afterhours-shift-manager/CHANGELOG.md
Adam Moussa 53c85f7eed
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Add changelog-driven releases and App Home tab (#112)
* Add changelog-driven releases and App Home tab

Version the bot continuously from CHANGELOG.md (the single source of
truth for both the version and the staff-readable notes) and surface
changes to users in two ways:

- A new afterhours-release-notifier Lambda posts a "What's New" message
  to the shift channel on minor/major releases (patches stay silent).
- The bot gains an App Home "About" tab showing what it does, the
  command list, and the current version's notes.

release.yaml runs on Deploy success (not release:published — GITHUB_TOKEN
events don't start downstream workflows), checks out the deployed commit,
and tags + publishes a GitHub Release + invokes the notifier. It assumes a
dedicated, boundary-carrying OIDC role scoped to InvokeFunction on the
notifier; the account's cfn role gates role creation on that boundary.
The manual Version Bump workflow is retired. A CI guard enforces that a
CHANGELOG edit is a clean SemVer bump and that the in-package copy matches.

* Harden release workflow and regex against CodeQL findings

Address three code-scanning alerts on the PR:

- Critical (actions/untrusted-checkout): split release.yaml into a
  read-only `prepare` job that checks out and runs repo code, and a
  privileged `publish` job (contents:write + OIDC) that never checks out
  repo code — it tags, releases, and invokes purely through the GitHub
  and AWS APIs. Also assert head_branch == main.
- High x2 (py/polynomial-redos): rewrite the italic and link regexes in
  markdown_to_mrkdwn with possessive quantifiers and exclusive character
  classes so they run in linear time on adversarial input. Adds a
  regression test.

* Move release/announce into Deploy workflow to clear CodeQL

The workflow_run-triggered release.yaml kept tripping CodeQL's
privileged-context rules (untrusted-checkout, then cache-poisoning) —
CodeQL distrusts any workflow_run that checks out a ref, regardless of
the main-only guarantee, and there is no autofix.

Fold the release job into deploy.yaml gated on `needs: deploy`. A
push-to-main run is a trusted context, so checking out and running repo
code with write/OIDC is safe there. This still gates on deploy success
and serializes via the deploy concurrency group, and removes the
separate workflow entirely.
2026-06-11 19:41:31 -04:00

101 lines
4.3 KiB
Markdown

# Changelog
What's changed in the **After-Hours Shift Manager** — the Slack bot that runs our
after-hours on-call phone duty. Newest first, in plain language.
Versions are `MAJOR.MINOR.PATCH`: a **minor** bump adds a new feature, a **patch**
is a fix or tidy-up, and a **major** would be a big change to how things work.
A few older entries cover two versions at once (e.g. `v1.9.0 / v1.9.1`) — that's
fine and still supported.
---
## v1.10.0 — June 11, 2026
**The bot now tells you what's new.** Two things:
- When a noticeable update ships (a new feature or a bigger change), the bot
posts a short "What's New" note right in the on-call channel — so you hear
about changes without having to go looking. Small fixes stay quiet.
- The bot now has an **About** page. Click the bot's name in Slack and open its
**Home** tab to see what it does, the full list of `/oncall` commands, and the
latest "What's New". It always shows the current version.
## v1.9.2 — June 1, 2026
**Setup-guide fix.** Corrected the install instructions so secrets (the Slack and
phone-system passwords) are stored in the right, secure place. No change to the
bot itself — this only affects someone setting it up from scratch.
## v1.9.0 / v1.9.1 — June 1, 2026
**You can no longer drop a shift at the last minute.** If a shift starts within
the next 24 hours, you can't just drop it and walk away — you have to hand it to
someone specific (a swap they accept), or ask an admin. This stops the phones
from being left uncovered with no notice. *(v1.9.1 was a routine update of
behind-the-scenes software libraries.)*
## v1.8.0 — June 1, 2026
**Swaps now need the other person to say yes.** Before, `/oncall swap` instantly
dumped your shift on someone else. Now they get a Slack message with **Accept**
and **Decline** buttons, and the shift only moves if they accept. Until then it
stays yours. If they don't respond before the shift starts, the request quietly
expires.
## v1.7.19 — June 1, 2026
**Quality safety net (no visible change).** Added an automated test suite that
checks the bot's behavior on every change, so bugs get caught before they ship.
You won't notice anything different day-to-day — it just makes future updates
safer.
---
## May 2026 — Phone-system automation & a big fix
- **Live phone routing follows the schedule.** The system that decides which
phone rings after hours now reads directly from the on-call schedule, so
pickups, drops, and swaps take effect automatically.
- **Fixed a release that had broken the whole bot.** A packaging mistake stopped
all of the bot's functions from running; this was found and fixed.
- Ongoing routine updates to behind-the-scenes software libraries.
- **Behind the scenes:** moved to an automated build-and-release pipeline, added
automatic code checks and formatting, and turned on automated dependency and
code-review tooling. None of this changes how you use the bot.
## May 1, 2026 — Reliability & notifications
- **No more double-booking.** Fixed a timing bug where two people could grab the
same open shift at once.
- **Shift changes are announced.** When someone picks up, drops, or swaps a
shift, a note is posted to the team channel.
- **Fixed a confusing error** that showed up when picking a shift even though the
pickup had actually worked.
## April 8, 2026 — Schedule & pay polish
- The weekly schedule now always starts on **Monday** (it used to start from
today).
- Tidied up the weekly pay report (recipient and wording).
## April 7, 2026 — Scheduling & pay
- **Two-week schedule view** instead of just the current week.
- **Weekly pay totals** for on-call shifts, with a configurable flat rate.
- **Per-person pay rates** and an `/oncall rate` command to manage them from
Slack.
- **Weekend day shifts** — weekends are split into a daytime and an overnight
shift.
- **Automatic employee roster sync** — the bot pulls the staff list from the
phone system each day, so the roster stays current on its own.
- **Weekly "Bonus Pay Summary"** emailed to payroll (and sent as a Slack DM to
the admin) every Monday.
## April 3, 2026 — Launch 🎉
The first version of the After-Hours Shift Manager:
- See the on-call schedule in Slack with `/oncall`.
- **Pick up** an open shift and **drop** a shift you're covering.
- Link your Slack account to your phone extension with `/oncall register`.