This website requires JavaScript.
Explore
Help
Sign in
adam
/
afterhours-shift-manager
Watch
1
Star
0
Fork
You've already forked afterhours-shift-manager
0
mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced
2026-10-04 11:22:04 +00:00
Code
Issues
Projects
Releases
Packages
Wiki
Activity
Actions
aa7b9b5e22
afterhours-shift-manager
/
src
/
release-notifier
/
requirements.txt
3 lines
38 B
Text
Raw
Normal View
History
Unescape
Escape
Add changelog-driven releases and App Home tab (#112) * Add changelog-driven releases and App Home tab Version the bot continuously from CHANGELOG.md (the single source of truth for both the version and the staff-readable notes) and surface changes to users in two ways: - A new afterhours-release-notifier Lambda posts a "What's New" message to the shift channel on minor/major releases (patches stay silent). - The bot gains an App Home "About" tab showing what it does, the command list, and the current version's notes. release.yaml runs on Deploy success (not release:published — GITHUB_TOKEN events don't start downstream workflows), checks out the deployed commit, and tags + publishes a GitHub Release + invokes the notifier. It assumes a dedicated, boundary-carrying OIDC role scoped to InvokeFunction on the notifier; the account's cfn role gates role creation on that boundary. The manual Version Bump workflow is retired. A CI guard enforces that a CHANGELOG edit is a clean SemVer bump and that the in-package copy matches. * Harden release workflow and regex against CodeQL findings Address three code-scanning alerts on the PR: - Critical (actions/untrusted-checkout): split release.yaml into a read-only `prepare` job that checks out and runs repo code, and a privileged `publish` job (contents:write + OIDC) that never checks out repo code — it tags, releases, and invokes purely through the GitHub and AWS APIs. Also assert head_branch == main. - High x2 (py/polynomial-redos): rewrite the italic and link regexes in markdown_to_mrkdwn with possessive quantifiers and exclusive character classes so they run in linear time on adversarial input. Adds a regression test. * Move release/announce into Deploy workflow to clear CodeQL The workflow_run-triggered release.yaml kept tripping CodeQL's privileged-context rules (untrusted-checkout, then cache-poisoning) — CodeQL distrusts any workflow_run that checks out a ref, regardless of the main-only guarantee, and there is no autofix. Fold the release job into deploy.yaml gated on `needs: deploy`. A push-to-main run is a trusted context, so checking out and running repo code with write/OIDC is safe there. This still gates on deploy success and serializes via the deploy concurrency group, and removes the separate workflow entirely.
2026-06-11 19:41:31 -04:00
slack_sdk>=3.42.0,<4.0
Update boto3 requirement in /src/release-notifier Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](https://github.com/boto/boto3/compare/1.43.27...1.43.43) --- updated-dependencies: - dependency-name: boto3 dependency-version: 1.43.43 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
2026-07-08 21:14:42 +00:00
boto3>=1.43.43
Reference in a new issue
Copy permalink