afterhours-shift-manager/src/release-notifier/app.py
Adam Moussa 53c85f7eed
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Add changelog-driven releases and App Home tab (#112)
* Add changelog-driven releases and App Home tab

Version the bot continuously from CHANGELOG.md (the single source of
truth for both the version and the staff-readable notes) and surface
changes to users in two ways:

- A new afterhours-release-notifier Lambda posts a "What's New" message
  to the shift channel on minor/major releases (patches stay silent).
- The bot gains an App Home "About" tab showing what it does, the
  command list, and the current version's notes.

release.yaml runs on Deploy success (not release:published — GITHUB_TOKEN
events don't start downstream workflows), checks out the deployed commit,
and tags + publishes a GitHub Release + invokes the notifier. It assumes a
dedicated, boundary-carrying OIDC role scoped to InvokeFunction on the
notifier; the account's cfn role gates role creation on that boundary.
The manual Version Bump workflow is retired. A CI guard enforces that a
CHANGELOG edit is a clean SemVer bump and that the in-package copy matches.

* Harden release workflow and regex against CodeQL findings

Address three code-scanning alerts on the PR:

- Critical (actions/untrusted-checkout): split release.yaml into a
  read-only `prepare` job that checks out and runs repo code, and a
  privileged `publish` job (contents:write + OIDC) that never checks out
  repo code — it tags, releases, and invokes purely through the GitHub
  and AWS APIs. Also assert head_branch == main.
- High x2 (py/polynomial-redos): rewrite the italic and link regexes in
  markdown_to_mrkdwn with possessive quantifiers and exclusive character
  classes so they run in linear time on adversarial input. Adds a
  regression test.

* Move release/announce into Deploy workflow to clear CodeQL

The workflow_run-triggered release.yaml kept tripping CodeQL's
privileged-context rules (untrusted-checkout, then cache-poisoning) —
CodeQL distrusts any workflow_run that checks out a ref, regardless of
the main-only guarantee, and there is no autofix.

Fold the release job into deploy.yaml gated on `needs: deploy`. A
push-to-main run is a trusted context, so checking out and running repo
code with write/OIDC is safe there. This still gates on deploy success
and serializes via the deploy concurrency group, and removes the
separate workflow entirely.
2026-06-11 19:41:31 -04:00

45 lines
1.6 KiB
Python

"""Lambda handler — announces a new release to the shift channel.
Invoked by the release workflow (``.github/workflows/release.yaml``) once a
minor or major version has been tagged *and* the new code has deployed
successfully. The event carries the version and notes already extracted from
CHANGELOG.md by the workflow, so this function never reads the changelog file
itself (it ships only in the slack-bot package, not here).
Event shape (the frozen contract between release.yaml and this function):
{"version": "1.10.0", "notes": "<markdown>", "date_label": "June 11, 2026"}
"""
import logging
import os
from slack_sdk import WebClient
from shared.blocks import build_release_announcement_blocks
from shared.secrets import get_secret
logger = logging.getLogger()
logger.setLevel(logging.INFO)
def handler(event, context):
event = event or {}
version = event.get("version")
notes = event.get("notes")
date_label = event.get("date_label", "")
if not version or not notes:
raise ValueError("event requires non-empty 'version' and 'notes'")
bot_token = get_secret(os.environ["SLACK_BOT_TOKEN_SECRET"])
channel_id = os.environ["SHIFT_CHANNEL"]
slack = WebClient(token=bot_token)
blocks = build_release_announcement_blocks(version, notes, date_label)
result = slack.chat_postMessage(
channel=channel_id,
blocks=blocks,
text=f"What's New — v{version}",
)
logger.info("Announced v%s to %s (ts=%s)", version, channel_id, result["ts"])
return {"announced": True, "version": version, "ts": result["ts"]}