Skip to content

chore(deps): bump the actions group with 2 updates - #82

Merged
hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-e062b07fec
Oct 10, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-e062b07fec

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor

Bumps the actions group with 2 updates: actions/upload-artifact and hyperpolymath/smtp-notify-action.

Updates actions/upload-artifact from 7.0.1 to 7.0.2

Release notes

Sourced from actions/upload-artifact's releases.

v7.0.2

What's Changed

  • Improves artifact download retries when the service returns HTTP 429 (rate limiting), including honoring valid Retry-After headers.
  • Updates @​actions/artifact to v6.3.1.

New Contributors

Full Changelog: actions/upload-artifact@v7.0.1...v7.0.2

Commits
  • cf430e0 Merge pull request #822 from actions/tunc-d-prepare-upload-v7-0-2
  • c2acded chore: prepare v7.0.2 release
  • 4687c1b Merge pull request #821 from actions/tunc-d-upload-artifact-package-bump
  • 8cbe1be Bump @​actions/artifact to 6.3.1
  • See full diff in compare view

Updates hyperpolymath/smtp-notify-action from 0.3.0 to 0.5.0

Release notes

Sourced from hyperpolymath/smtp-notify-action's releases.

v0.5.0

Newsgroup posting, on the same binary

protocol: nntp with newsgroups posts one article over implicit TLS (NNTPS, 563) or STARTTLS on the news port (RFC 4642, 119), authenticating with AUTHINFO USER/PASS. Transport selection is fail-closed and unchanged in shape from the SMTP path: a server that does not advertise the upgrade is refused before any credential is written.

Refusals name their own reason, including the two 4xx codes that are not retries — 440 at POST and 441 at the article, where a class-only rule would have advised a retry and duplicated the post. Malformed newsgroups and CR/LF in a header-bound value are refused before the socket is opened. The body is dot-stuffed on the wire and a Message-ID is generated per run.

The NNTP session is a second proven contract — spec/Nntp/ (6 rows implicit, 8 with STARTTLS, plus the Newsgroups grammar and newsgroupsNoInjection) — emitted into the same src/generated/smtp_fsm.zig, so the existing drift gate covers it. The SMTP section of that file is unchanged.

The Marketplace listing can finally be published

The publish form refuses a description of 125 characters or more (measured on the parsed value, so a folded scalar does not hide it) and reads action.yml from the release tag — which is why this ships as a tag rather than a commit on main. The description is now 110 characters with STARTTLS and 365 in it; the full text lives in the README, which the listing page renders. scripts/check-action.sh and the action-metadata job keep the limit from regressing, with a selftest proving 125 is refused and 124 accepted.

server_port now defaults to empty, meaning the port the protocol and transport imply: SMTP 465/587/25, NNTP 563/119.

Provenance

CI rebuilt both static musl binaries from this tag and verified they hash to exactly the SHA-256 pins inside this tag's action.yml before publishing. SHA256SUMS is attached:

2683da8f619dd5f310c9f6884da39e825c807c2c86a6319c19aba39b27f9c5c9  smtp-notify-x86_64-linux-musl
a58138308fb9832e1ceb551a12f1b04e591dc38ba5fd336c9acfb3f263161f29  smtp-notify-aarch64-linux-musl

See CHANGELOG.adoc for the full entry, and KNOWN-DEFECTS.adoc for what is not proven — notably D-015: no real news server has ever seen this code; the end-to-end evidence is a containerised fixture.

v0.4.0

Static, byte-reproducible smtp-notify binaries. CI rebuilt them from this tag and verified they hash to exactly the SHA-256 pins inside this tag's action.yml before publishing.

Changelog

Sourced from hyperpolymath/smtp-notify-action's changelog.

// SPDX-License-Identifier: MPL-2.0 = Changelog :toc: macro :toclevels: 2

All notable changes to this action are recorded here. The format follows https://keepachangelog.com/en/1.1.0/[Keep a Changelog]; versions follow https://semver.org/spec/v2.0.0.html[Semantic Versioning].

The unit of release is the action ref: the tag or commit you pin determines both action.yml and, through the SHA-256 pins inside it, the exact binary that runs.

toc::[]

== v0.5.0 — 2026-10-04

Newsgroup posting, and the release that can finally be listed on the GitHub Marketplace. The two are one release because the description fix can only take effect from a tag — the Marketplace validates action.yml at the release's tag, not on main — and a tag is what this release is for.

NOTE: The tag must be pushed immediately after this merge. Between the two, the tagged commit's action.yml names v0.5.0 assets that do not exist yet, and @main inherits that window; the release workflow refuses to publish unless the asset URL equals the tag, so the window is a property of the release process rather than of this tree. If the tag lands on a later day, correct this heading with a follow-up commit, as was done for v0.4.0.

=== Added

  • protocol input (smtp | nntp, default smtp), chosen explicitly and never inferred. newsgroups set while protocol is smtp fails the step naming the mismatch, and protocol: nntp without newsgroups fails too, rather than either combination being guessed at.
  • NNTP posting — one article per run. Implicit TLS (NNTPS, normally 563) or STARTTLS on the cleartext news port (RFC 4642, normally 119), with AUTHINFO USER/PASS (RFC 4643). The article carries From, Newsgroups, Subject (RFC 2047 for non-ASCII), Date, a generated Message-ID, optional Content-Language, MIME-Version, Content-Type and Content-Transfer-Encoding; the body is dot-stuffed on the wire. The STARTTLS path re-reads CAPABILITIES after the upgrade, as RFC 4642 §2.2 requires, and a server that does not advertise the upgrade is refused rather than posted to in the clear.
  • A second proven contract. spec/Nntp/StateMachine.idr and spec/Nntp/Serialize.idr hold the NNTP session tables (6 rows implicit, 8 with STARTTLS) and the Newsgroups grammar, with the same style of properties as the SMTP spec: deterministic coverage, termination, ordering, and that the upgrade is on the walked path — plus newsgroupsNoInjection, the analogue of the Content-Language theorem. Both emit into the same src/generated/smtp_fsm.zig, so the existing drift gate covers them; the

... (truncated)

Commits
  • c1c9fa0 feat(nntp): NNTP posting + unblock the Marketplace listing (needs tag v0.5.0)...
  • 7ea6d7a docs(changelog): date v0.4.0 at its actual tag push (#26)
  • 170f53a ci(secret-scan): canonical estate scanner caller, key scan (D243) (#25)
  • 9f3f89f docs: add Signed commits section to CONTRIBUTING (#24)
  • acd2d3d fix: address CodeRabbit review of #21 — CertificateRequest shape checks, benc...
  • c9b6790 fix: CodeRabbit auto-fixes for PR #21 (#22)
  • 10f080a fix/issue 6 hardening (#21)
  • 5574cdc Resolve community health, accessibility, diagnostics, and benchmark debt
  • 106e28f fix(ci): reconcile the workflows with actions.lock (gh-actions-lock) (#19)
  • 2c98910 fix(ci): pin third-party actions to full commit SHAs (#18)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 2 updates: [actions/upload-artifact](https://github.com/actions/upload-artifact) and [hyperpolymath/smtp-notify-action](https://github.com/hyperpolymath/smtp-notify-action).


Updates `actions/upload-artifact` from 7.0.1 to 7.0.2
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@043fb46...cf430e0)

Updates `hyperpolymath/smtp-notify-action` from 0.3.0 to 0.5.0
- [Release notes](https://github.com/hyperpolymath/smtp-notify-action/releases)
- [Changelog](https://github.com/hyperpolymath/smtp-notify-action/blob/main/CHANGELOG.adoc)
- [Commits](hyperpolymath/smtp-notify-action@22e7bdb...c1c9fa0)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: hyperpolymath/smtp-notify-action
  dependency-version: 0.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from hyperpolymath as a code owner October 10, 2026 05:35
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 10, 2026
@sonarqubecloud

Copy link
Copy Markdown

@coderabbitai

coderabbitai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 55baaf9c-fc26-4cc1-8d10-a3cbb49c6932

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 47 issues detected

Severity Count
🔴 Critical 6
🟠 High 14
🟡 Medium 27

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/label-triage.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "triage"
  },
  {
    "reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/labels.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "sync"
  },
  {
    "line": 38,
    "reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/labels.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 44,
    "reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/push-email-notify.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 82,
    "reason": "job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/hypatia-scan.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 52,
    "reason": "job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/label-triage.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 33,
    "reason": "workflow .github/workflows/labels.yml:33 job `sync` has no `timeout-minutes:` — defaults to 360 min on hang",
    "type": "WH006",
    "file": ".github/workflows/labels.yml",
    "action": "report",
    "rule_module": "workflow_hardening",
    "severity": "medium"
  },
  {
    "line": 47,
    "reason": "workflow .github/workflows/label-triage.yml:47 job `triage` has no `timeout-minutes:` — defaults to 360 min on hang",
    "type": "WH006",
    "file": ".github/workflows/label-triage.yml",
    "action": "report",
    "rule_module": "workflow_hardening",
    "severity": "medium"
  },
  {
    "line": null,
    "reason": "workflow .github/workflows/hypatia-scan.yml uploads SARIF to code scanning but masks the scanner's failure (`|| true` / `|| echo 0`) and never asserts the findings artefact is a non-empty array. When the scanner fails, this uploads a SARIF with zero results, and GitHub AUTO-CLOSES every previously-open alert for that category — silently, with the job green.",
    "type": "WH014",
    "file": ".github/workflows/hypatia-scan.yml",
    "action": "report",
    "rule_module": "workflow_hardening",
    "severity": "high"
  },
  {
    "reason": "Code scanning (Hypatia): hypatia/workflow_audit/missing_timeout_minutes -- Hypatia workflow_audit: missing_timeout_minutes -- 8 day(s) old",
    "type": "CSA001",
    "file": ".github/workflows/labels.yml",
    "action": "review",
    "rule_module": "code_scanning_alerts",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@hyperpolymath
hyperpolymath merged commit 33e19ff into main Oct 10, 2026
29 checks passed
@hyperpolymath
hyperpolymath deleted the dependabot/github_actions/actions-e062b07fec branch October 10, 2026 09:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant