Releases: NexusPHP/carson
Releases · NexusPHP/carson
Release list
v1.0.0
Immutable
release. Only release title and notes can be modified.
What's Changed
Initial release.
Added
- Carson as a GitHub App distributed as a GitHub Action: each consumer registers their own App, supplies
app_id/private_keyas action inputs, and the action handles one workflow event per run through an in-process Probot. - Thirteen bundled subscribers, opted into per repository via
.github/carson.ymlon the default branch:- auto-labeler: labels PRs by path globs, title/body regex, or branch patterns, with optional sync mode.
- conflicts-notifier: comments on PRs with merge conflicts and resolves the comment when fixed.
- issue-intake: turns
repository_dispatchevents from an external system into labeled issues carrying a correlation marker. - lock-old-issues: locks closed issues inactive past a configurable age.
- no-response-closer: closes labeled items whose activity has gone stale past a threshold.
- pr-title-linter: validates PR titles against configurable regex rules as a check run.
- signed-commits: posts a check requiring every commit in a PR to be signed and verified.
- stale: marks inactive items stale, then closes them after a grace period.
- template-enforcer: flags issues and PRs whose description does not match the configured template.
- thanks: thanks contributors when someone else merges their PR.
- triage-labeler: labels PRs with their review state.
- webhook-notifier: POSTs a signed JSON callback to a configured URL when tracked issues close or reopen.
- welcome: greets first-time and returning contributors on PRs and issues.
- Scheduled (cron) dispatch for maintenance subscribers, with scans narrowed server-side through the GitHub search API.
repository_dispatchsupport for events pushed from outside GitHub.- Preflight permission check that fails the run with per-subscriber remediation when the consumer's App is under-permissioned, before any subscriber can 403.
- Registration filtering: only subscribers listed in
carson.ymlare attached at all. {{placeholder}}template interpolation for consumer-configured messages, including the universal{{app_name}}/{{app_slug}}/{{app_login}}context.- Hardening for
pull_request_targetconsumers: comment-marker forgery defenses and markdown escaping of attacker-controlled text. - Click-through App installer at https://nexusphp.github.io/carson/.
- Action inputs:
app_id,private_key,webhook_secret,log_level.
Full Changelog: https://github.com/NexusPHP/carson/commits/v1.0.0