Skip to content

chore(deps): Bump hyperpolymath/smtp-notify-action from 0.3.0 to 0.5.0 in the actions group - #127

Merged
hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-1afb5b2680
Oct 7, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-1afb5b2680

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps the actions group with 1 update: hyperpolymath/smtp-notify-action.

Updates hyperpolymath/smtp-notify-action from 0.3.0 to 0.5.0

Release notes

Sourced from hyperpolymath/smtp-notify-action's releases.

v0.5.0

Newsgroup posting, on the same binary

protocol: nntp with newsgroups posts one article over implicit TLS (NNTPS, 563) or STARTTLS on the news port (RFC 4642, 119), authenticating with AUTHINFO USER/PASS. Transport selection is fail-closed and unchanged in shape from the SMTP path: a server that does not advertise the upgrade is refused before any credential is written.

Refusals name their own reason, including the two 4xx codes that are not retries — 440 at POST and 441 at the article, where a class-only rule would have advised a retry and duplicated the post. Malformed newsgroups and CR/LF in a header-bound value are refused before the socket is opened. The body is dot-stuffed on the wire and a Message-ID is generated per run.

The NNTP session is a second proven contract — spec/Nntp/ (6 rows implicit, 8 with STARTTLS, plus the Newsgroups grammar and newsgroupsNoInjection) — emitted into the same src/generated/smtp_fsm.zig, so the existing drift gate covers it. The SMTP section of that file is unchanged.

The Marketplace listing can finally be published

The publish form refuses a description of 125 characters or more (measured on the parsed value, so a folded scalar does not hide it) and reads action.yml from the release tag — which is why this ships as a tag rather than a commit on main. The description is now 110 characters with STARTTLS and 365 in it; the full text lives in the README, which the listing page renders. scripts/check-action.sh and the action-metadata job keep the limit from regressing, with a selftest proving 125 is refused and 124 accepted.

server_port now defaults to empty, meaning the port the protocol and transport imply: SMTP 465/587/25, NNTP 563/119.

Provenance

CI rebuilt both static musl binaries from this tag and verified they hash to exactly the SHA-256 pins inside this tag's action.yml before publishing. SHA256SUMS is attached:

2683da8f619dd5f310c9f6884da39e825c807c2c86a6319c19aba39b27f9c5c9  smtp-notify-x86_64-linux-musl
a58138308fb9832e1ceb551a12f1b04e591dc38ba5fd336c9acfb3f263161f29  smtp-notify-aarch64-linux-musl

See CHANGELOG.adoc for the full entry, and KNOWN-DEFECTS.adoc for what is not proven — notably D-015: no real news server has ever seen this code; the end-to-end evidence is a containerised fixture.

v0.4.0

Static, byte-reproducible smtp-notify binaries. CI rebuilt them from this tag and verified they hash to exactly the SHA-256 pins inside this tag's action.yml before publishing.

Changelog

Sourced from hyperpolymath/smtp-notify-action's changelog.

// SPDX-License-Identifier: MPL-2.0 = Changelog :toc: macro :toclevels: 2

All notable changes to this action are recorded here. The format follows https://keepachangelog.com/en/1.1.0/[Keep a Changelog]; versions follow https://semver.org/spec/v2.0.0.html[Semantic Versioning].

The unit of release is the action ref: the tag or commit you pin determines both action.yml and, through the SHA-256 pins inside it, the exact binary that runs.

toc::[]

== v0.5.0 — 2026-10-04

Newsgroup posting, and the release that can finally be listed on the GitHub Marketplace. The two are one release because the description fix can only take effect from a tag — the Marketplace validates action.yml at the release's tag, not on main — and a tag is what this release is for.

NOTE: The tag must be pushed immediately after this merge. Between the two, the tagged commit's action.yml names v0.5.0 assets that do not exist yet, and @main inherits that window; the release workflow refuses to publish unless the asset URL equals the tag, so the window is a property of the release process rather than of this tree. If the tag lands on a later day, correct this heading with a follow-up commit, as was done for v0.4.0.

=== Added

  • protocol input (smtp | nntp, default smtp), chosen explicitly and never inferred. newsgroups set while protocol is smtp fails the step naming the mismatch, and protocol: nntp without newsgroups fails too, rather than either combination being guessed at.
  • NNTP posting — one article per run. Implicit TLS (NNTPS, normally 563) or STARTTLS on the cleartext news port (RFC 4642, normally 119), with AUTHINFO USER/PASS (RFC 4643). The article carries From, Newsgroups, Subject (RFC 2047 for non-ASCII), Date, a generated Message-ID, optional Content-Language, MIME-Version, Content-Type and Content-Transfer-Encoding; the body is dot-stuffed on the wire. The STARTTLS path re-reads CAPABILITIES after the upgrade, as RFC 4642 §2.2 requires, and a server that does not advertise the upgrade is refused rather than posted to in the clear.
  • A second proven contract. spec/Nntp/StateMachine.idr and spec/Nntp/Serialize.idr hold the NNTP session tables (6 rows implicit, 8 with STARTTLS) and the Newsgroups grammar, with the same style of properties as the SMTP spec: deterministic coverage, termination, ordering, and that the upgrade is on the walked path — plus newsgroupsNoInjection, the analogue of the Content-Language theorem. Both emit into the same src/generated/smtp_fsm.zig, so the existing drift gate covers them; the

... (truncated)

Commits
  • c1c9fa0 feat(nntp): NNTP posting + unblock the Marketplace listing (needs tag v0.5.0)...
  • 7ea6d7a docs(changelog): date v0.4.0 at its actual tag push (#26)
  • 170f53a ci(secret-scan): canonical estate scanner caller, key scan (D243) (#25)
  • 9f3f89f docs: add Signed commits section to CONTRIBUTING (#24)
  • acd2d3d fix: address CodeRabbit review of #21 — CertificateRequest shape checks, benc...
  • c9b6790 fix: CodeRabbit auto-fixes for PR #21 (#22)
  • 10f080a fix/issue 6 hardening (#21)
  • 5574cdc Resolve community health, accessibility, diagnostics, and benchmark debt
  • 106e28f fix(ci): reconcile the workflows with actions.lock (gh-actions-lock) (#19)
  • 2c98910 fix(ci): pin third-party actions to full commit SHAs (#18)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 1 update: [hyperpolymath/smtp-notify-action](https://github.com/hyperpolymath/smtp-notify-action).


Updates `hyperpolymath/smtp-notify-action` from 0.3.0 to 0.5.0
- [Release notes](https://github.com/hyperpolymath/smtp-notify-action/releases)
- [Changelog](https://github.com/hyperpolymath/smtp-notify-action/blob/main/CHANGELOG.adoc)
- [Commits](hyperpolymath/smtp-notify-action@22e7bdb...c1c9fa0)

---
updated-dependencies:
- dependency-name: hyperpolymath/smtp-notify-action
  dependency-version: 0.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from hyperpolymath as a code owner October 7, 2026 00:45
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 7, 2026
@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 8e6ad284-9256-4b4d-8c6a-b6b3b79c153e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 15cf26a into main Oct 7, 2026
37 of 38 checks passed
@hyperpolymath
hyperpolymath deleted the dependabot/github_actions/actions-1afb5b2680 branch October 7, 2026 06:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant