notifications.yml is invoked via workflow_call from the caller
workflow, so inside this job gitea.event_name reports "workflow_call"
rather than the top-level event (push/schedule/...) that actually
started the run. Comparing that against the Actions API's per-run
event field (which reports the real trigger) never matched, so
previous_conclusion always stayed "unknown" and healed notifications
never fired. Now the current run's real event is captured from the API
response itself and used for the comparison, falling back to
gitea.event_name only if the current run isn't found in the scanned
history.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Gitea's PyPI registry only resolves /simple/<package>/, not the bare
/simple/ index root, so the v1.11.2 probe added to give visible
diagnostics for the private-index setup step was always 404ing even
when the index and credentials were correct. This broke installs of
private Python packages during builds. The probe now only fails hard
on 401/403 (auth rejected) or an unreachable host; a plain 404 is
logged and left to pip's own resolution to confirm.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
python:3.14-slim has no Node.js so actions/checkout@v4 fails with
'node: executable file not found in PATH'. Switch to the same
gitea_runner_python314 custom image used by python-checks.yml which
has both Python 3.14 and Node.js. Drop the python_version input as it
no longer drives the container selection.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Dedicated security-only workflow using python:VERSION-slim.
Runs Bandit (or any security tool) without pytest or coverage.
Supports python_version, install_command, security_command,
and working_directory inputs with sensible defaults.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Notification job had no checkout step so git log always failed,
producing "Commit info unavailable". Now uses the existing
API_GITEA_TOKEN and gitea.sha context to fetch the commit message
from the Gitea API directly.
Also raises default coverage threshold in python-checks to 80%.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>