Skip to content

v0.1.8

Latest

Choose a tag to compare

@github-actions github-actions released this 22 Sep 14:31
8913fb2
v0.1.8: per-project event filter

A webhook delivers every event to the project URL, so the server ran the
script on push alone. That excludes workflow_dispatch, which is how a
manual deploy reaches the hook: such a request passes the HMAC check and
returns 200 with no run, so the caller reads a success and nothing
deploys.

Each project now lists the events that run its script. The key defaults
to [push], so an existing config keeps its behavior. A project deployed
by hand lists workflow_dispatch alone, which also stops a push from
reaching it.

Dependencies move to their current releases. Four majors change the API.
hmac 0.13 and sha2 0.11 take new_from_slice from KeyInit. rand 0.10
drops RngCore from the root, so the job id comes from rand::random. A
known body hashes to the same digest as before the bump, and a forged
signature still gets a 400.