Releases: max-lt/github-hook-rs
Releases · max-lt/github-hook-rs
Release list
v0.1.8
v0.1.8: per-project event filter A webhook delivers every event to the project URL, so the server ran the script on push alone. That excludes workflow_dispatch, which is how a manual deploy reaches the hook: such a request passes the HMAC check and returns 200 with no run, so the caller reads a success and nothing deploys. Each project now lists the events that run its script. The key defaults to [push], so an existing config keeps its behavior. A project deployed by hand lists workflow_dispatch alone, which also stops a push from reaching it. Dependencies move to their current releases. Four majors change the API. hmac 0.13 and sha2 0.11 take new_from_slice from KeyInit. rand 0.10 drops RngCore from the root, so the job id comes from rand::random. A known body hashes to the same digest as before the bump, and a forged signature still gets a 400.
v0.1.7
v0.1.7: mask webhook secrets in logs Secret newtype (serde-transparent String holder) with a custom Debug that prints *** — the startup Config dump and the per-request debug log no longer leak the webhook secrets. README bumped to v0.1.7.
v0.1.6
v0.1.6: matrix-build amd64 + arm64 binaries
The CI was only producing an amd64 binary, which fails with 'Exec
format error' on ARM hosts (Scaleway VPS, Raspberry Pi, etc.).
Workflow changes:
- Matrix over { ubuntu-latest (amd64), ubuntu-24.04-arm (arm64) }
- Upload artifacts per arch, then a release job attaches all of them
- Replace the deprecated actions/create-release@v1 +
upload-release-asset@v1 (archived by GitHub) with
softprops/action-gh-release@v2
- Release assets: github-hook-linux-amd64, github-hook-linux-arm64, and
github-hook (=amd64 alias, kept for backward compatibility)
README: install snippet now shows both arch URLs.
Release v0.1.5
Release v0.1.5: Unix socket support + deps refresh
Features:
- New SOCKET_PATH env var. When set, the server binds a Unix domain
socket (chmod 0660) instead of a TCP port. Takes precedence over PORT.
Lets a reverse proxy (cloudflared, nginx, …) handle network exposure
without opening a port on the host.
- README documents the systemd unit (RuntimeDirectory, UMask) and
example ingress configs for cloudflared and nginx.
Dependencies:
- serde_yaml (archived) → serde_yml 0.0.12 (maintained fork, same API)
- rand 0.8 → 0.9 (rand::thread_rng() renamed to rand::rng())
- actix-web 4.5 → 4.13, env_logger 0.11.3 → 0.11.10, plus minor bumps
- Drop unused 'small_rng' feature flag from rand
- Pin to minor versions in Cargo.toml so patches roll in via cargo update
Cleanup (clippy strict, all-targets -D warnings):
- .split('/').last() → .next_back()
- !x.is_ok() → x.is_err()
- .expect(format!(...).as_str()) → .unwrap_or_else(|e| panic!(...)),
preserving the underlying error in the message
- Reap the child process after the stdout/stderr threads join, so it
doesn't linger as a zombie (clippy::zombie_processes)
Release v0.1.4
Update dependencies (v0.1.4)