renovate[bot]
37f12421fd
chore(deps): update pip minor and patch ( #246 )
...
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-09 18:40:59 +00:00
renovate[bot]
42921aa2ba
chore(deps): update pip minor and patch ( #243 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-31 16:06:56 +00:00
renovate[bot]
b30828b701
chore(deps): update dependency boto3 to >=1.43.78 ( #238 )
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
2026-08-24 21:54:44 +00:00
dependabot[bot]
f599294e75
chore(deps): update boto3 requirement in /src/release-notifier ( #227 )
2026-08-19 03:46:07 +00:00
dependabot[bot]
6141cd38be
chore(deps): update boto3 requirement in /src/release-notifier ( #219 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.62...1.43.67 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.67
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 00:06:43 +00:00
Adam Moussa
4b6c15644f
chore(deps): batch boto3 bumps to >=1.43.62 (DEV-25) ( #210 )
...
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
* chore(deps): update boto3 requirement in /src/holiday-router
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.58...1.43.62 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.62
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
* chore(deps): update boto3 requirement in /src/release-notifier
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.58...1.43.62 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.62
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
* chore(deps): update boto3 requirement in /src/ring-scheduler
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.58...1.43.62 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.62
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
* chore(deps): update boto3 requirement in /src/roster-sync
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.58...1.43.62 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.62
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
* chore(deps): update boto3 requirement in /src/shared
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.58...1.43.62 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.62
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
* chore(deps): update boto3 requirement in /src/slack-bot
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.58...1.43.62 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.62
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
* chore(deps): update boto3 requirement in /src/weekly-post
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.58...1.43.62 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.62
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 14:24:23 -04:00
dependabot[bot]
94ab731331
chore(deps): update boto3 requirement in /src/release-notifier
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.53...1.43.58 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.58
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-28 19:46:51 -04:00
Adam Moussa
e769260598
chore: batch Dependabot boto3 bumps ( #176 , #177 , #178 , #179 , #180 , #181 , #182 ) ( #183 )
...
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
* Update boto3 requirement in /src/holiday-router
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.53
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
* Update boto3 requirement in /src/release-notifier
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.53
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
* Update boto3 requirement in /src/ring-scheduler
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.53
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
* Update boto3 requirement from >=1.43.48 to >=1.43.53 in /src/roster-sync
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.53
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
* Update boto3 requirement from >=1.43.48 to >=1.43.53 in /src/shared
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.53
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
* Update boto3 requirement from >=1.43.48 to >=1.43.53 in /src/slack-bot
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.53
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
* Update boto3 requirement from >=1.43.48 to >=1.43.53 in /src/weekly-post
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.53
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
* chore: gitignore .idea/
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-22 13:08:01 -04:00
dependabot[bot]
2eefd46410
Update boto3 requirement in /src/release-notifier ( #169 )
...
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.48 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.48
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 16:52:52 +00:00
dependabot[bot]
0ca4ffeec2
Update slack-sdk requirement in /src/release-notifier ( #163 )
...
Updates the requirements on [slack-sdk](https://github.com/slackapi/python-slack-sdk ) to permit the latest version.
- [Release notes](https://github.com/slackapi/python-slack-sdk/releases )
- [Commits](https://github.com/slackapi/python-slack-sdk/compare/v3.42.0...v3.43.0 )
---
updated-dependencies:
- dependency-name: slack-sdk
dependency-version: 3.43.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-08 17:50:48 -04:00
dependabot[bot]
f6c6bd8f5e
Update boto3 requirement in /src/release-notifier ( #162 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.27...1.43.43 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.43
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-08 21:16:42 +00:00
Adam Moussa
53c85f7eed
Add changelog-driven releases and App Home tab ( #112 )
...
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
* Add changelog-driven releases and App Home tab
Version the bot continuously from CHANGELOG.md (the single source of
truth for both the version and the staff-readable notes) and surface
changes to users in two ways:
- A new afterhours-release-notifier Lambda posts a "What's New" message
to the shift channel on minor/major releases (patches stay silent).
- The bot gains an App Home "About" tab showing what it does, the
command list, and the current version's notes.
release.yaml runs on Deploy success (not release:published — GITHUB_TOKEN
events don't start downstream workflows), checks out the deployed commit,
and tags + publishes a GitHub Release + invokes the notifier. It assumes a
dedicated, boundary-carrying OIDC role scoped to InvokeFunction on the
notifier; the account's cfn role gates role creation on that boundary.
The manual Version Bump workflow is retired. A CI guard enforces that a
CHANGELOG edit is a clean SemVer bump and that the in-package copy matches.
* Harden release workflow and regex against CodeQL findings
Address three code-scanning alerts on the PR:
- Critical (actions/untrusted-checkout): split release.yaml into a
read-only `prepare` job that checks out and runs repo code, and a
privileged `publish` job (contents:write + OIDC) that never checks out
repo code — it tags, releases, and invokes purely through the GitHub
and AWS APIs. Also assert head_branch == main.
- High x2 (py/polynomial-redos): rewrite the italic and link regexes in
markdown_to_mrkdwn with possessive quantifiers and exclusive character
classes so they run in linear time on adversarial input. Adds a
regression test.
* Move release/announce into Deploy workflow to clear CodeQL
The workflow_run-triggered release.yaml kept tripping CodeQL's
privileged-context rules (untrusted-checkout, then cache-poisoning) —
CodeQL distrusts any workflow_run that checks out a ref, regardless of
the main-only guarantee, and there is no autofix.
Fold the release job into deploy.yaml gated on `needs: deploy`. A
push-to-main run is a trusted context, so checking out and running repo
code with write/OIDC is safe there. This still gates on deploy success
and serializes via the deploy concurrency group, and removes the
separate workflow entirely.
2026-06-11 19:41:31 -04:00