Stacked on !238.
Added: mr.closed, mr.reviewed, mr.edited, mr.retargeted,
issue.edited, issue.labeled, issue.assigned, issue.milestoned,
mr.milestoned, release.deleted. mr close and issue edit also
notify participants now, which they did not.
EventKinds is the published list. TestEventKindsAreRecorded reads the
RecordEvent calls out of the source and fails if either side has
something the other does not — a name in only one place is a subscription
that silently never fires, which is the failure #112 is about. I checked
the guard is load-bearing by renaming an event and watching it fail both
directions.
That list also lets webhook add --events refuse a name this forge never
emits. It runs before URL validation, which resolves DNS: a typo in the
event list should not need a reachable host to report.
No repo.deleted, deliberately. events.repo_id and
webhooks.repo_id both cascade from repos, so recording one would
delete it — and every webhook that could have received it — in the same
statement. It is undeliverable by construction, not an oversight; the
audit log is where a deletion is visible. Documented at the call site.
Closes #112
retargeted from issue-search to main: !238 merged
2026-09-04 17:13 UTC