Skip to content

v0.8 W66 — Alert routing adapters and activity/event webhooks #215

Description

@ammarheidari

Status

ACTIVE — shared W62 event/telemetry contracts are stable; provider-specific notifier work may proceed independently of W65.

Scope

  • notifier adapter model for Webhook, Email, Slack, Teams, Telegram and PagerDuty;
  • activity/event webhook subscriptions;
  • typed destination profiles, event filters and safe payload projections;
  • finite retry/backoff/deduplication/delivery evidence;
  • provider-specific capability/error mapping.

Safety

  • no arbitrary per-request destination URL;
  • server-side secret references only;
  • SSRF protection, HTTPS policy, redirect restrictions and destination allowlist;
  • bounded payload size/rate/fanout/retry lifetime;
  • protected record/query/secret data excluded unless separately and explicitly admitted.

Authority: scope #208; tracker #209; W61/W62 complete.

Activation boundary

Initial implementation should establish typed notifier/provider contracts, bounded delivery state and destination-validation/SSRF policy before enabling any real outbound adapter. No generic HTTP proxy, caller-controlled URL, secret-bearing event payload or unlimited retry loop is admitted.

Webhook runtime slice — COMPLETE / PROTECTED-MAIN

  • PR feat(notifications): add W66 bounded webhook runtime #255: bounded webhook notification runtime;

  • final exact head: c92ed6d3fcbc6fb622a535f4c3092cbe1f27ad6d;

  • configured webhook profiles only;

  • fixed safe event projection;

  • endpoint resolution/pinning and opaque credential binding preserved;

  • no generic HTTP proxy, arbitrary request URL/headers, retry loop, durable worker, subscriptions or API/UI activation;

  • Email/Slack/Teams/Telegram/PagerDuty remain future slices.

  • rebased without semantic changes onto protected-main cb2519bc853ed21da5b3e310530c6d062324ca20; exact-head CI and Codex are clean; fresh CODEOWNER approval remains.

  • protected-main merge baseline: 67edb7950d09020bbb03e5441df932ce7b0f0a0f;

  • rebased exact-head Quality/v03/v04/Dependency/Release/CodeQL: SUCCESS;

  • Codex: CLEAN;

  • CODEOWNER approval admitted;

  • bounded webhook runtime is now protected-main admitted.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions