Repository navigation
Releases: ChiefGyk3D/hypeman
Release list
v0.3.4: PyPI publishing, for real
Fixed
- PyPI publishing, for real. 0.3.3 moved the upload into a job of this
repository'srelease.ymlbut wrappedpypa/gh-action-pypi-publishin a
composite action, and that action names its Docker image from the
repository that contains it, so the image pull failed. The pypa action is
now a direct step of the job, as it was for 0.2.0. 0.3.4 carries the code of
0.3.1 to 0.3.3 unchanged and is the first 0.3 release on PyPI.
v0.3.3: PyPI publishing fixed
Fixed
- PyPI publishing works again. PyPI Trusted Publishing cannot use a
reusable workflow as the publisher (pypi/warehouse#11096), so 0.3.1 and
0.3.2 reached GitHub but were rejected by PyPI withinvalid-publisher.
The upload now runs in apublish-pypijob of this repository's own
release.yml(GYST v1.19.0'spublish-pypicomposite action). 0.3.3 is the
first version of the 0.3 line on PyPI; it carries the code of 0.3.1 and
0.3.2 with no change.
v0.3.2
What's Changed
- release: 0.3.2, re-pin GYST to v1.17.0 by @ChiefGyk3D in #74
Full Changelog: v0.3.1...v0.3.2
v0.3.1: per-platform duplicate detection
Fixed
- Duplicate detection is now per platform. The recently-posted history
was one list shared by every platform, so the Matrix, Bluesky and Mastodon
announcements for the same video (more than 80% of their words shared with
the Discord one) were rejected as "Duplicate of a recently posted message"
and fell back to the template. Measured on Boon-Tube-Daemon over 15
uploads, Mastodon passed 7 of 15 for this reason.is_duplicate_message()
andadd_to_message_cache()take an optionalplatform(omitted means the
sharedgenericbucket),generate_validated()andapply_guardrails()
pass theplatformthey already receive, and the same text posted twice to
one platform is still rejected. Threshold, window size and
LLM_ENABLE_DEDUPLICATIONare unchanged; existing callers need no change.
Changed
- CI, security scanning and the PyPI release now call the reusable workflows
inChiefGyk3D/git-your-ship-together(v1.6.3) instead of hand-written
jobs: oneCI greengate per workflow, egress blocked to measured hosts,
Semgrep and gitleaks added, build provenance andSHA256SUMSattached to
each GitHub release.codeql.ymlandscorecard.ymlare folded into
security.yml. Package contents are unchanged.
Also in this release: 0.3.0 (never released on its own)
Added
- Image attachments on Bluesky and Mastodon: pass
stream_data={'images': [{'data': b'...', 'alt': '...'}, ...]}(or
{'url': ..., 'alt': ...}to have the picture fetched for you) and the
post carries them as pictures of their own, each with its own alt text —
as an images embed on Bluesky, as media attachments on Mastodon. Up to
four per post; a picture that cannot be resolved or uploaded is logged and
left out rather than blocking the text. The media type is sniffed from
the bytes, so a chart rendered in memory needs no naming. This is what
SolarStorm Scout needs for its D-RAP map, aurora oval and GOES X-ray
chart, and is distinct fromthumbnail_url, which still drives link
cards for announcements about a URL.
attached_images()andsniff_image_mime()are exported from
hypeman_social.social.basefor platforms that want the same rules.
Changed
- Mastodon no longer demands an OAuth client id/secret. An access
token and the instance URL are enough, which is how Mastodon.py itself
works and how most bots are set up (Preferences → Development → copy the
token). A full client pair is still passed through when both are present;
a lone half of the pair is ignored with a warning. - Doppler config reads are cached.
get_config()used to open a Doppler
client and fetch the whole project on every call — andBaseLLMalone
makes about twenty calls while being constructed — so a daemon with
Doppler enabled could trip the rate limit reading settings that never
change. Plain settings now read through the same once-per-process cache
as credentials (reset_secret_cache(), now exported from
hypeman_social.config, forces a re-read). One consequence: with
DOPPLER_CONFIGunset, settings and secrets now both default to the
prdconfig, where settings alone used to default todev. hypeman_social.__version__now matches the package version (it had
been left at 0.1.0).
Callers
The daemons pin hypeman-social==0.2.0; move them to 0.3.1. The 0.3.0 changes include image attachments and token-only Mastodon auth, so each daemon's CI must pass before it is deployed.
v0.2.0
What's new in 0.2.0
Threads support
New ThreadsPlatform posts via the official Threads Graph API (container create → publish), with the 500-character limit enforced, link-preview cards attached, and reply threading. Plain HTTPS — no extra to install. Registered in REGISTRY as 'threads', so every daemon picks it up automatically.
Starred-repository rendering on every platform
Pass event_kind: EVENT_STAR and a repo_data dict (the GitHub/GitLab API repository object) in stream_data, and each platform renders the repo natively — ported from Star-Daemon's connectors:
- Discord: rich embed (GitHub purple / GitLab orange / gold) with Repository, Description, Language, Stars, and Forks fields, owner-avatar thumbnail
- Bluesky: external card built from API metadata (no page scraping), avatar as the thumb
- Mastodon: text card appended to the status, avatar uploaded with alt text
- Matrix: "⭐ Starred on GitHub" heading with repository paragraphs
LLMManager.generate_validated()
The generate → guardrails → stricter-retry flow every daemon used to reimplement, now shared. Leniently ships the original message when the retry still has minor style issues (style problems beat silence), with hard vetoes for profanity and duplicates.
Typing
The package now ships py.typed (PEP 561) so mypy/pyright check against the library's own annotations. get_config() has overloads so a string default provably returns a string. A mypy gate runs in CI.
Security posture
- CodeQL analysis and OpenSSF Scorecard workflows, both SHA-pinned
- Dependabot for GitHub Actions and Python dependencies
Documentation site
The docs are now published to https://chiefgyk3d.github.io/hypeman/ (mkdocs-material), rebuilt on every push to main.
Full changelog: https://github.com/ChiefGyk3D/hypeman/blob/main/CHANGELOG.md
No breaking changes — 0.2.0 is fully additive over 0.1.x.