Check every destination, including hosts without a dot, and fix CI, pins and imports past the plugin surface #1
Labels
No labels
bug
documentation
enhancement
security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo-apprise#1
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found in the 2026-09-15 audit of the plugin repositories.
1. Hostnames without a dot skip the destination check
src/postulo_apprise/notifier.py:34: the_HOSTNAMEregex requires at least one dot.:74-80:destination_ofreturnsNonefor any host that doesn't match, and:136-140then skipshttp.check_destination.json://redis:6379/,form://paperless:8000/andgotify://internal/(Docker service names and single-label LAN hosts) are never checked.Fix:
json,xml,form) throughapi.client, so the check and the connection are one act.json://redis:6379/refused with private destinations off.2. CI cannot pass
.forgejo/workflows/ci.yml:39,41runsscripts/compile_messages.py, and the repository has noscripts/directory.Fix: use the
postulo-messagescompile command, and add a tag-triggered job runninguv run pytest -m release.3. The version pin is a label
__version__is0.1.0whilepyproject.tomlsays0.3.0.maincommit that is not on0.3.0.Fix: version from
importlib.metadata, pin the core tov0.3.0, and fail instead of skipping under-m release.4. Imports past
postulo.plugins.apinotifier.py:26-27importspostulo.plugins.httpandpostulo.plugins.base. MoveFieldSpec/TestResultandclienttoapinow. MoveDestinationRefused/check_destinationonce the core exposes them (core plugin-surface issue (postulo/postulo#229)). Add the surface AST check to CI.