /oncall
|
|
|
|
|
url: <API_URL>
|
|
|
|
|
description: Manage after-hours on-call shifts
|
|
|
|
|
usage_hint: "[next|pick|drop|swap|register|pay|rate|roster|help] …"
|
|
|
|
|
should_escape: false
|
|
|
|
|
app_home:
|
|
|
|
|
home_tab_enabled: true
|
|
|
|
|
messages_tab_enabled: true
|
|
|
|
|
messages_tab_read_only_enabled: false
|
|
|
|
|
|
|
|
|
|
oauth_config:
|
|
|
|
|
scopes:
|
|
|
|
|
bot:
|
|
|
|
|
- commands
|
|
|
|
|
- chat:write
|
|
|
|
|
- im:write
|
|
|
|
|
- users:read
|
2026-06-27 15:45:01 -04:00
|
|
|
# channels:history lets the bot receive message.channels events for the
|
|
|
|
|
# schedule channel, which drive the activity bump that keeps the schedule
|
|
|
|
|
# post at the bottom of the channel. Requires a one-time reinstall.
|
|
|
|
|
- channels:history
|
Add changelog-driven releases and App Home tab (#112)
* Add changelog-driven releases and App Home tab
Version the bot continuously from CHANGELOG.md (the single source of
truth for both the version and the staff-readable notes) and surface
changes to users in two ways:
- A new afterhours-release-notifier Lambda posts a "What's New" message
to the shift channel on minor/major releases (patches stay silent).
- The bot gains an App Home "About" tab showing what it does, the
command list, and the current version's notes.
release.yaml runs on Deploy success (not release:published — GITHUB_TOKEN
events don't start downstream workflows), checks out the deployed commit,
and tags + publishes a GitHub Release + invokes the notifier. It assumes a
dedicated, boundary-carrying OIDC role scoped to InvokeFunction on the
notifier; the account's cfn role gates role creation on that boundary.
The manual Version Bump workflow is retired. A CI guard enforces that a
CHANGELOG edit is a clean SemVer bump and that the in-package copy matches.
* Harden release workflow and regex against CodeQL findings
Address three code-scanning alerts on the PR:
- Critical (actions/untrusted-checkout): split release.yaml into a
read-only `prepare` job that checks out and runs repo code, and a
privileged `publish` job (contents:write + OIDC) that never checks out
repo code — it tags, releases, and invokes purely through the GitHub
and AWS APIs. Also assert head_branch == main.
- High x2 (py/polynomial-redos): rewrite the italic and link regexes in
markdown_to_mrkdwn with possessive quantifiers and exclusive character
classes so they run in linear time on adversarial input. Adds a
regression test.
* Move release/announce into Deploy workflow to clear CodeQL
The workflow_run-triggered release.yaml kept tripping CodeQL's
privileged-context rules (untrusted-checkout, then cache-poisoning) —
CodeQL distrusts any workflow_run that checks out a ref, regardless of
the main-only guarantee, and there is no autofix.
Fold the release job into deploy.yaml gated on `needs: deploy`. A
push-to-main run is a trusted context, so checking out and running repo
code with write/OIDC is safe there. This still gates on deploy success
and serializes via the deploy concurrency group, and removes the
separate workflow entirely.
2026-06-11 19:41:31 -04:00
|
|
|
|
|
|
|
|
settings:
|
|
|
|
|
event_subscriptions:
|
|
|
|
|
request_url: <API_URL>
|
|
|
|
|
bot_events:
|
|
|
|
|
- app_home_opened
|
2026-06-27 15:45:01 -04:00
|
|
|
# message.channels drives the activity bump that keeps the schedule post
|
|
|
|
|
# at the bottom of the channel (debounced delete + repost).
|
|
|
|
|
- message.channels
|
Add changelog-driven releases and App Home tab (#112)
* Add changelog-driven releases and App Home tab
Version the bot continuously from CHANGELOG.md (the single source of
truth for both the version and the staff-readable notes) and surface
changes to users in two ways:
- A new afterhours-release-notifier Lambda posts a "What's New" message
to the shift channel on minor/major releases (patches stay silent).
- The bot gains an App Home "About" tab showing what it does, the
command list, and the current version's notes.
release.yaml runs on Deploy success (not release:published — GITHUB_TOKEN
events don't start downstream workflows), checks out the deployed commit,
and tags + publishes a GitHub Release + invokes the notifier. It assumes a
dedicated, boundary-carrying OIDC role scoped to InvokeFunction on the
notifier; the account's cfn role gates role creation on that boundary.
The manual Version Bump workflow is retired. A CI guard enforces that a
CHANGELOG edit is a clean SemVer bump and that the in-package copy matches.
* Harden release workflow and regex against CodeQL findings
Address three code-scanning alerts on the PR:
- Critical (actions/untrusted-checkout): split release.yaml into a
read-only `prepare` job that checks out and runs repo code, and a
privileged `publish` job (contents:write + OIDC) that never checks out
repo code — it tags, releases, and invokes purely through the GitHub
and AWS APIs. Also assert head_branch == main.
- High x2 (py/polynomial-redos): rewrite the italic and link regexes in
markdown_to_mrkdwn with possessive quantifiers and exclusive character
classes so they run in linear time on adversarial input. Adds a
regression test.
* Move release/announce into Deploy workflow to clear CodeQL
The workflow_run-triggered release.yaml kept tripping CodeQL's
privileged-context rules (untrusted-checkout, then cache-poisoning) —
CodeQL distrusts any workflow_run that checks out a ref, regardless of
the main-only guarantee, and there is no autofix.
Fold the release job into deploy.yaml gated on `needs: deploy`. A
push-to-main run is a trusted context, so checking out and running repo
code with write/OIDC is safe there. This still gates on deploy success
and serializes via the deploy concurrency group, and removes the
separate workflow entirely.
2026-06-11 19:41:31 -04:00
|
|
|
interactivity:
|
|
|
|
|
is_enabled: true
|
|
|
|
|
request_url: <API_URL>
|
|
|
|
|
org_deploy_enabled: false
|
|
|
|
|
socket_mode_enabled: false
|