Releases: PastureStack/webhook-automation-service
Release list
v0.10.3
Webhook Automation Service v0.10.3
This patch release makes the Receiver schema reflect the authenticated project's actual write permissions. Owners and members retain create/delete capabilities; restricted and read-only roles receive read-only Receiver methods, matching the existing API enforcement. Schema responses are private and non-cacheable so a writable capability response cannot be reused for another role.
The change covers both /v1-webhooks/schemas and /v1-webhooks/schemas/receiver without changing Receiver data, credentials, routes, or project isolation. Regression tests check both endpoints, mixed roles, and concurrent requests against a shared schema.
Merged source: fbcc0ca.
Linux archive SHA-256: 6babbc18cee9a192009cfadcd143e6b9a5f2b550c4dc419781f3e3657caa022a.
Security release gate passed on the merged commit, including deterministic packaging, race/integration tests, binary vulnerability analysis, and source/artifact scans. Server 8080 UI acceptance is a separate integration gate.
Webhook Automation Service v0.10.2
Webhook Automation Service v0.10.2
This release closes project and object-type authorization gaps in webhook receiver management and execution:
- A project-scoped management request must carry the matching trusted control-plane project header.
- Read-only roles are enforced when the trusted role header contains multiple roles.
- Receiver list, lookup, delete, name checks, and key or signed-JWT execution accept only
webhookReceiverobjects. - Regression tests cover cross-project access, unrelated generic-object kinds, and valid receiver execution.
The release was built from merged commit 7e8bdcd4b6b9456116a4b2e2c9c40e501b456366. The Linux security-release gate completed successfully, including unit and integration tests, deterministic packaging, vulnerability analysis, and artifact scans. This component release alone does not claim Server 8080 deployment or browser acceptance; those are separate Server integration gates.
Webhook Automation Service v0.10.1
Go 1.27 runtime refresh with reproducible Linux amd64 artifact, SBOM, source/artifact Trivy evidence, and govulncheck evidence. The security release gate passed at commit dac77b0.