Sometimes these releases take time. Cherish it.
π‘οΈ What's Unmessed
Caution
There was a small command injection risk in prior versions. I consider it very low because of the specifics of the action use case. But still, do upgrade, okay?
@illera88π° fixed this template injection bug in #37 by passing inputs via env vars.
See GHSA-gj76-h2ch-5m76 for more detail that was first reported by @Corbynx010π° while I was at EuroPython.
β¨ What's Improved
I did a bunch of internal refactoring including hints of what @max-sixtyπ° reported in #23. And took a small patch of @krokofantπ° in. This involved a bunch of preparatory infra work with testing infra.
One notable improvement is that now thanks to @tomasr8π°'s and @hugovkπ°'s UX suggestions in #31, the gate status output is colored in the console and should be easier to scan in the log output per line. They entries now have leading β/β acceptance marks and the actual incoming job outcomes are labeled with π’/π΄/β¬/β«.
π What's Fixed
The job-statuses summary could print "Some of the allowed to be skipped jobs did not succeed" based on the wrong condition β it's now tied to allowed-skips as intended, not allowed-failures.
πͺ New Contributors
- @Corbynx010π° lurked in GHSA-gj76-h2ch-5m76 before everyone else π
- @illera88 made their first contribution in #37 and GHSA-gj76-h2ch-5m76
- @krokofant and @max-sixty first contributed in #23
- @tomasr8 and @hugovk in #31
πͺ Full Diff: v1.2.2...v1.3.0
π§ββοΈ Release Manager: @webknjaz πΊπ¦
π¬ Discuss on Bluesky π¦, on Mastodon π and on GitHub.