Sometimes these releases take time. Cherish it.
🛡️ What's Unmessed
Caution
There was a small command injection risk in prior versions. I consider it very low because of the specifics of the action use case. But still, do upgrade, okay?
@illera88💰 fixed this template injection bug in #37 by passing inputs via env vars.
See GHSA-gj76-h2ch-5m76 for more detail that was first reported by @Corbynx010💰 while I was at EuroPython.
✨ What's Improved
I did a bunch of internal refactoring including hints of what @max-sixty💰 reported in #23. And took a small patch of @krokofant💰 in. This involved a bunch of preparatory infra work with testing infra.
One notable improvement is that now thanks to @tomasr8💰's and @hugovk💰's UX suggestions in #31, the gate status output is colored in the console and should be easier to scan in the log output per line. They entries now have leading ✓/❌ acceptance marks and the actual incoming job outcomes are labeled with 🟢/🔴/⬜/⚫.
🐛 What's Fixed
The job-statuses summary could print "Some of the allowed to be skipped jobs did not succeed" based on the wrong condition — it's now tied to allowed-skips as intended, not allowed-failures.
💪 New Contributors
- @Corbynx010💰 lurked in GHSA-gj76-h2ch-5m76 before everyone else 😉
- @illera88 made their first contribution in #37 and GHSA-gj76-h2ch-5m76
- @krokofant and @max-sixty first contributed in #23
- @tomasr8 and @hugovk in #31
🪞 Full Diff: v1.2.2...v1.3.0
🧔♂️ Release Manager: @webknjaz 🇺🇦
💬 Discuss on Bluesky 🦋, on Mastodon 🐘 and on GitHub.