Skip to content

Releases: PastureStack/webhook-automation-service

v0.10.3

Choose a tag to compare

@chen21019 chen21019 released this 27 Sep 06:09
fbcc0ca

Webhook Automation Service v0.10.3

This patch release makes the Receiver schema reflect the authenticated project's actual write permissions. Owners and members retain create/delete capabilities; restricted and read-only roles receive read-only Receiver methods, matching the existing API enforcement. Schema responses are private and non-cacheable so a writable capability response cannot be reused for another role.

The change covers both /v1-webhooks/schemas and /v1-webhooks/schemas/receiver without changing Receiver data, credentials, routes, or project isolation. Regression tests check both endpoints, mixed roles, and concurrent requests against a shared schema.

Merged source: fbcc0ca.
Linux archive SHA-256: 6babbc18cee9a192009cfadcd143e6b9a5f2b550c4dc419781f3e3657caa022a.
Security release gate passed on the merged commit, including deterministic packaging, race/integration tests, binary vulnerability analysis, and source/artifact scans. Server 8080 UI acceptance is a separate integration gate.

Webhook Automation Service v0.10.2

Choose a tag to compare

@chen21019 chen21019 released this 27 Sep 04:36
7e8bdcd

Webhook Automation Service v0.10.2

This release closes project and object-type authorization gaps in webhook receiver management and execution:

  • A project-scoped management request must carry the matching trusted control-plane project header.
  • Read-only roles are enforced when the trusted role header contains multiple roles.
  • Receiver list, lookup, delete, name checks, and key or signed-JWT execution accept only webhookReceiver objects.
  • Regression tests cover cross-project access, unrelated generic-object kinds, and valid receiver execution.

The release was built from merged commit 7e8bdcd4b6b9456116a4b2e2c9c40e501b456366. The Linux security-release gate completed successfully, including unit and integration tests, deterministic packaging, vulnerability analysis, and artifact scans. This component release alone does not claim Server 8080 deployment or browser acceptance; those are separate Server integration gates.

Webhook Automation Service v0.10.1

Choose a tag to compare

@chen21019 chen21019 released this 26 Aug 02:00

Go 1.27 runtime refresh with reproducible Linux amd64 artifact, SBOM, source/artifact Trivy evidence, and govulncheck evidence. The security release gate passed at commit dac77b0.