Erica Portnoy
340f43235f
quote armhf
2026-04-17 11:59:08 -07:00
Erica Portnoy
7636bd5a66
get snap files with flat layout
2026-04-17 11:58:57 -07:00
Erica Portnoy
bdcd06b328
rerun nightly tests on failure
2026-04-16 19:23:02 -07:00
Erica Portnoy
2320d1ea60
remove choice as it is not allowed in workflow_call; add validation job
2026-04-16 19:23:02 -07:00
Erica Portnoy
94d83feca3
change type choice ordering
2026-04-16 19:23:02 -07:00
Erica Portnoy
a673937e46
export cflags to try to find augeas.h
2026-04-16 19:23:02 -07:00
Erica Portnoy
1632ff35d1
pass variables through better
2026-04-16 19:23:02 -07:00
Erica Portnoy
3c077568ff
add nightly tests
2026-04-16 19:23:02 -07:00
Erica Portnoy
e27756959c
Build all snaps on all archs including dns; test on arm64 and amd64
2026-04-16 19:23:02 -07:00
Erica Portnoy
5abc392030
migrate advanced tests to github actions
...
credentials for launchpad may or may not be working.
2026-04-16 19:23:02 -07:00
Erica Portnoy
736fecc85f
add slightly nicer label
2026-04-16 19:23:02 -07:00
Erica Portnoy
6b9184c1c6
user newer versions of standard actions to get rid of node deprecation warning
2026-04-16 19:23:02 -07:00
Erica Portnoy
14cd7451b4
remove combined tox steps file so we can see better names
2026-04-16 19:23:02 -07:00
Erica Portnoy
e9d9f76c68
cancel runs when a new commit is pushed to a pr branch
2026-04-16 19:23:02 -07:00
Erica Portnoy
62f6736222
add nicer names
2026-04-16 19:23:02 -07:00
Erica Portnoy
ea49e96532
split into setup/run/upload
2026-04-16 19:23:02 -07:00
Erica Portnoy
2f20c993a0
remove tox steps workflow, that won't work
2026-04-16 19:23:02 -07:00
Erica Portnoy
a9db62ebc4
stop failing fast
2026-04-16 19:23:02 -07:00
Erica Portnoy
489cef4bab
run all jobs even if one fails
2026-04-16 19:23:02 -07:00
Erica Portnoy
cb27f4677e
add eof newlines
...
pass secrets and env vars
set minimum permissions
move permissions to job level, switch to contents read
change name to AWS_TEST_FARM_PEM for consistency
move comments, remove azure pipelines on-pr file
match permissions
remove runs-on: self-hosted. why was that even there?
add shell:bash
the auto-converted decided python 3.1 == 3.10. come on.
put python version in quotes
move python version to matrix
copy from matrix into env
matrix must take a list
update matrix syntax
remove composite
put composite back
2026-04-16 19:23:02 -07:00
Erica Portnoy
a7af7be2d4
update gitignore
2026-04-16 19:23:02 -07:00
ohemorange and Erica Portnoy
bc6a84917a
Add workflow certbot/pr-test-suite
...
Add composite action azure_pipelines_templates_steps_tox_steps
Add composite action azure_pipelines_templates_steps_sphinx_steps
Add reusable workflow azure_pipelines_templates_jobs_standard_tests_jobs
rename files
2026-04-16 19:23:02 -07:00
Brad Warren and GitHub
3a5c92c6be
update base docker image ( #10620 )
...
fixes https://github.com/certbot/certbot/issues/10619
you can see docker builds and tests passing on this change at
https://dev.azure.com/certbot/certbot/_build/results?buildId=10360&view=results
i'm also creating a calendar event for us so we remember to keep this
updated in the future
i don't think this PR requires two reviews
2026-04-13 12:21:34 -07:00
Brad Warren and GitHub
0cc0844f2c
Release certbot 5.5.0 ( #10616 )
2026-04-07 14:29:50 -07:00
Erica Portnoy
fc91823888
Bump version to 5.6.0
2026-04-07 09:38:18 -07:00
Erica Portnoy
6a7443f654
Remove built packages from git
2026-04-07 09:38:18 -07:00
Erica Portnoy
82dda45352
Release 5.5.0
v5.5.0
2026-04-07 09:38:17 -07:00
Erica Portnoy
171cb29183
Update changelog for 5.5.0 release
2026-04-07 09:37:45 -07:00
0eb8af20a5
Add @ing mattermost notifications to release build successes and failures ( #10604 )
...
Fixes https://github.com/certbot/certbot/issues/10599
This approach creates a new azure stage Notify and posts to the
mattermost webhook directly from within azure.
The python script uses the azure rest api to get the status of the
Deploy stage specifically. This will be failed if it failed, or skipped
if a previous stage failed, or abandoned if it timed out.
We may want to remove the existing azure build failure notification when
this is merged. It can be deleted from
[here](https://dev.azure.com/certbot/certbot/_settings/serviceHooks )
(it's the one that says "Build release, status Failed"), although
personally I think it's fine to keep it.
History of alternate general approaches I investigated:
1. give azure a custom file to say a message that depends on the
requestedBy field. impossible. no custom messages at all, much less
dependant ones.
2. hook azure build completed webhook trigger directly to github
respository_dispatch event. impossible. azure will send data in a
[specific
format](https://learn.microsoft.com/en-us/azure/devops/service-hooks/events?view=azure-devops#build.complete ),
which is not the format [github
requires](https://docs.github.com/en/rest/repos/repos?apiVersion=2026-03-10#create-a-repository-dispatch-event ).
3. option 2, but put a custom server somewhere to translate them. or to
grab azure and send directly to mattermost. this is a horrible idea; no
one wants to be managing a production server with secrets on it.
4. a mattermost bot is just a special user account. the sender still has
to format the data so mm can read it.
5. block on migrating from azure to github actions. drawback: this will
likely take a while, and also we're not definitely doing it. see
https://github.com/certbot/certbot/issues/10581
6. smaller than 5; wrap release in a github action that calls azure
inside of it. and then if we end up migrating more, it should be pretty
smooth to move things inside of actions. drawback: this will probably
not integrate as smoothly, given we use the azure integration. I did not
investigate further.
7. there doesn't seem to be any sort of github actions event about
builds passing on a certain branch that we can check
8. just message mattermost directly from within the pipeline as a final
stage --> where I landed.
There's further discussion in the comments about others ways we tried to
structure the pipeline and get information from azure that's not super
necessary to read to review this PR.
Relevant links:
https://learn.microsoft.com/en-us/azure/devops/service-hooks/events?view=azure-devops#build.complete
https://learn.microsoft.com/en-us/azure/devops/service-hooks/services/webhooks?view=azure-devops#resource-details-to-send
https://learn.microsoft.com/en-us/azure/devops/pipelines/build/variables?view=azure-devops&tabs=yaml#agent-variables
https://learn.microsoft.com/en-us/azure/devops/pipelines/process/conditions?view=azure-devops&tabs=yaml#job-status-functions
https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows
https://docs.github.com/en/rest/repos/repos?apiVersion=2026-03-10#create-a-repository-dispatch-event
https://docs.github.com/en/webhooks/webhook-events-and-payloads#repository_dispatch
Results of tests with the latest code are here:
https://dev.azure.com/certbot/certbot/_build/results?buildId=10309&view=results
https://dev.azure.com/certbot/certbot/_build/results?buildId=10310&view=results
https://dev.azure.com/certbot/certbot/_build/results?buildId=10311&view=results
Plus the mattermost messages did get sent.
---------
Co-authored-by: Brad Warren <bmw@users.noreply.github.com >
2026-04-02 14:14:27 -07:00
Brad Warren and GitHub
08c2354f46
update poetry ( #10615 )
...
this is in response to
https://github.com/certbot/certbot/security/dependabot/126
as you can see by examining the github status checks on this PR, i ran
the full test suite and everything passed
i also don't think this PR requires two reviews
2026-04-02 14:11:07 -07:00
ohemorange and GitHub
3d803821b7
Repin dependencies ( #10611 )
2026-03-27 09:03:31 -07:00
6f1c0b0abd
merge certbot-apache and certbot-nginx into certbot ( #10522 )
...
based on the suggestion @bmw made in #10484 , this moves nearly
everything from `certbot-apache` and `certbot-nginx` into subdirectories
in `certbot/src/certbot/_internal`, and corresponding "extra"
dependencies are made for the certbot distribution. in their place,
entrypoint shims are made in the old distributions.
this way, installing `certbot[nginx]` will pull in the extra
dependencies needed for the nginx code, and also pull in the shim in
`certbot-nginx`, letting our plugin discovery system work just as it did
before. ditto for apache.
note that this doesn't yet deprecate anything, which was one of the
primary goals of the original issue -- i spun out that work into #10521
fixes #10484
---------
Co-authored-by: Brad Warren <bmw@users.noreply.github.com >
Co-authored-by: ohemorange <erica@eff.org >
2026-03-23 18:09:04 -07:00
ohemorange and GitHub
9599364837
Use python warning filters from pytest.ini during integration tests ( #10602 )
...
Fixes https://github.com/certbot/certbot/issues/10180 .
So first of all, the core issue here is that [pyca deliberately
chose](https://github.com/pyca/cryptography/blob/ec80c1c2894320d30fd674ea2c6103d91b4e777e/src/cryptography/utils.py#L15-L18 )
to override the default python functionality and make deprecation
warnings appear by default. This isn't common. If they'd actually used a
`DeprecationWarning`, it wouldn't have shown up to users, at least. That
being said, we should still try to catch it, as we do in fact want to
know about deprecation warnings for our own updates.
To do that, this PR searches upwards for a `pytest.ini` file from the
file's location. If found, it reads the warnings from the file, and
passes them using the `PYTHONWARNINGS` env variable. It also explicitly
sets warnings to `error` always in case we can't find the `pytest.ini`,
and ignores the subsequent unverified-https-on-localhost warning. It
also fixes a warning in our test nginx config that seemed reasonable to
address.
I tested this by adding a temporary warning, which I then removed, but
since it turned out there were two other warnings, that wasn't actually
necessary.
Options I considered and rejected:
- Switch from `atexit` to calling `main` directly. To do this, we'd have
to switch our `main` function to something like a try-finally. That's
complicated by the fact that we call `atexit` from other places in the
code. Also, `exc_info` isn't availabe in `finally` while it is in
`at_exit`, so it's not as versatile. But mostly if we wanted to do this,
we'd have to implement a custom atexit handler, basically, and that
seems worse than this option.
- Looking into pytest-forked. It's apparently buggy and not being
maintained. Not even sure this is what it's for anyway.
- Multiple
[-W](https://docs.python.org/3/using/cmdline.html#cmdoption-W ) options
can be given instead of an env variable. The env version seemed cleaner.
- More closely mimicking [how pytest finds ini
files](https://docs.pytest.org/en/stable/reference/customize.html#finding-the-rootdir ).
It seemed unnecessary to me.
Potential drawbacks:
- If we move or rename the `pytest.ini` file and for some reason don't
do a reasonable grep for `pytest.ini`, we will no longer catch any
additional `ignore`s in there. But imo we're likely to do that grep, and
also a missing ignore will then show up when we run the tests.
2026-03-20 14:40:31 -07:00
Brad Warren and GitHub
9ed92009db
deprecate certbot.ocsp ( #10584 )
...
this is part of https://github.com/certbot/certbot/issues/10517
to update this description in response to the discussion below, i'd
recommend reviewing this PR by commit. the first commit just moves
ocsp.py under _internal making no other changes while the second commit
fixes everything else up. the diff really isn't as big here as it looks
2026-03-19 15:14:10 -07:00
ohemorange and GitHub
b42b986fb7
List certbot-dns-eurodns as a third-party plugin ( #10605 )
...
Fixes https://github.com/certbot/certbot/issues/10603
The link to the github repo is 404'ing. I've asked for a current link,
but the pypi link seems fine to me also. It was released yesterday so it
does seem to still be in active development.
<img width="910" height="214" alt="Screenshot 2026-03-18 at 10 30 19 AM"
src="https://github.com/user-attachments/assets/25208402-ebd1-4d9e-8c46-f1a3f5b83ec0 "
/>
2026-03-18 10:52:14 -07:00
James Moss and GitHub
26a0b0295b
Logo & Wording for DigitalOcean Open Source Sponsorship in Readme.rst ( #10601 )
...
In exchange for participating in Open Source Sponsorship, DigitalOcean
has assembled a guide. This commit should bring the readme in line with
the provided guide.
https://opensource.nyc3.cdn.digitaloceanspaces.com/attribution/index.html
2026-03-17 13:33:36 -07:00
Brad Warren and GitHub
e9f3c986a2
update manual docs for IP certs ( #10596 )
...
i noticed this when reviewing jsha's upcoming blog post
this probably should have been done as part of
https://github.com/certbot/certbot/pull/10544 , but we forgot to do it
then
i don't think this PR requires two reviews
2026-03-11 12:51:40 -07:00
ohemorange and GitHub
fa0b0b1057
Merge pull request #10594 from certbot/candidate-5.4.0
...
Candidate 5.4.0
2026-03-10 12:15:27 -07:00
Will Greenberg
8ebbe24190
Bump version to 5.5.0
2026-03-10 10:47:29 -07:00
Will Greenberg
1ff7e2032a
Remove built packages from git
2026-03-10 10:47:29 -07:00
Will Greenberg
95c004cb96
Release 5.4.0
v5.4.0
2026-03-10 10:47:28 -07:00
Will Greenberg
564a7b70d6
Update changelog for 5.4.0 release
2026-03-10 10:46:56 -07:00
ohemorange and GitHub
c31974128b
Add thanks section to readme; thank digital ocean ( #10592 )
...
Fixes https://github.com/certbot/certbot/issues/10580
Direct link to preview of updated README:
https://github.com/certbot/certbot/blob/47786891acc4cb5031d5934de76399620c08a013/certbot/README.rst#thanks
2026-03-06 17:58:31 -08:00
ohemorange and GitHub
e6efb5c6d3
Add notice about AI generated code policy to pull request checklist ( #10590 )
2026-03-05 11:02:22 -08:00
ohemorange and GitHub
15e73753a6
Fix link in docker readme ( #10582 )
...
The link in the docker README is no longer accurate, we've changed the
headings on the website. This updates the README to match.
2026-02-25 21:17:09 -08:00
ff281d48a8
Improve the error message when certbot renew is used with the -d option ( #10225 )
...
Co-authored-by: Brad Warren <bmw@eff.org >
2026-02-13 23:55:35 +00:00
ohemorange and GitHub
4c61a450d4
Reset mock call count using reset_mock since new thread-safe implementation means it can no longer just be set to 0 ( #10576 )
...
This should fix our failing tests.
Python 3.14.3 has the following in its changelog:
> [gh-142651](https://github.com/python/cpython/issues/142651 ):
[unittest.mock](https://docs.python.org/3/library/unittest.mock.html#module-unittest.mock ):
fix a thread safety issue where
[Mock.call_count](https://docs.python.org/3/library/unittest.mock.html#unittest.mock.Mock.call_count )
may return inaccurate values when the mock is called concurrently from
multiple threads.
As a result, we have to call `reset_mock()` instead of using
`.call_count = 0`. See example
[here](https://github.com/matplotlib/matplotlib/pull/31153 ).
Tests on my machine showing that this change fixes things, and it's the
only place to fix:
```bash
$ brew upgrade pyenv
$ pyenv install 3.14.3
$ pyenv global 3.14.3
$ tools/venv.py
$ source venv/bin/activate
$ pytest certbot -k "test_rollback_too_many"
====================================================================== test session starts =======================================================================
platform darwin -- Python 3.14.3, pytest-9.0.2, pluggy-1.6.0
rootdir: /Users/erica/certbot
configfile: pytest.ini
plugins: anyio-4.12.1, xdist-3.8.0, cov-7.0.0
collected 1039 items / 1038 deselected / 1 selected
certbot/src/certbot/_internal/tests/reverter_test.py . [100%]
=============================================================== 1 passed, 1038 deselected in 2.94s ===============================================================
$ git grep 'call_count = 0'
$ git checkout main
$ pytest certbot -k "test_rollback_too_many"
====================================================================== test session starts =======================================================================
platform darwin -- Python 3.14.3, pytest-9.0.2, pluggy-1.6.0
rootdir: /Users/erica/certbot
configfile: pytest.ini
plugins: anyio-4.12.1, xdist-3.8.0, cov-7.0.0
collected 1039 items / 1038 deselected / 1 selected
certbot/src/certbot/_internal/tests/reverter_test.py F [100%]
============================================================================ FAILURES ============================================================================
_______________________________________________________ TestFullCheckpointsReverter.test_rollback_too_many _______________________________________________________
self = <certbot._internal.tests.reverter_test.TestFullCheckpointsReverter testMethod=test_rollback_too_many>
mock_logger = <MagicMock name='logger' id='4463351456'>
> ???
E AssertionError: assert 2 == 1
E + where 2 = <MagicMock name='logger.warning' id='4463351792'>.call_count
E + where <MagicMock name='logger.warning' id='4463351792'> = <MagicMock name='logger' id='4463351456'>.warning
certbot/src/certbot/_internal/tests/reverter_test.py:363: AssertionError
==================================================================== short test summary info =====================================================================
FAILED certbot/src/certbot/_internal/tests/reverter_test.py::TestFullCheckpointsReverter::test_rollback_too_many - AssertionError: assert 2 == 1
=============================================================== 1 failed, 1038 deselected in 0.48s ===============================================================
$ git grep 'call_count = 0'
certbot/src/certbot/_internal/tests/reverter_test.py: mock_logger.warning.call_count = 0
```
2026-02-13 13:08:06 -08:00
Jacob Hoffman-Andrews and GitHub
59a631f21a
webroot: add IP address support ( #10543 )
...
Part of #10346
2026-02-12 11:00:03 -08:00
Brad Warren and GitHub
8ae17fd174
update dns-azure URL ( #10573 )
...
until sometime in the last year,
https://github.com/binkhq/certbot-dns-azure redirected to
https://github.com/terricain/certbot-dns-azure according to
https://web.archive.org/web/20250901000000*/https://github.com/binkhq/certbot-dns-azure .
since then, that redirect was broken/removed
this has [caused
confusion](https://github.com/certbot/certbot/pull/8727#issuecomment-3880163261 )
and since [terricain expressed interest in their plugin being
listed](https://github.com/certbot/certbot/pull/8727#issuecomment-815287041 ),
let's fix up that link
2026-02-10 14:06:19 -08:00
ohemorange and GitHub
d4681f9a49
Merge pull request #10571 from certbot/candidate-5.3.1
...
update files from 5.3.1 release
2026-02-10 11:39:30 -08:00