Skip to content

v1.4.0

Latest

Choose a tag to compare

@github-actions github-actions released this 07 Oct 23:26
· 1 commit to main since this release

Features

  • receipt: read the integration key for receipt secret from stdin with --key - (b259aeb)
  • action: add an encrypt input so a missing key fails the step instead of sending readable text (9ab1760)
  • action: add e2e-key and acknowledgement inputs, keep sealed text out of the log (8b3cc70)
  • receipt: repeat notifications until acknowledged and follow or cancel their receipts (0e48e00)
  • callback: derive the whsec_ callback signing secret from an integration key (e437df3)
  • e2e: encrypt notification text with a configured key and add the e2e commands (d7d8bb9)
  • config: resolve an e2e_key from PUSHWARD_E2E_KEY or the config file (1d12b9f)
  • e2e: seal and open pw1 envelopes, with the shared test vectors (0f06705)

Fixes

  • receipt: cancel by every --tag given, not only the last (f5b008f)
  • action: mask the callback secret receipt secret prints, whichever key it came from (e79840c)
  • action: fail when encryption was asked for but the command cannot encrypt (3ce1e8d)
  • e2e: read a key pasted over several lines whole when e2e import prompts (50f3be0)
  • action: also mask the callback secret without its whsec_ prefix (362ea5b)
  • action: refuse e2e and auth even when flags come before the command (60a0d33)
  • e2e: check pre-sealed envelopes and refuse readable text next to them (d0b4f8c)
  • e2e: refuse an encrypted field that is not an envelope instead of sending in the clear (ae3bf95)
  • deps: update all non-major dependencies (#6) (81ecf7f)

Documentation

  • skill: notification send encrypts too (65930e1)
  • collapse-id replaces only sends from the same key, name notification send for e2e-key (4290666)
  • e2e: name the app's End-to-End Encryption settings row (f36bdac)
  • receipt: the 25-alert cap is per account, cancel by tag per key (fd4504d)
  • warn that CLI 1.3.x and earlier drop a stored e2e_key on login and logout (222464a)
  • cover acknowledged alerts, receipts and the e2e-key input (e3dfedd)

Tests

  • e2e: refuse an envelope whose last base64url character has unused bits set (bafeba5)

Maintenance

  • spec: refresh openapi.yaml with the acknowledging-tap wording (4c42f5b)
  • spec: refresh openapi.yaml with encrypted notifications and notification receipts (0b94f61)
  • release: write to pushward-action and homebrew-tap with the mac-lucky-ci app (079f318)
  • skills: do not persist checkout credentials (9dddc76)
  • deps: pin dependencies (#7) (6bc2d20)

Full changelog: v1.3.0...v1.4.0