- GitLab, GitHub, and Gitea crashed with a 500 on push payloads without
a commit list, and other malformed payloads (missing repository,
project, ref, Bitbucket changes, non-string values, unsupported
Gitea events) also returned 500. They now get a clean response; a
push with an unknown file list still deploys, and a branch deletion
does not deploy.
- The manual webhook lockout counts only distinct failed attempts: the
same wrong GitLab token, or an identical HMAC redelivery, counts
once, so a misconfigured hook no longer locks out a valid one. Every
new guess still counts (30 per scope and minute). Attempts are
stored only as HMAC hashes.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>