feat(alerts): add webhook2 channel with custom headers and timeout - #535
Conversation
Adds a new built-in alert channel 'webhook2' that accepts a JSON-encoded
target string {url, headers?, timeoutMs?}, enabling per-config custom HTTP
headers and timeout overrides without touching the existing webhook channel.
- src/alerts/webhook2.ts: new channel implementation with parseWebhook2Target()
for robust validation, custom header merging, configurable timeout (default
10 000 ms), and identical HMAC-SHA256 signing to the original webhook channel
- src/alerts/builtins.ts: additive-only change — registers 'webhook2' alongside
the existing five channels; original webhook registration is untouched
- tests/alerts/webhook2.test.ts: 32 TDD tests covering target parsing, HTTP
request shape, custom headers, HMAC signing, timeout override, success/error
handling, and registry integration
- tests/alerts/builtins.test.ts: updated channel-count and signing assertions to
reflect the new six-channel registry; added webhook2 delegation and
missingTargetError tests
|
Warning Review limit reached
Next review available in: 23 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (4)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@marvelousjeremiah24 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
|
| GitGuardian id | GitGuardian status | Secret | Commit | Filename | |
|---|---|---|---|---|---|
| - | - | Generic High Entropy Secret | ded54f4 | tests/commands/guard-cli-export-import.test.ts | View secret |
🛠 Guidelines to remediate hardcoded secrets
- Understand the implications of revoking this secret by investigating where it is used in your code.
- Replace and store your secret safely. Learn here the best practices.
- Revoke and rotate this secret.
- If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.
To avoid such incidents in the future consider
- following these best practices for managing and storing secrets including API keys and other credentials
- install secret detection on pre-commit to catch secret before it leaves your machine and ease remediation.
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.
|
Merged into |
Adds a new built-in alert channel 'webhook2' that accepts a JSON-encoded target string {url, headers?, timeoutMs?}, enabling per-config custom HTTP headers and timeout overrides without touching the existing webhook channel.
What does this PR do?
Why?
Does this touch secret-key handling or transaction submission?
Checklist
npm test)npx tsc --noEmit)npm run lint)console.login core logic