You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
v0.1.8: per-project event filter
A webhook delivers every event to the project URL, so the server ran the
script on push alone. That excludes workflow_dispatch, which is how a
manual deploy reaches the hook: such a request passes the HMAC check and
returns 200 with no run, so the caller reads a success and nothing
deploys.
Each project now lists the events that run its script. The key defaults
to [push], so an existing config keeps its behavior. A project deployed
by hand lists workflow_dispatch alone, which also stops a push from
reaching it.
Dependencies move to their current releases. Four majors change the API.
hmac 0.13 and sha2 0.11 take new_from_slice from KeyInit. rand 0.10
drops RngCore from the root, so the job id comes from rand::random. A
known body hashes to the same digest as before the bump, and a forged
signature still gets a 400.