Repository navigation
v0.3.1: per-platform duplicate detection
Fixed
- Duplicate detection is now per platform. The recently-posted history
was one list shared by every platform, so the Matrix, Bluesky and Mastodon
announcements for the same video (more than 80% of their words shared with
the Discord one) were rejected as "Duplicate of a recently posted message"
and fell back to the template. Measured on Boon-Tube-Daemon over 15
uploads, Mastodon passed 7 of 15 for this reason.is_duplicate_message()
andadd_to_message_cache()take an optionalplatform(omitted means the
sharedgenericbucket),generate_validated()andapply_guardrails()
pass theplatformthey already receive, and the same text posted twice to
one platform is still rejected. Threshold, window size and
LLM_ENABLE_DEDUPLICATIONare unchanged; existing callers need no change.
Changed
- CI, security scanning and the PyPI release now call the reusable workflows
inChiefGyk3D/git-your-ship-together(v1.6.3) instead of hand-written
jobs: oneCI greengate per workflow, egress blocked to measured hosts,
Semgrep and gitleaks added, build provenance andSHA256SUMSattached to
each GitHub release.codeql.ymlandscorecard.ymlare folded into
security.yml. Package contents are unchanged.
Also in this release: 0.3.0 (never released on its own)
Added
- Image attachments on Bluesky and Mastodon: pass
stream_data={'images': [{'data': b'...', 'alt': '...'}, ...]}(or
{'url': ..., 'alt': ...}to have the picture fetched for you) and the
post carries them as pictures of their own, each with its own alt text —
as an images embed on Bluesky, as media attachments on Mastodon. Up to
four per post; a picture that cannot be resolved or uploaded is logged and
left out rather than blocking the text. The media type is sniffed from
the bytes, so a chart rendered in memory needs no naming. This is what
SolarStorm Scout needs for its D-RAP map, aurora oval and GOES X-ray
chart, and is distinct fromthumbnail_url, which still drives link
cards for announcements about a URL.
attached_images()andsniff_image_mime()are exported from
hypeman_social.social.basefor platforms that want the same rules.
Changed
- Mastodon no longer demands an OAuth client id/secret. An access
token and the instance URL are enough, which is how Mastodon.py itself
works and how most bots are set up (Preferences → Development → copy the
token). A full client pair is still passed through when both are present;
a lone half of the pair is ignored with a warning. - Doppler config reads are cached.
get_config()used to open a Doppler
client and fetch the whole project on every call — andBaseLLMalone
makes about twenty calls while being constructed — so a daemon with
Doppler enabled could trip the rate limit reading settings that never
change. Plain settings now read through the same once-per-process cache
as credentials (reset_secret_cache(), now exported from
hypeman_social.config, forces a re-read). One consequence: with
DOPPLER_CONFIGunset, settings and secrets now both default to the
prdconfig, where settings alone used to default todev. hypeman_social.__version__now matches the package version (it had
been left at 0.1.0).
Callers
The daemons pin hypeman-social==0.2.0; move them to 0.3.1. The 0.3.0 changes include image attachments and token-only Mastodon auth, so each daemon's CI must pass before it is deployed.