winem/st2
52.8
Adequate · 22 September 2026
82.5k
lines of production code
Python
primary language
5
measurements over time
What this system is
This system is an enterprise-grade automation platform that orchestrates distributed workflows and event-driven actions across heterogeneous environments. It provides a unified interface to execute, monitor, and manage tasks on Linux, Windows, and remote hosts via SSH and WinRM. The platform supports complex, multi-step workflows with pause, resume, and retry capabilities, while also enabling real-time event streaming and automated rule enforcement.
How it got here
2014 — Modularization and packaging of core components
95 changes.
This period focused on restructuring the codebase into distinct, standalone Python packages (st2common, st2api, st2auth, st2reactor, st2actions) with dedicated build systems and entry points. It involved refactoring internal modules into modular, reusable components, introducing new models and utilities, and establishing a comprehensive test suite for each component.
2015–2016 — Infrastructure and service modernization
84 changes.
This period focused on modernizing the StackStorm architecture by refactoring core components like content registration, logging, and action runners into modular, reusable packages. It introduced new services for streaming events and exporting execution data, while significantly expanding test coverage and CI/CD infrastructure to support these changes.
2017–2020 — Runner and workflow engine integration
41 changes.
This period focused on integrating the Orquesta workflow engine and introducing new remote execution runners (WinRM, Inquirer) alongside significant refactoring of existing runners into modular Python packages. The work also established a metrics collection framework and a pluggable RBAC architecture to support these new capabilities.
Features
Add CPU load average check action and sensor
A new check action and sensor have been added to the test packs to monitor CPU load average. The action, defined in check\_loadavg.yaml and implemented in check\_loadavg.py, reads /proc/loadavg and /proc/cpuinfo to calculate and display 1, 5, and 15-minute load averages per core. The sensor directory includes a .gitignore file to manage test artifacts. This introduces a new capability for users to monitor system load metrics.
st2tests/testpacks/checks · high confidence
Add Hello StackStorm example pack with sensor, action, and rule
Introduces the 'hello\_st2' pack, providing a complete example of a StackStorm pack including a Python sensor that dispatches triggers, a shell-based action for greeting, an alias, a concurrency policy, and a rule to trigger the action on the sensor's event. The pack metadata includes Python version compatibility and dependency information.
_contrib/hello\st2 · medium confidence
Add NGINX configuration for st2 web UI and API endpoints
A new NGINX configuration file (st2.conf) is introduced to expose the st2 web UI, handle HTTP-to-HTTPS redirection (308), and reverse-proxy the st2api, st2auth, and stream endpoints. The configuration sets specific timeouts (90s for API/auth, 200s for stream), disables buffering and chunked encoding for streaming, and provides custom error pages for 502/503 conditions.
conf/nginx · high confidence
Add Orquesta runner functions for task state and key-value lookup
New Python modules are introduced in the Orquesta runner to support workflow execution. The \runtime.py\ module provides a \task\ function that queries the database for task execution details, including route information. The \st2kv.py\ module implements the \st2kv\ function, which retrieves key-value pairs from the database and now supports a \default\ parameter to return a fallback value when a key is not found, rather than raising an error.
_contrib/runners/orquesta\_runner/orquesta\functions · high confidence
Add Python linting configuration files
Added configuration files for Python linting tools, including .flake8 and .pylintrc, to enforce code style, license headers, and suppress specific pylint warnings. The .flake8 config enables copyright checks and sets line length limits, while the .pylintrc configures message suppression, type checking exclusions, and formatting rules.
lint-configs · high confidence
Add WinRM runner with entry points and build support
The WinRM runner is introduced as a new component, providing entry points for 'winrm-cmd', 'winrm-ps-cmd', and 'winrm-ps-script' to integrate with the StackStorm platform. The package includes a setup script that reads the version from the local \_\init\\_.py, fetches dependencies from requirements.txt (specifically pywinrm), and includes a dist\_utils.py module to handle build-time requirements and Vagrant workarounds without relying on third-party libraries.
_contrib/runners/winrm\runner · high confidence
Add Windows PowerShell script to display system uptime
A new PowerShell script named get\_uptime.ps1 has been added to the Windows actions examples. This script calculates and displays the system's uptime in days, hours, and minutes by querying the operating system's last boot time.
contrib/examples/actions/windows · high confidence
Add concurrency and mock exception policy definitions
New policy definitions are introduced for testing purposes: a concurrency policy that limits concurrent action executions with a configurable threshold, and a mock exception policy that raises an exception during policy application. These are registered in the content bootstrap to make them available for use in tests.
st2tests/st2tests/policies/meta · high confidence
Add configuration files for logging and syslog export
New configuration files are introduced to support logging and syslog export functionality. The \logging.exporter.conf\ file defines handlers for console, file, and audit logging, while \syslog.exporter.conf\ configures a syslog handler for verbose logging. Additionally, \st2exporter.dev.conf\ sets up messaging and logging exclusions for the development environment.
st2exporter/conf · medium confidence
Add configuration files for st2auth logging and deployment
Added new configuration files for the st2auth service, including logging setups for console, file, syslog, and gunicorn environments, as well as an Apache sample configuration for WSGI deployment with SSL and external authentication support.
st2auth/conf · high confidence
Add development and debugging utility scripts to the tools directory
A collection of new utility scripts has been added to the \tools/\ directory to aid in development, debugging, and maintenance. These include \config\_gen.py\ for generating sample configuration files, \diff-db-disk.py\ to compare registered content in the database against the filesystem, and \launchdev.sh\ to manage the local development environment. Additional tools include \db\cleanup.sh\ for database maintenance, \migrate\\*\ scripts for data migration, and various debugging utilities such as \queue\_consumer.py\, \queue\_producer.py\, \direct\_queue\_publisher.py\, \log\watcher.py\, and \st2-analyze-links.py\ for analyzing rule links. The \tools/\\init\\_.py\ file is also added to make the directory a proper Python package.
tools · high confidence
Add example sensors for Flask, polling, and echo patterns
Added new example sensors to the contrib/examples/sensors directory, including a Flask-based echo sensor, a Fibonacci number generator, and generic sample sensors for both event-driven and polling patterns. These examples demonstrate how to implement custom sensors, handle configuration, and dispatch triggers within the system.
contrib/examples/sensors · high confidence
Add examples pack with configuration schema and environment utilities
The examples pack is now available, providing example sensors, triggers, actions, and rules. This update introduces a new configuration schema (config.schema.yaml) defining required API keys, secrets, and region settings, alongside a Python utility (lib/environ.py) for retrieving environment variables. The pack metadata (pack.yaml) has been established with version 0.2.1.
contrib/examples · high confidence
Add executable entry points for StackStorm action runners and services
New executable scripts are added to the st2actions/bin directory, including st2actionrunner, st2notifier, st2resultstracker, st2scheduler, and st2workflowengine, each invoking their respective Python modules. Additionally, the runners.sh script is introduced to manage worker processes, supporting both systemd and upstart init systems to start the appropriate number of action runner workers.
st2actions/bin · high confidence
Add high-availability configuration sample
A new sample configuration file (st2.conf.sample) is provided for setting up a high-availability environment. It includes specific settings for the stream and workflow\_engine components, along with other service configurations like API, auth, and database connections, to support multi-node deployments.
conf/HA · high confidence
Add inquirer\_runner package with setup and distribution utilities
The inquirer\_runner package is now fully packaged for distribution, including a new MANIFEST.in, a standalone dist\_utils.py for handling requirements and version parsing, and a setup.py that registers the runner via the st2common entry point. The runner's metadata (name, version, dependencies) is now explicitly defined, enabling proper installation and integration with the StackStorm platform.
_contrib/runners/inquirer\runner · high confidence
Add new Linux system and network diagnostic actions
The Linux pack introduces a suite of new actions for monitoring and managing Linux systems. This includes checks for CPU load average and running processes, network diagnostics via dig and netstat, process management with pkill and lsof, file operations (cp, mv, rm, touch), remote file transfer (scp, rsync), SSH connectivity checks, and service management. The wait\_for\_ssh action now supports configurable connection timeouts and retry delays, while the traceroute action validates that the binary is available in the PATH before execution.
contrib/linux/actions · high confidence
Add noop, echo, and StatsD metrics drivers
The metrics subsystem now includes three new driver implementations: a NoopDriver that discards all metrics, an EchoDriver that logs each metrics operation for debugging, and a StatsD driver that sends metrics to a StatsD server. The StatsD driver treats network-related errors as non-fatal to prevent application crashes, and supports gauge metric types in addition to counters and timers.
st2common/st2common/metrics/drivers · high confidence
Add packaging and build infrastructure for st2stream
The st2stream component now includes the necessary files for building and distributing the package. This adds a Makefile with targets for building RPMs, DEBs, and wheels, along with a dist\_utils.py script to handle dependency resolution and version parsing. A setup.py file is also added to define the package metadata and dependencies, enabling the component to be built as a standalone Python package.
st2stream · high confidence
Add sample Nginx configurations for StackStorm high availability
Added new sample Nginx configuration files for a high-availability deployment. The \st2.conf\ file provides a single-node setup with HTTP-to-HTTPS redirection and reverse proxy rules for the web UI, API, stream, and auth endpoints. The \st2.conf.controller\ file extends this for HA by defining an upstream block to distribute traffic across multiple backend nodes, implementing error handling for API, stream, and auth services, and serving the static web UI files.
conf/HA/nginx · high confidence
Add scaffolding for SSO backends in st2auth
The st2auth component now includes a new SSO (Single Sign-On) backend architecture. This introduces a base class (BaseSingleSignOnBackend) and a default NoOp backend that raises errors, allowing future implementations to plug in custom SSO providers via the st2auth.sso.backends namespace. The change also adds a noop SSO backend that explicitly requires configuration of a real backend, as the noop implementation is not a proper authentication method.
st2auth · high confidence
Add send\_mail action with attachment and UTF-8 support
Introduces the new send\_mail action, enabling users to send emails with support for local file attachments, UTF-8 encoded subjects, and configurable content types. The action automatically detects the sendmail binary, constructs multipart MIME messages for attachments, and handles empty body scenarios gracefully.
_contrib/core/actions/send\mail · high confidence
Add st2auth executable entry point
A new executable script has been added at st2auth/bin/st2auth, providing a Python 3 entry point that invokes the st2auth API main function. This change ensures the st2auth service can be launched directly via the command line, facilitating user interaction with the authentication endpoint.
st2auth/bin, st2exporter/bin · high confidence
Add st2exporter CLI entry point
A new Python module at st2exporter/st2exporter/cmd/st2exporter\_starter.py provides the command-line interface for the StackStorm exporter. This entry point initializes the exporter service, starts the background worker, and handles process lifecycle management, enabling users to run the exporter as a standalone process.
st2exporter/st2exporter/cmd · high confidence
Add st2stream command-line entry point
A new st2stream command-line interface has been introduced, providing the entry point to start the Stream API server. This includes the necessary setup and teardown logic, configuration registration, and signal handling for graceful shutdown, enabling users to run the Stream service directly.
st2stream/st2stream/cmd · high confidence
Add test pack for library dependency prioritization
A new test pack named 'test\_library\_dependencies' has been added to the test fixtures. This pack includes a Python action (get\_library\_path.py) and its corresponding pack.yaml metadata. This change supports the fix ensuring that libraries within a pack's virtual environment are prioritized over StackStorm's built-in libraries when executing actions.
_st2tests/st2tests/fixtures/packs/test\_library\dependencies · medium confidence
Add text\_gen action fixture for local runner testing
A new test fixture named 'text\_gen' has been added to the local runner pack. This includes a Python script that generates random characters and a corresponding YAML configuration file that defines the action's parameters and entry point, enabling automated tests to verify local runner behavior.
_st2tests/st2tests/fixtures/localrunner\pack · high confidence
Add ubuntu\_pkg\_info example action
An example action named ubuntu\_pkg\_info has been added to the contrib/examples directory. This Python-based action queries the local system's package information using apt-cache and returns the results as JSON. It includes a data transformer module to format the output and handles exceptions by converting error messages to text using six.text\_type.
_contrib/examples/actions/ubuntu\_pkg\info · high confidence
Added Python example actions for debugging and data conversion
New example Python actions have been added to the \contrib/examples/actions/pythonactions\ directory to assist with debugging and common data conversion tasks. This includes \print\_python\_environment\ and \print\_python\_version\ actions that output the Python executable path, version, and platform details to help diagnose runner issues. Additionally, new actions for converting JSON and YAML strings to objects, checking for prime numbers, parsing GitHub pages, and iterating through data have been introduced to demonstrate various Python scripting patterns within the framework.
contrib/examples/actions/pythonactions · high confidence
Added build infrastructure for the st2reactor component
The st2reactor component now includes a complete build system to support packaging and distribution. This includes a new Makefile with targets for building RPM and DEB packages, generating Python wheels, and managing dependencies. A new dist\_utils.py script provides shared build logic, including functions to parse requirements, check pip versions, and handle Vagrant-specific workarounds. Additionally, a MANIFEST.in file ensures all necessary source files are included in source distributions, and a setup.py file defines the package metadata and dependencies for standard Python packaging tools.
st2reactor · high confidence
Added exit-code action for testing error code outputs
A new shell script action named 'error-exit-code' has been added to the errorcheck test pack. This action accepts an optional parameter to specify an exit code, allowing users to validate error code outputs in their tests.
st2tests/testpacks/errorcheck · medium confidence
Added migration script for datastore scope and secret attributes
A new Python script, st2-migrate-datastore-to-include-scope-secret.py, has been added to the v1.5 migrations directory. This script iterates through existing key-value pairs in the database and updates them to include the 'scope' and 'secret' attributes, ensuring all datastore items are properly scoped and marked as secrets where applicable.
st2common/bin/migrations/v1.5 · high confidence
Added migration scripts for datastore scopes and runner registration
A new migration script, st2-migrate-datastore-scopes.py, was added to migrate datastore items by updating their scope values from the short-form SYSTEM\_SCOPE/USER\_SCOPE to the full-form FULL\_SYSTEM\_SCOPE/FULL\_USER\_SCOPE. Additionally, a new shell script, st2-migrate-runners.sh, was introduced to register runners using st2ctl. These scripts facilitate the upgrade process for existing installations.
st2common/bin/migrations/v2.1 · high confidence
Added mock runner implementations for testing
New mock runner implementations have been added to the test suite, including AsyncTestRunner, PollingAsyncTestRunner, and MockActionRunner. These components provide controlled, predictable behavior for unit testing the StackStorm runner framework, allowing tests to simulate action execution without invoking real external systems.
st2tests/st2tests/mocks/runners · high confidence
Added sample configuration files for Carbon and Statsd metrics
Added sample configuration files for Carbon and Statsd metrics. This includes storage-aggregation.conf and storage-schemas.conf for Carbon, defining retention policies and aggregation methods for Whisper files, and a localConfig.js for Statsd, specifying the Graphite host, port, and listening address.
conf/metrics · high confidence
Added shell autocomplete script for st2 CLI
A new shell completion script (st2.complete.sh) has been added to enable command-line autocomplete for the st2 CLI tool. This script registers the Python argcomplete library to provide interactive suggestions when using the st2 command in supported shells.
st2client/conf · high confidence
Added test query module for workflow status querying
A new test query module has been added to the test fixtures, providing a mock implementation of the Querier interface. This allows for testing workflow status queries by returning a succeeded status and associated context, facilitating the development and validation of components that interact with the result tracker.
_st2tests/st2tests/fixtures/packs/runners/test\querymodule/query · high confidence
Centralized constant definitions for StackStorm components
The st2common/st2common/constants directory now contains dedicated modules for various system components, including action statuses, API headers, authentication modes, error messages, exit codes, garbage collection settings, key-value store scopes, logging configuration, pack metadata, policy types, rule enforcement states, rule types, runner configurations, scheduler and timer log lines, secret masking attributes, sensor partition loaders, system versioning, trace identifiers, trigger definitions, and resource types. This consolidation provides a single source of truth for these values across the platform.
st2common/st2common/constants · high confidence
Expanded Orquesta and Action Chain example workflows
Added numerous example workflows for the Orquesta and Action Chain runners, covering scenarios such as pause/resume, cancellation, task retry, error handling, and data flow. The examples also demonstrate Jinja and Yaql functions, inquiry handling, and output streaming, providing templates for common workflow patterns.
contrib/examples/actions · high confidence
HTTP runner adds host allowlisting and restricts URL access
The HTTP action runner now supports both blacklisting and whitelisting of hostnames in the URL. Administrators can use the new 'url\_hosts\_whitelist' parameter to restrict outbound HTTP requests to a specific set of allowed hosts, or use 'url\_hosts\_blacklist' to block specific hosts. This change enhances security by preventing SSRF-style attacks where an action might be tricked into making requests to internal or unauthorized endpoints. The 'url\_hosts\_blacklist' parameter is now a secret, ensuring sensitive host lists are handled securely.
_contrib/runners/http\_runner/http\runner · high confidence
Initial packaging and build infrastructure for st2common
The st2common package is introduced with a new build system, including a Makefile that manages the build process, a MANIFEST.in file to define the source tree contents, and a setup.py script that configures the package metadata, dependencies, and entry points. The package now includes several utility scripts (such as st2ctl, st2-cleanup-db, and st2-self-check) and registers metrics drivers and RBAC backends via entry points. Additionally, the package's internal dependencies are managed through an in-requirements.txt file, which is processed to generate the final requirements.txt.
st2client, st2common · high confidence
Introduce API and DB models for core entities
The st2common package now includes a new st2common/models/api directory containing API model definitions for key system entities, including Action, LiveAction, ActionExecution, Inquiry, Key-Value pairs, Authentication (User, Token, ApiKey), Notifications, and the ActionRunner. These models define the structure and validation schemas for the corresponding database models, enabling the API layer to serialize and deserialize data consistently. This change establishes the foundation for the new action runner and execution tracking capabilities.
st2common/st2common/models/api · high confidence
Introduce Orquesta workflow runner with pause, resume, and rerun capabilities
Adds the Orquesta workflow engine runner to the system, enabling users to execute complex workflows with support for pausing, resuming, and rerunning specific tasks. The runner now exposes workflow execution IDs and source channels in the context, provides configurable task completion notifications, and returns structured output schemas for errors and results. This change replaces the previous 'orchestra' naming with 'orquesta' and implements the full lifecycle management for workflow executions.
_contrib/runners/orquesta\_runner/orquesta\runner · high confidence
Introduce RBAC system roles and permission types
The st2common module now includes a new RBAC (Role-Based Access Control) subsystem. This adds a database migration that inserts default system roles during service setup and defines a comprehensive set of permission types and resource types (e.g., for actions, webhooks, timers, and inquiries) to enforce access control on API endpoints.
st2common/st2common/rbac · high confidence
Introduce WinRM runner for remote Windows execution
Adds a new WinRM-based remote execution runner that enables running Command Prompt and PowerShell commands and scripts on remote Windows hosts. The update introduces the \winrm-cmd\, \winrm-ps-cmd\, and \winrm-ps-script\ runners, allowing users to execute arbitrary commands or upload and run PowerShell scripts via WinRM with configurable parameters such as host, port, scheme, and timeout.
_contrib/runners/winrm\_runner/winrm\runner · high confidence
Introduce base Querier class for polling external services
A new base Querier class has been added to st2common/query, providing a reusable framework for polling external services and updating action execution states. This change introduces the core polling logic, including thread pool management, query scheduling, and state object deletion on error, which will be used by specific runner implementations.
st2common/st2common/query · high confidence
Introduce base model classes for serialization and secret masking
Added new base model classes in st2common/models, including a DictSerializableClassMixin that provides a to\_serializable\_dict method for converting objects to JSON-serializable dictionaries, along with support for masking secret values during serialization.
st2common/st2common/models · high confidence
Introduce base workflow validator for Mistral workbooks
Added a new base class, WorkflowValidator, in st2common/st2common/validators/workflow/base.py. This class provides an abstract interface for validating workflow definitions, specifically supporting Mistral workbooks. The implementation uses Python 2/3 compatible syntax (via the 'six' library) and includes standard Apache 2.0 licensing headers.
st2common/st2common/validators/workflow · medium confidence
Introduce content pack loading and resource registration infrastructure
The st2common package now includes a new content module that provides the core infrastructure for loading content packs and registering resources. This includes a ContentPackLoader to scan directories for pack metadata and content, utility functions to resolve pack base paths and validate pack names, and a bootstrap script that orchestrates the registration of triggers, sensors, actions, rules, aliases, policies, and configs. This change shifts the responsibility of discovering and registering content from external scripts into the st2common library, enabling more consistent and modular resource management.
st2common/st2common/content · high confidence
Introduce dedicated command-line entry points for background services and utilities
The st2reactor component now provides distinct, dedicated command-line entry points for the garbage collector, rules engine, timer engine, and sensor container, each with its own configuration and lifecycle management. Additionally, new utility scripts are introduced: a rule tester for validating rule logic, and a trigger re-fire tool for manually re-dispatching trigger instances. These changes separate the concerns of each background process and add new operational tools for testing and debugging.
st2actions/st2actions/cmd, st2reactor/st2reactor/cmd · high confidence
Introduce dedicated timer engine with new configuration and base implementation
A new timer engine module has been added to the st2reactor package, providing a dedicated implementation for managing scheduled triggers. The change introduces a new base class (base.py) that utilizes APScheduler to handle interval, date, and cron-based timers, along with a configuration file (config.py) that registers the necessary options. This establishes the foundation for the timer engine to operate as a distinct component, separating timer logic from the general reactor system.
st2reactor/st2reactor/timer · high confidence
Introduce execution export worker and configuration
The st2exporter module now includes a new worker (ExecutionsExporter) that consumes execution events from the message queue and persists them to a configurable dump directory. The worker converts database models to API models before queuing, supports bootstrapping missed executions from the database, and masks secrets in the exported data. Configuration for the exporter, including the dump directory and logging settings, is now defined in a dedicated config module using oslo\_config.
st2exporter/st2exporter · high confidence
Introduce file-based export dumper with date-based subdirectories
The exporter now includes a \Dumper\ component that writes exported data to the local filesystem as JSON files. The dumper organizes output into date-stamped subdirectories, uses a background thread to periodically flush batches of data, and persists a database marker to track the last successfully exported timestamp. Supporting components include a \TextFileWriter\ for file I/O and a \JsonConverter\ for serialization.
st2exporter/st2exporter/exporter · high confidence
Introduce metrics collection framework with base driver and utility classes
The st2common package now includes a new metrics subsystem, providing a base driver interface (BaseMetricsDriver) and utility classes (Timer, Counter, CounterWithTimer) for instrumenting code. This change adds the core infrastructure for collecting metrics, including support for timers, counters, and gauges, along with key generation utilities that allow for configurable prefixes.
st2common/st2common/metrics · high confidence
Introduce mock implementations for testing
Added mock classes for action, sensor, datastore, execution, liveaction, and workflow components to facilitate pack testing. These mocks provide controlled environments for unit and integration tests, ensuring that components like the scheduler, notifier, and workflow engine can be tested in isolation without relying on external services or real database states.
st2tests/st2tests/mocks · high confidence
Introduce multi-process sensor container with hash-based partitioning
The sensor container has been refactored to run each sensor in a separate process, improving isolation and stability. A new \ProcessSensorContainer\ manages these child processes, handling lifecycle events like spawning, monitoring, and respawning sensors. To support distributed deployments, a \HashPartitioner\ is introduced, allowing sensors to be distributed across nodes based on hash ranges. The \SensorWrapper\ now executes sensors in a sandboxed environment, inheriting configuration and environment variables from the parent process. This change also includes a \SingleSensorPartitioner\ for running a specific sensor in isolation.
st2reactor/st2reactor/container · high confidence
Introduce new CLI utility modules for formatting, HTTP, and interactive input
The st2client now includes a new suite of utility modules in the st2client/utils package to enhance the command-line interface experience. The color module provides ANSI colorized status output for better visual feedback in the terminal. The date module adds human-friendly formatting for ISO dates and timestamps, including support for user-specified timezones. The httpclient module introduces an HTTP client that supports SSL verification, API key and token authentication, and debug logging of cURL-style request lines. The interactive module enables rich, schema-based interactive prompts for configuration and input. The jsutil module adds fast-path JSON path evaluation for improved performance. The terminal module improves terminal size detection and provides a task indicator for progress updates. The types module introduces an OrderedSet for consistent iteration order. These utilities collectively improve the CLI's usability, debugging, and visual presentation.
st2client/st2client/utils · high confidence
Introduce new action system models for command and script execution
The system now uses new \ShellCommandAction\ and \ShellScriptAction\ models to handle local command and script execution. These models support passing environment variables, setting a working directory, specifying timeouts, and providing sudo passwords securely. The implementation includes proper quoting and escaping of command arguments to prevent shell injection, and ensures sensitive information like sudo passwords is masked in logs.
python · high confidence
Introduce new database models for core StackStorm entities
The \st2common/st2common/models/db\ directory now contains the initial set of database models for core StackStorm entities, including Action, ActionAlias, Execution, ExecutionState, ExecutionQueue, KeyValue, LiveAction, Notification, and Auth (User, Token, ApiKey). These models define the schema for storing and querying data in MongoDB, with each model including specific indexes and field definitions that support the system's operational requirements.
st2common/st2common/models/db · high confidence
Introduce new st2client models for core resources
The st2client library now includes a comprehensive set of Python models for managing StackStorm resources, including Actions, Executions, Policies, RBAC roles, and more. This change provides a structured, object-oriented interface for interacting with the StackStorm API, replacing previous ad-hoc or less structured approaches with dedicated classes for each resource type.
st2client/st2client/models · high confidence
Introduce new system models for action chains, resource references, and remote execution
Added new model classes to define the structure and validation of action chains, including nodes with support for 'parameters' (and deprecated 'params'), success/failure routing, publish fields, and notifications. Introduced ResourceReference and UserKeyReference classes to handle scoped resource and key-value lookups, along with specific error classes for invalid references. Added Paramiko-based remote command and script action models that support environment variables, working directory, and sudo password handling while ensuring sensitive data like sudo passwords are not logged.
st2common/st2common/models/system · high confidence
Introduce new workflow execution handler for Orquesta workflows
A new workflow execution handler has been added to the st2actions package, introducing a dedicated service for processing Orquesta-based workflow executions. This includes a new config module for workflow engine settings and a workflow handler that listens to message queues to process workflow and action execution updates. The handler supports both workflow and action execution messages, applying post-run policies and updating progress, while also implementing error handling to fail workflows or tasks on unexpected exceptions.
st2actions/st2actions/workflows · high confidence
Introduce st2api Python package with build and packaging infrastructure
The st2api component is now a standalone Python package with a new setup.py, Makefile, and dist\_utils.py for build automation. The package includes an in-requirements.txt listing dependencies such as eventlet, mongoengine, oslo.config, and gunicorn. The build system supports generating Debian and RPM packages, creating Python wheels, and running flake8 linting. A Vagrant-specific workaround is included to handle shared folder limitations during source distribution builds.
st2api · high confidence
Introduce st2exporter package for RabbitMQ execution updates
Added the st2exporter component, which listens to execution updates from RabbitMQ and creates JSON files out of them. The new package includes a setup.py configuration, a Makefile for building wheels and handling dependencies, and a dist\_utils.py module for managing build-time requirements and version strings. This enables packaging and distributing the exporter as a standalone Python package.
st2exporter · high confidence
Introduce st2tests as a standalone, installable Python package
The st2tests package is now a fully distributable Python package, complete with a setup.py, MANIFEST.in, and dist\_utils.py to handle versioning and requirements parsing. This enables users to install st2tests directly via pip or build RPM/DEB packages using the provided Makefile targets. The package includes updated dependencies (psutil, webob, pyrabbit, nose-parallel, RandomWords) and enforces Apache 2.0 licensing headers across all source files.
st2tests · high confidence
Introduce the Rules Engine for automated rule enforcement
The rules engine is now a standalone component that listens for trigger instances, matches them against defined rules, and enforces actions. This includes a new RulesEngine class to handle trigger instances, a RulesMatcher to evaluate criteria, a RuleEnforcer to execute actions, and a RuleTester for validation. The engine processes messages from the 'rulesengine' queue, updates trigger instance status, and records enforcement results.
st2reactor/st2reactor/rules · high confidence
Introduce the new st2stream service for streaming API events
A new st2stream service has been added to handle streaming API events. This service exposes HTTP endpoints for streaming data, configured via st2stream/st2stream/app.py and config.py, and includes middleware for CORS, logging, and error handling. The service listens on a configurable host and port (defaulting to 127.0.0.1:9102) and integrates with the existing StackStorm infrastructure, including database and message queue connections.
st2stream/st2stream · high confidence
Introduce v1 authentication and SSO controllers
The st2auth service now exposes a new v1 API for token validation and authentication. Users can POST to the /v1/auth/tokens/validate endpoint to check if a token is valid, and POST to /v1/auth/tokens to obtain a new token. Additionally, Single Sign-On (SSO) endpoints are now available at /v1/auth/sso, allowing users to initiate SSO redirects, handle identity provider callbacks, and check if SSO is enabled. This change also fixes a bug where authentication would return an internal server error if the auth.api\_url config option was not set.
st2auth/st2auth/controllers/v1 · high confidence
Introduces a structured exception hierarchy for StackStorm components
The \st2common\ package now provides a comprehensive, organized set of custom exceptions for every major subsystem, including authentication, RBAC, database, workflows, sensors, and action runners. This change replaces generic error handling with specific, typed exceptions (such as \AccessDeniedError\, \StackStormDBObjectConflictError\, and \WorkflowExecutionException\), enabling more precise error reporting and handling across the platform.
st2common/st2common/exceptions · high confidence
Introduces structured logging configuration for st2actions components
Adds new logging configuration files for the st2actions service and its sub-components (notifier, resultstracker, scheduler, workflowengine). These configs define handlers for console, file, and syslog outputs, including a JSON-formatted audit log handler and a configurable syslog handler, enabling structured logging and detailed traceability for each service.
st2actions/conf · high confidence
Introduction of dedicated middleware components for CORS, logging, and metrics
The st2common package now includes a new middleware directory containing separate, dedicated components for handling Cross-Origin Resource Sharing (CORS), error handling, request/response logging, request ID generation, and metrics instrumentation. This refactors the previous monolithic or inline implementations into distinct, reusable classes (CorsMiddleware, ErrorHandlingMiddleware, LoggingMiddleware, RequestIDMiddleware, InstrumentationMiddleware, and StreamingMiddleware), each with specific responsibilities such as masking sensitive query parameters in logs, tracking API request timing, and ensuring proper HTTP headers for browser security.
st2common/st2common/middleware · high confidence
Introduction of pluggable RBAC backend architecture
The RBAC system has been refactored to support pluggable backends, allowing for different implementations of role-based access control. A new \backends\ package has been introduced, containing a \base.py\ module that defines abstract base classes (\BaseRBACBackend\, \BaseRBACPermissionResolver\, etc.) that all backends must implement. Additionally, a \noop.py\ module provides a \NoOp\ implementation that effectively disables RBAC checks, returning true for all permission checks. The \\_\init\\_.py\ file in the \backends\ directory provides utility functions to retrieve available backends and instances, utilizing a cache to optimize access. This change enables future integration of alternative RBAC backends while maintaining backward compatibility through the no-op default.
st2common/st2common/rbac/backends · high confidence
Migrate CI infrastructure to CircleCI with custom service setup scripts
The project has replaced its previous CI system with CircleCI, introducing a new set of shell scripts in the .circle directory to manage the build environment. This includes scripts to configure RabbitMQ and PostgreSQL services, install and start MongoDB with specific performance and testing flags (such as --notablescan), and set up the 'stanley' user with SSH keys and sudo privileges. Environment variables for the StackStorm build are also centralized in new buildenv scripts.
.circle · high confidence
New Bash example actions for exit codes, ping, and random numbers
Added four new Bash script examples to the contrib/examples/actions directory: bash\_exit\_code (generates a random exit code), bash\_ping (pings a host with a configurable count), bash\_random (outputs a single random number), and bash\_random2 (outputs multiple random numbers in a loop). These scripts provide simple, executable examples of basic Bash scripting patterns.
_contrib/examples/actions/bash\_exit\_code, contrib/examples/actions/bash\_ping, contrib/examples/actions/bash\random · high confidence
New CLI commands for pack management, validation, and cleanup
Added new CLI scripts for managing StackStorm packs and system state: st2-pack-install, st2-pack-download, and st2-pack-setup-virtualenv enable downloading, installing, and configuring pack environments (including Python 3 support); st2-pack-install now supports installing multiple packs at once; st2-pack-setup-virtualenv allows standalone virtual environment setup; st2-validate-config validates configuration files against a schema; st2-validate-api-spec checks the OpenAPI spec for duplicate keys and missing model definitions; st2-purge-executions and st2-purge-trigger-instances provide targeted data cleanup. Additionally, st2-generate-api-spec now prints the OpenAPI spec to stdout rather than writing a file.
st2common/st2common/cmd · high confidence
New ChatOps actions for matching, executing, and formatting results
Added new actions to the chatops pack: 'match' to find matching action aliases, 'match\_and\_execute' to match and run an alias while waiting for completion, 'format\_execution\_result' to render execution results using Jinja templates, and 'post\_result' (Orquesta workflow) to post execution outcomes to chat channels. These actions enable richer, template-based chatbot responses and direct execution of matched commands.
contrib/chatops/actions · high confidence
New concurrency and retry policy applicators
Added three new policy applicators: ConcurrencyApplicator and ConcurrencyByAttributeApplicator, which enforce limits on concurrent action executions (delaying or canceling new runs when thresholds are reached), and ExecutionRetryPolicyApplicator, which automatically retries failed or timed-out actions with a configurable delay and maximum retry count.
st2actions/st2actions/policies · high confidence
New core actions for system integration and workflow control
Added several new core actions to the platform: \announcement\ for broadcasting messages to stream consumers, \ask\ for initiating inquiries in workflows, \error\ for error simulation, \inject\_trigger\ for programmatically triggering events, \pause\ for workflow delays, and \noop\ for testing. Additionally, the \http\ action now supports the PURGE and HEAD methods, and the \sendmail\ action now supports file attachments and an empty body option.
contrib/core/actions · high confidence
New executable scripts for StackStorm reactor components
Added new entry-point scripts for the rule tester, trigger refire, garbage collector, rules engine, sensor container, and timers engine. Each script is a Python 3 executable that invokes the corresponding command module, enabling direct execution of these reactor components.
st2reactor/bin · high confidence
New logging configuration files for API services
Added new logging configuration files for the st2api service, including console, file, and syslog handlers. The configurations define specific log levels, formatters, and output destinations (stdout, rotating files, and syslog) to improve log management and debugging capabilities.
st2api/conf · high confidence
New logging configuration files for st2stream
Added new logging configuration files for st2stream, including console, file, audit, syslog, and Gunicorn-specific setups. These configurations define how st2stream handles log output to various destinations such as console, rotating files, and syslog, with specific formatters and handlers for different logging levels and contexts.
st2stream/conf · high confidence
New pack management actions for installation, configuration, and environment setup
The \contrib/packs/actions\ directory now contains a comprehensive set of new actions for managing StackStorm packs, including \install\, \download\, \setup\_virtualenv\, \update\_virtualenv\, \delete\, \get\, \get\_config\, \get\_pack\_dependencies\, \get\_pack\_warnings\, \load\, \restart\_component\, \search\, \show\, \uninstall\, \unload\, and \virtualenv\_prerun\. These actions provide users with granular control over pack installation, virtual environment creation and updates, content loading/unloading, and dependency management.
contrib/packs/actions · high confidence
New scheduler service with configurable scheduling and cleanup intervals
The scheduler is now a standalone service with its own configuration file and logging setup. Users can now configure the scheduler's sleep interval, garbage collection interval, pool size, and retry settings via the new 'scheduler' configuration group. The scheduler also handles cleaning up deprecated 'policy-delayed' status executions and auto-populates missing action\_execution\_id values in the scheduling queue.
st2actions/st2actions/scheduler · high confidence
New st2ctl and st2-self-check scripts for service management and system verification
The st2ctl script has been updated to manage system services using the appropriate service manager (systemd, upstart, or SysV), with improved handling of component lists and environment variables. The st2-self-check script has been added to verify the StackStorm installation, including running tests for all packs and workflows, with options to skip specific test types (e.g., Windows or Orquesta tests). Additionally, new utility scripts have been introduced: st2-cleanup-db for dropping the MongoDB database, st2-generate-schemas for generating JSON schemas for content models, st2-generate-api-spec for API specification generation, st2-generate-symmetric-crypto-key for secure key generation, st2-pack-download/install/setup-virtualenv for pack management, st2-purge-executions and st2-purge-trigger-instances for data cleanup, st2-register-content for content registration, st2-run-pack-tests for pack testing, st2-track-result for result tracking, st2-validate-api-spec and st2-validate-pack-config for validation, and paramiko\_ssh\_evenlets\_tester for SSH testing.
st2common/bin · high confidence
New streaming endpoints for execution output and general events
Added a new GET /v1/stream/executions/\<id\>/output endpoint that streams execution output events in real-time, allowing clients to monitor live action output. Additionally, the existing /v1/stream endpoint now supports filtering by action refs and execution IDs, and enforces STREAM\_VIEW RBAC permissions. The stream controller also sends a special EOF event when the stream closes, and headers are set to prevent caching and buffering.
st2stream/st2stream/controllers · high confidence
Orquesta runner integration and function registration
The orquesta\_runner package is introduced to the StackStorm distribution, providing the workflow engine integration. The setup.py registers a comprehensive set of expression functions—including data parsing (JSON/YAML), string manipulation, version comparison, and time formatting—allowing users to leverage these capabilities within Orquesta workflows.
_contrib/runners/orquesta\runner · high confidence
Python action runner packaged as a proper Python package
The Python action runner is now a proper Python package with a \setup.py\ file, enabling standard Python packaging and distribution. The package includes a \MANIFEST.in\ to ensure all necessary files (like \runner.yaml\ and \dist\_utils.py\) are included in the distribution. A \dist\_utils.py\ file is added to handle build-time requirements parsing and Vagrant workarounds. The \setup.py\ registers the runner via a stevedore entry point (\st2common.runners.runner\), allowing StackStorm to discover and load the Python runner. The package name is prefixed with \stackstorm-runner-\.
_contrib/runners/python\runner · high confidence
Remote runner package structure and build files added
The remote runner is now packaged as a standalone Python package with its own \setup.py\, \MANIFEST.in\, and \dist\_utils.py\ utility script. This includes a symlinked \runner.yaml\ and an empty \in-requirements.txt\ file, enabling the runner to be built and installed as a distinct distribution unit within the StackStorm platform.
_contrib/runners/remote\runner · high confidence
Architecture
Refactor pack management actions into a modular structure
The pack management actions have been reorganized into a new \pack\_mgmt\ subpackage, introducing dedicated action classes for each operation: \delete.py\ (uninstall), \download.py\ (download), \get\_installed.py\ (get installed), \get\_pack\_dependencies.py\ (get dependencies), \get\_pack\_warnings.py\ (get warnings), \register.py\ (register), \search.py\ (search), \setup\_virtualenv.py\ (setup virtualenv), \show\_remote.py\ (show remote), \unload.py\ (unload), and \virtualenv\_setup\_prerun.py\ (prerun). This refactoring groups related functionality into separate files, improving code maintainability and separation of concerns within the pack management system.
_contrib/packs/actions/pack\mgmt · high confidence
Refactored and expanded utility modules in st2common/util
The st2common/util package has been reorganized into a collection of specialized utility modules, each handling a specific domain of the application. New modules include action\_db.py for database operations related to actions and live actions, actionalias\_helpstring.py and actionalias\_matching.py for processing and matching action aliases, api.py for constructing API URLs, argument\_parser.py for generating CLI argument parsers from metadata, auth.py for token and API key validation, casts.py for type casting, compat.py for Python 2/3 compatibility, concurrency.py for abstracting eventlet/gevent, and config\_loader.py for loading configuration. This refactoring improves code reuse, readability, and maintainability by grouping related functionality into dedicated files.
st2common/st2common/util · high confidence
Refactored content registration into modular registrar classes
The content registration logic has been refactored into dedicated registrar classes (ActionsRegistrar, AliasesRegistrar, ConfigsRegistrar, PoliciesRegistrar, RulesRegistrar, RuleTypesRegistrar, RunnersRegistrar, and SensorsRegistrar) within the st2common/bootstrap package. This change introduces a more consistent and reusable structure for registering StackStorm resources, with each registrar handling its specific resource type and supporting features like caching, fail-on-failure modes, and validation. The base ResourceRegistrar class provides common functionality, while specific registrars implement the logic for their respective resources, improving code organization and maintainability.
st2common/st2common/bootstrap · high confidence
Refactored st2common services into a modular services package
The st2common services have been reorganized into a dedicated services package, introducing new modules for access control, action execution, configuration, coordination, datastore, execution tracking, inquiry handling, key-value lookups, and pack management. This structural change improves code organization and separation of concerns within the common library.
st2common/st2common/services · high confidence
Reorganized persistence layer into individual modules
The persistence layer in st2common has been reorganized from a single monolithic file into separate modules for each resource type (e.g., action, execution, keyvalue, rbac). This change improves code maintainability and reduces import dependencies, making the codebase easier to navigate and modify.
st2common/st2common/persistence · high confidence
Restructured remote runner into modular components
The remote runner implementation has been reorganized from a single package into a modular structure with separate modules for command and script execution. This change introduces \remote\_command\_runner\ and \remote\_script\_runner\ modules, each with their own \get\_metadata\ function that returns a dictionary with metadata for the requested runner, ensuring consistent metadata retrieval. The \runner.yaml\ configuration file is updated to reflect this new structure, allowing users to continue using the \remote-shell-cmd\ and \remote-shell-script\ runners without changes to their existing configurations.
_contrib/runners/remote\_runner/remote\runner · high confidence
Behavioural changes
API validation logic restructured into dedicated validator modules
The API validation logic has been reorganized into new, dedicated modules: action.py for action validation, reactor.py for trigger and criteria validation, and misc.py for system pack restrictions. This refactoring introduces specific validation for action parameters (including immutability and position uniqueness), trigger parameters and payloads (with configurable validation for non-system triggers), and criteria object validation, while also preventing updates or deletions of resources belonging to system-level packs.
st2common/st2common/validators/api · medium confidence
Action runner packages now include runner.yaml and use stevedore entry points
The action chain and noop runners are now proper Python packages with \setup.py\ files that include \runner.yaml\ and \dist\_utils.py\ in the distribution. Each runner now registers a stevedore entry point (e.g., \action-chain\ and \noop\) under the \st2common.runners.runner\ namespace, enabling StackStorm to discover and load them by name rather than module path.
_contrib/runners/action\_chain\runner · high confidence
Add Pylint plugins for API and database models
New Pylint plugins have been added to help the linter understand dynamically assigned attributes on API model classes (based on jsonschema definitions) and database model classes (specifically handling mongoengine's implicit 'id' and '\_fields' attributes). This reduces false-positive linting errors for these specific class hierarchies.
_pylint\plugins · high confidence
Add copyright and license headers to test fixture files
Added Apache 2.0 license headers to the my\_sensor.py files in the dummy\_pack\_2 and dummy\_pack\_3 test fixtures. This ensures that the test pack fixtures carry the correct copyright and licensing information, aligning with project standards for legal compliance in test data.
_st2tests/st2tests/fixtures/packs/dummy\_pack\_2/sensors, st2tests/st2tests/fixtures/packs/dummy\_pack\3/sensors · high confidence
Add logging configuration files for reactor components
New logging configuration files have been added for the garbage collector, rules engine, sensor container, and timers engine. These files define how each component logs to the console, to rotating log files, and to syslog, ensuring that each service has its own dedicated logging setup rather than sharing a generic configuration.
st2reactor/conf · medium confidence
Add st2stream executable entry point
A new executable script named 'st2stream' has been added to the bin directory, allowing users to run the st2stream command-line interface directly. The script is configured to use Python 3 and invokes the main function from the st2stream.cmd.api module.
st2stream/bin · medium confidence
Added dummy pack fixture for testing config context rendering
A new test fixture has been added to the dummy pack, introducing a Python action and its corresponding YAML definition. This action, named 'render\_config\_context', is designed to validate how configuration context values are rendered, specifically accepting an optional string parameter 'value1' that defaults to a config context item.
_st2tests/st2tests/fixtures/packs/dummy\_pack\7/actions · medium confidence
Added migration script to clean up deprecated 'policy-delayed' status
A new migration script has been added to the v3.1 migration suite. This script connects to the database and executes a cleanup of executions that still hold the deprecated 'policy-delayed' status, ensuring the system is cleaned up during the upgrade process.
st2common/bin/migrations/v3.1 · medium confidence
Announcement runner refactored into a proper Python package
The announcement runner has been restructured into a proper Python package, introducing an \_\init\\_.py that defines the module version (3.4dev) and a runner.yaml configuration file that defines the runner's parameters (experimental flag and route). The main implementation in announcement\_runner.py now exposes get\_runner and get\_metadata functions, aligning the runner with the standard package-based structure used by other runners.
_contrib/runners/announcement\_runner/announcement\runner · high confidence
Centralized policy metadata definitions in st2common
The metadata definitions for concurrency, retry, and concurrency\_by\_attr policies have been moved from st2actions to st2common, centralizing the schema for these policy types. The concurrency policy now allows users to specify the action to perform when a concurrency threshold is reached, with options to delay or cancel executions. The retry policy's delay parameter now supports a maximum of 120 seconds.
st2common/st2common/policies/meta · medium confidence
Enhanced ChatOps message rendering with web URL and structured results
The default ChatOps template has been updated to include the execution's web URL when available, and to render action results in a structured, serialized format specific to each runner type (e.g., http-request, python-script, remote-shell). This change improves the readability and completeness of ChatOps notifications by ensuring all relevant execution data is presented clearly.
contrib/chatops/actions/templates · medium confidence
Enhanced subprocess execution with live read and configurable buffers
The \st2common.util.green.shell.run\_command\ function has been updated to support 'live read' mode, allowing stdout and stderr to be read dynamically as data becomes available via new \read\_stdout\_func\ and \read\_stderr\_func\ callbacks. Additionally, the function now accepts \preexec\_func\ and \kill\_func\ arguments to customize process execution and termination behavior, and includes a \bufsize\ parameter to control the subprocess buffer. These changes improve handling of high-output commands and prevent race conditions during timeouts.
st2common/st2common/util/green · medium confidence
Expanded garbage collection for executions, inquiries, and trigger instances
The garbage collection service in st2common now includes dedicated modules for purging action execution outputs, handling timed-out Inquiries, and cleaning up orphaned workflow executions and trigger instances. Users will see more granular cleanup of execution output objects, automatic cancellation of expired Inquiries, and improved logging of deleted object counts.
_st2common/st2common/garbage\collection · high confidence
Extract resultstracker into its own package with dedicated configuration
The resultstracker module has been moved from the st2actions root into a dedicated st2actions/resultstracker package, including a new config.py that registers specific options (such as the logging config path) and an \_\init\\_.py. This separation allows the resultstracker to have its own standalone configuration, distinct from the broader st2actions namespace, while still importing common utilities and constants from st2common.
st2actions/st2actions/resultstracker · medium confidence
File watch sensor now accepts file paths via rule parameters
The Linux pack's file watch sensor has been updated to receive the file path to monitor through a rule's trigger parameters rather than a static config file. Users must now define a rule specifying the 'file\_path' parameter for the 'linux.file\_watch.line' trigger type. The sensor still emits the same payload containing the file path, file name, and line content, but the mechanism for supplying the monitored file has changed from a global configuration to a per-rule parameter.
contrib/linux/sensors · medium confidence
Introduce RunnerContainer to manage action execution lifecycle
The st2actions/container module now provides a central RunnerContainer class that orchestrates the full lifecycle of action executions. This includes dispatching actions to the appropriate runners, handling status updates (requested, running, canceled, paused, resumed), managing temporary authentication tokens, and ensuring proper cleanup and logging of results. This change consolidates execution logic, improves error handling, and ensures consistent state updates for liveactions.
st2actions/st2actions/container · high confidence
Introduce configurable garbage collection for action execution outputs
The garbage collector service now supports purging action execution output objects separately from the main action executions, with a default time-to-live (TTL) of 7 days. This new capability is controlled via the \action\_executions\_output\_ttl\ configuration option, allowing administrators to manage the retention period for execution output data independently of other garbage collection tasks.
_st2reactor/st2reactor/garbage\collector · high confidence
Introduce custom JSON Schema validation for action and runner parameters
The \st2common\ module now includes a dedicated schema validation layer for action and runner parameters. This change introduces a custom JSON Schema validator that supports default values for nested properties, enforces required attributes, and allows the \secret\ attribute. The implementation separates the schema definitions for action parameters, action output, and general custom schemas, ensuring that parameter validation occurs before trigger creation and that default values are correctly assigned during validation.
st2common/st2common/util/schema · medium confidence
Introduce the Inquirer runner for interactive workflow prompts
A new 'inquirer' runner has been added to the system, enabling workflows to pause and request user input during execution. The runner supports configurable validation schemas, user and role-based access control for responses, and configurable timeouts. This change also includes a fix for a race condition where the parent workflow might not pause correctly when the inquiry is pending.
_contrib/runners/inquirer\_runner/inquirer\runner · medium confidence
Local runner package now includes runner.yaml and metadata for proper loading
The local runner package now explicitly includes the runner.yaml file and other necessary assets (like dist\_utils.py and requirements.txt) in the distribution, ensuring the runner is correctly recognized and loaded by the platform. This change also updates the setup.py to use the actual runner name from runner.yaml for stevedore extension/driver naming, and ensures the package data is correctly packaged for installation.
_contrib/runners/local\runner · medium confidence
Local runner refactored into a modular package with enhanced security and configuration options
The local runner has been restructured from a single module into a Python package (local\_runner) containing a shared base class (base.py) and separate modules for shell commands and scripts. This refactor introduces the sudo\_password parameter, which allows execution with sudo when passwordless access is unavailable; this parameter is now marked as a secret to ensure secure handling. Additionally, the shell script runner now supports a debug mode and a content\_revision parameter for specifying git revisions, while the command runner exposes a cmd parameter for arbitrary Linux commands.
_contrib/runners/local\_runner/local\runner · high confidence
Major CLI refactoring and new commands
The st2client commands have been refactored into a new modular structure under st2client/commands, introducing base classes like Branch and Command to standardize CLI behavior. This change introduces several new commands including 'st2 whoami' to display the currently authenticated user and their token expiry, and 'st2 login' to authenticate and update the CLI config directory. The 'st2 run' command now supports the '--tail' flag to immediately tail the new execution, and the 'st2 execution tail' command has been improved to handle workflow child executions and print raw output by default. Additionally, the CLI now supports filtering executions by user, status, and timestamp, and displays the elapsed time for all running executions.
st2client/st2client/commands · medium confidence
Major refactoring of the st2client CLI architecture
The st2client package has been restructured into a modular architecture, introducing dedicated modules for the CLI shell, base application logic, client configuration parsing, and exception handling. This refactoring introduces a new \BaseCLIApp\ base class to centralize common CLI functionality, implements a \CLIConfigParser\ to handle configuration file parsing and validation, and updates the \Client\ class to manage resource managers for all supported API endpoints. As a result, the CLI now supports more robust configuration management, including environment variable precedence, token caching, and SSL warning suppression, while maintaining backward compatibility for existing commands.
st2client/st2client · high confidence
Migrate st2api to a modern WSGI application with OpenAPI routing
The st2api service has been refactored from a Pecan-based application to a modern WSGI app using an OpenAPI router. This change introduces a new middleware stack (including CORS, logging, request ID, and instrumentation) and enables streaming endpoints for execution output. Configuration options such as 'allow\_origin' and 'mask\_secrets' are now managed through the API config, and RBAC validation is performed at startup to ensure correct configuration.
st2api/st2api · high confidence
New configuration files for log rotation and service defaults
Added a new \conf/logrotate.conf\ file that defines log rotation rules for all StackStorm services (API, auth, stream, action runner, scheduler, workflow engine, etc.), using \st2ctl reopen-log-files\ to signal services instead of restarting them. Updated \conf/st2.conf.sample\ and environment-specific configs (\st2.dev.conf\, \st2.package.conf\, \st2.tests.conf\) to reflect current defaults, such as enabling \system.validate\_trigger\_parameters\ and \system.validate\_trigger\_payload\ by default, setting \stream\_output\ to \True\ in dev environments, and configuring logging paths for new components like the workflow engine and notifier. Also added \conf/st2\_kvstore\_demo.crypto.key.json\ for key-value store encryption and \conf/st2rc.sample.ini\ for CLI configuration.
conf · high confidence
New expression functions for data, regex, time, and versioning
Expression evaluation now includes new functions for data serialization (to\_json\_string, to\_yaml\_string, from\_json\_string, from\_yaml\_string), regex operations (regex\_match, regex\_replace, regex\_search, regex\_substring), time formatting (to\_human\_time\_from\_seconds), and version comparison (version\_compare, version\_more\_than, version\_less\_than, version\_equal, version\_match, version\_bump\_major, version\_bump\_minor). Additionally, the decrypt\_kv function now provides a more user-friendly error message when a referenced datastore item does not exist or is empty, and the to\_yaml\_string function has been updated to handle MongoDB base types.
st2common/st2common/expressions · high confidence
New logging configuration files for test environments
Added new logging configuration files (logging.api.conf, logging.auth.conf, logging.conf, logging.sensorcontainer.conf) and a st2.conf for the test environment. These configurations define how logs are written to files in /tmp with timestamps, and specify handlers for console, file, and audit logging. The st2.conf also includes settings for API, auth, syslog, messaging, and SSH runner for tests.
st2tests/conf · high confidence
New logging infrastructure with secret masking and log rotation
The logging module has been reorganized into a new \st2common.logging\ package, introducing custom filters to exclude spammy messages (like \heartbeat\_tick\), a \FormatNamedFileHandler\ that uses a Unix timestamp in log filenames, and formatters that support masking sensitive attribute values in log output. Additionally, log files are now reopened on the SIGUSR1 signal to support log rotation.
st2common/st2common/logging · high confidence
New sensor base classes and configuration options
The sensor container now uses a new sensor class hierarchy with a \BaseSensor\ interface that includes \setup\, \run\, and \cleanup\ lifecycle methods, as well as trigger management methods (\add\_trigger\, \update\_trigger\, \remove\_trigger\). Active sensors inherit from \PollingSensor\, which adds a \poll\ method and configurable \poll\_interval\. Configuration for the sensor container is now managed via the \sensorcontainer\ section in \st2reactor/st2reactor/sensor/config.py\, introducing options for logging, partitioning (renamed from 'shard' to 'partition'), and a new \single\_sensor\_mode\ for environments like Kubernetes.
st2reactor/st2reactor/sensor · high confidence
NoopRunner converted to a proper Python package
The noop runner is now a proper Python package, with its code and configuration split into \_\init\\_.py, noop\_runner.py, and runner.yaml. This change ensures the runner is correctly packaged and includes the necessary metadata and license headers, improving how the system handles and loads this specific action runner.
_contrib/runners/noop\_runner/noop\runner · medium confidence
Notifier service restructured and enhanced with Jinja templating
The notifier module has been reorganized into a dedicated package under st2actions, introducing a standalone configuration file and separate logging setup. The Notifier class now supports Jinja templating for notification messages and data payloads, allowing dynamic content generation. Additionally, the service now scans the action execution queue instead of the liveaction queue, and includes TraceContext in notifications. The implementation also adds metric instrumentation, handles null timestamps, and ensures policies are not applied to disabled actions.
st2actions/st2actions/notifier · medium confidence
Python runner module reorganization
The Python runner implementation has been reorganized into a dedicated module (pythonrunner.py) with an updated \_\init\\_.py that explicitly exports the Action class. This change improves code structure and maintainability by separating the Python runner logic into its own file while maintaining backward compatibility through the module's public API.
st2actions/st2actions/runners · medium confidence
Python runner refactored into a standalone package
The Python runner has been restructured into a standalone Python package (python\runner) with its own \\init\\_.py, python\_action\_wrapper.py, and python\_runner.py modules. This change improves import time by removing the database dependency from the Python runner, ensures pack virtual environment libraries are prioritized over st2's own libraries, and adds support for passing large parameters via stdin to avoid command-line length limits. The runner now inherits from GitWorktreeActionRunner, supports content\_revision and debug parameters, and includes a runner.yaml configuration file defining the output schema and runner parameters.
_contrib/runners/python\_runner/python\runner · medium confidence
Refactor API service entry point and initialization
The API service entry point has been refactored into a new \st2api/cmd/api.py\ module, which now handles the complete lifecycle of the API service. This includes early monkey-patching for SSL support, explicit registration of configuration options, and execution of pre-runtime validation checks (such as RBAC configuration) before the WSGI server starts. The refactoring also introduces a common setup/teardown pattern shared across services, ensuring consistent initialization, signal handling, and graceful shutdown behavior for the API process.
st2api/st2api/cmd · medium confidence
Refactor REST API controllers with new base classes and utilities
The REST API controllers have been refactored to use new base classes and utility functions. A new \BaseRestControllerMixin\ in \base.py\ provides shared query parameter parsing and secret masking logic. A \ResourceController\ in \resource.py\ introduces support for \exclude\_fields\ and \include\_fields\ filtering, pagination limits, and sorting. A \RootController\ in \root.py\ now serves the API index page with version and documentation URL. These changes centralize common functionality and improve consistency across API endpoints.
st2api/st2api/controllers · high confidence
Refactor Travis CI test execution into modular, reusable scripts
The Travis CI configuration has been refactored to use a suite of new helper scripts in the scripts/travis directory, replacing the previous monolithic or inline configurations. These scripts now handle specific CI tasks: build orchestration (build.sh), environment setup for Python 3 and unit/integration tests (install-requirements.sh), MongoDB installation and optimization (install-and-run-mongodb.sh, mongod.conf), integration test preparation (prepare-integration.sh), code coverage submission (submit-codecov-coverage.sh), and build timeout enforcement (time-command.sh). This change improves the maintainability and clarity of the CI pipeline by separating concerns into distinct, testable shell scripts.
scripts/travis · high confidence
Refactor action chain runner to use output\_key and output\_schema
The action chain runner has been refactored to replace the previous output\_path mechanism with an explicit output\_key and output\_schema definition. Users will now see published variables and task results exposed under the 'published' key in the runner's output, as defined in the new runner.yaml configuration. This change simplifies how action chain outputs are structured and accessed, moving away from file-based output paths to a structured data key.
_contrib/runners/action\_chain\_runner/action\_chain\runner · high confidence
Refactor st2auth service startup and configuration handling
The st2auth service entry point has been refactored to use a common service setup module, reducing code duplication and fixing cyclic imports. The service now supports a 'mode' option and allows HTTPS to be optional via the 'use\_ssl' configuration, enabling deployment behind reverse proxies like Apache or Nginx. Additionally, the code now validates that certificate and private key files exist when SSL is enabled, and logging is configured earlier to capture messages during config parsing.
st2auth/st2auth/cmd · medium confidence
Refactored CLI output formatters into a modular, extensible system
The CLI's output formatting has been refactored into a new \st2client.formatters\ package, introducing a base \Formatter\ class and specialized formatters for JSON, YAML, tables, and execution results. This change introduces support for YAML output, allows users to define custom attribute display orders, and improves table rendering with dynamic column width calculation and better handling of edge cases like empty results or carriage returns. The refactoring also adds Apache 2.0 license headers and improves Python 3 compatibility.
st2client/st2client/formatters · high confidence
Refactored action alias and parameter utilities into st2common/models/utils
The codebase has been reorganized by moving and refactoring several utility modules into the new \st2common/st2common/models/utils\ directory. This includes \action\_alias\_utils.py\ (containing the \ActionAliasFormatParser\ and parameter extraction logic), \action\_param\_utils.py\ (for parameter casting and validation), \profiling.py\ (for MongoDB query logging), and \sensor\_type\_utils.py\ (for sensor type creation). These changes improve code reuse, fix parsing bugs, and provide cleaner access to common model utilities.
st2common/st2common/models/utils · high confidence
Refactored action execution dispatcher and worker logic
The st2actions module has been refactored to improve the handling of action executions. The \ActionExecutionDispatcher\ in \worker.py\ now explicitly tracks running live actions to handle cleanup on shutdown and manages state transitions for scheduled, canceling, pausing, and resuming actions. The \config.py\ module centralizes common configuration options, and the worker now uses a dedicated \ActionsQueueConsumer\ with dispatcher pools. These changes support better error handling, logging, and state management for action runners.
st2actions/st2actions · medium confidence
Refactored action runner infrastructure into st2common
The action runner implementation has been moved and refactored within the st2common package. This includes new base classes for action runners and Python actions, a refactored parallel SSH client, and updated runner loading logic that now supports dynamic enumeration via stevedore. Additionally, the change introduces a new callback handler base class and utility functions for logging and configuration handling.
st2common/st2common/runners · high confidence
Refactored authentication backend infrastructure
The st2auth backends module has been restructured to provide a more robust and extensible foundation for authentication plugins. A new base class, BaseAuthenticationBackend, is introduced with abstract methods for authentication, user info retrieval, and group membership checks. The backend loading mechanism has been updated to use the stevedore library for dynamic plugin discovery, replacing the previous home-grown solution. Additionally, a constants module defines AuthBackendCapability flags (CAN\_AUTHENTICATE\_USER, HAS\_USER\_INFORMATION, HAS\_GROUP\_INFORMATION) to declare backend features, and the get\_groups method has been renamed to get\_user\_groups for clarity.
st2auth/st2auth/backends · medium confidence
Refactored message bus transport layer with improved reliability and structure
The transport module has been restructured to improve reliability and maintainability. A new \ConnectionRetryWrapper\ handles automatic reconnection and cluster failover for RabbitMQ, ensuring the system recovers from connection drops. Message consumers now use a \BufferedDispatcher\ with configurable pool sizes to prevent workflow actions from blocking regular actions. The bootstrap process pre-declares all exchanges and queues on startup to prevent message loss. Additionally, SSL/TLS configuration for RabbitMQ connections has been moved to the \utils\ module, and a custom pickle serializer is registered to handle UTF-8 encoded messages.
st2common/st2common/transport · high confidence
Refactored policy application architecture with concurrency support
The policy application logic has been restructured into a new base class, ResourcePolicyApplicator, which introduces explicit apply\_before and apply\_after hooks for policy execution. A new BaseConcurrencyApplicator has been added to handle concurrent action execution, supporting both delay and cancel actions. The policy loading mechanism has been updated to use a factory pattern, making the system more robust and easier to extend.
st2common/st2common/policies · medium confidence
Refactored v1 API controllers to enforce RBAC and support attribute filtering
The v1 API controllers for actions, executions, and aliases have been refactored to enforce RBAC permissions and support include/exclude attribute filtering. This change ensures that users can only access resources they have permission to view or modify, and allows clients to request specific fields in API responses, reducing payload size and improving performance.
st2api/st2api/controllers/v1 · high confidence
Reimplement st2auth as an OpenAPI-based service
The st2auth service has been reimplemented to use an OpenAPI specification, replacing the previous Pecan-based router. This change introduces a new middleware stack (including CORS, logging, and request instrumentation) and updates the authentication handlers to support impersonation and remote group synchronization. The service now validates configuration and auth backend capabilities at startup, and the WSGI entry point ensures early monkey patching for Gunicorn workers.
st2auth/st2auth · medium confidence
Reorganized test infrastructure with new base classes and utilities
The test suite has been reorganized to improve consistency and reusability across different test types. New base test case classes have been introduced: BaseActionTestCase for Python runner action tests, BaseSensorTestCase for sensor tests, and BaseActionAliasTestCase for action alias tests. A new FixturesLoader helper class was added to simplify loading test fixtures into the database, supporting features like using object IDs from fixture files. Additionally, API-related test utilities and base classes were moved into the st2tests.api module for better organization and external reuse.
st2tests/st2tests · high confidence
Reorganized test pack fixtures structure
The st2tests pack fixtures have been reorganized. The 'core' pack is now a symbolic link to the main contrib/core directory, and the 'test\_content\_version' pack is now a git submodule pointing to a specific commit. This change updates how test content is referenced within the test suite.
st2tests/st2tests/fixtures/packs · medium confidence
Restructure st2actions into a standalone Python package
The st2actions component is now packaged as a standalone Python distribution, complete with its own setup.py, MANIFEST.in, and Makefile. This change introduces a new dist\_utils.py module to handle build-time requirements and version parsing, and explicitly registers the st2actionrunner, st2notifier, st2resultstracker, st2workflowengine, and st2scheduler scripts for installation.
st2actions · high confidence
StackStorm version 3.4dev release and common configuration consolidation
The st2common package is updated to version 3.4dev. This release consolidates common configuration options into st2common/config.py, including RBAC, system, content, and database settings. It also introduces a new ComplexDateTimeField for precise microsecond timestamp handling in MongoDB, refactors the logging module to support Python 3 compatibility and custom caller detection, and updates the OpenAPI specification to reflect current API endpoints and security headers.
st2common/st2common · high confidence
Standardize action runner packaging and metadata
Each action runner (e.g., announcement, http) is now a proper Python package with its own setup.py, MANIFEST.in, and dist\_utils.py. The package names use the 'stackstorm-runner-' prefix, and the setup.py files include runner.yaml and other necessary files in the distribution. Stevedore entry points are configured to use the actual runner name from runner.yaml rather than the Python module name, ensuring correct registration and loading of runners.
_contrib/runners/http\runner · medium confidence
Standardize license headers and Python syntax in test pack fixtures
The test pack fixtures for dummy\_pack\_1, dummy\_pack\_2, and dummy\_pack\_3 have been updated to include standardized Apache 2.0 license headers and updated to use Python 3 syntax. This ensures consistent licensing across all test action files and aligns the codebase with modern Python standards.
_st2tests/st2tests/fixtures/packs/dummy\_pack\_1/actions, st2tests/st2tests/fixtures/packs/dummy\_pack\_2/actions, st2tests/st2tests/fixtures/packs/dummy\_pack\3/actions · medium confidence
Stream listener refactored into reusable components
The stream listener logic has been moved into the st2common package, making it available for use across different parts of the system. The previous single listener class has been split into specialized components: a base listener class and specific listeners for execution output (stdout/stderr). This refactoring introduces a more modular approach to handling streaming events, with improved filtering capabilities for event names, action references, and execution IDs.
st2common/st2common/stream · medium confidence
Updated Python build scripts for pip 10.0+ compatibility
The scripts in the scripts/ directory, including dist\_utils.py and fixate-requirements.py, have been updated to support pip 10.0 and later versions. This change ensures that the build process correctly handles environment markers in requirements files and resolves import path changes in pip's internal modules, preventing failures during the generation of pinned requirements.
scripts · high confidence
Updated dummy pack fixtures with valid versions
The dummy pack fixtures for dummy\_pack\_2 and dummy\_pack\_3 have been reorganized and updated to include valid version numbers in their pack.yaml files. This ensures that pack validation does not fail during testing, preventing errors related to missing or invalid version metadata in the test fixtures.
_st2tests/st2tests/fixtures/packs/dummy\_pack\_2, st2tests/st2tests/fixtures/packs/dummy\_pack\3 · medium confidence
Updated dummy\_pack\_1 fixture with valid configuration schema and metadata
The dummy\_pack\_1 test fixture was reorganized to include a config.schema.yaml defining required string fields (api\_key, api\_secret, region) and a pack.yaml with version 0.1.0 and contributor details. This ensures the test pack passes validation and provides a complete example for pack structure.
_st2tests/st2tests/fixtures/packs/dummy\_pack\1 · medium confidence
Updated index page with version, logo, and documentation link
The index page now displays the StackStorm version, the StackStorm logo, and a link to the documentation. Previously, the index page may have been broken or lacked these elements.
st2api/st2api/templates · high confidence
st2api executable updated to use Python 3
The st2api entry-point script has been updated to use the Python 3 interpreter via the shebang line, ensuring the API service runs on the correct Python version.
st2api/bin · high confidence
Fixes
Empty fixtures package initialization
An empty \_\init\\_.py file was added to the st2tests/fixtures directory, creating a Python package structure for test fixtures.
st2tests/st2tests/fixtures · low confidence
Revert content registration refactoring
The refactoring that moved content registration into separate files has been reverted. This change restores the previous structure for content registration in the st2actions and st2reactor bootstrap modules, ensuring the system reverts to the prior state of how components are registered.
st2actions/st2actions/bootstrap, st2reactor/st2reactor/bootstrap · medium confidence
Test coverage
Add dummy pack fixture with UTF-8 config support; Add dummy pack sensor fixtures for testing; Add execution test fixtures for the st2tests pack; Add functional test base class for st2auth; Add integration tests for the export worker and dumper; Add test SSL certificates and CA for testing; Add test fixture for PollingAsyncTestRunner; Add test fixtures for API logging configuration; Add test fixtures for history view filters; Add test utility classes to st2tests.api module; Added Python action test resources; Added SSH runner integration tests; Added SSH test fixtures for passphrase and custom port configurations; Added \_\init\\.py to local runner unit tests; Added empty \\init\\.py files for remote runner test packages; Added empty \\init\\.py for st2actions/tests package; Added empty \\init\\.py for test package; Added empty \\init\\_.py to st2common/tests; Added empty integration test package; Added htpasswd test fixture; Added initial test coverage for the Linux dig action; Added integration test package markers; Added integration test stub for winrm\runner; Added integration tests for Gunicorn WSGI entry points; Added integration tests for Python runner behavior and process wrapper; Added integration tests for RabbitMQ SSL, content registration, and log filtering; Added integration tests for the Orquesta workflow engine; Added integration tests for the results tracker and action state consumer; Added missing \\init\\_.py to runners fixtures; Added mock callback handler for testing; Added mock query callback runner for testing; Added mock runner test fixture; Added test fixture for async runner; Added test fixtures and unit tests for sensor components; Added test fixtures for CLI execution output formatting; Added test fixtures for invalid Python syntax and missing script files; Added test package for st2reactor; Added test resource for audit logging configuration; Added test resources for plugin loading; Added test utilities for policy evaluation and concurrency; Added tests for pack management actions; Added unit test infrastructure for st2stream; Added unit tests for RBAC validation utility; Added unit tests for SSO and token authentication controllers; Added unit tests for action execution, cancellation, and remote runners; Added unit tests for chatops execution result formatting; Added unit tests for core actions; Added unit tests for scheduler, retry, and concurrency policies; Added unit tests for st2auth components; Added unit tests for st2common services; Added unit tests for stream and execution output API endpoints; Added unit tests for the Inquirer runner; Added unit tests for the NoopRunner; Added unit tests for the dumper and JSON converter components; Added unit tests for the isprime action; Added unit tests for the root controller; Establish test infrastructure for st2client CLI; Expanded action fixture library for testing; Expanded test coverage for v1 API controllers; Expanded unit test coverage for st2common; Expanded unit test coverage for the st2client CLI; Refactor unit tests into separate directory.
Dependencies
Standardize Python dependency management with per-component requirements files
The project has restructured its dependency management by introducing individual \requirements.txt\ files for each component (such as st2client, st2common, st2api, st2auth, st2actions, st2exporter, st2reactor, st2stream, and st2tests) as well as for contrib packs and runners. This change replaces the previous monolithic or shared dependency files with isolated dependency specifications, ensuring that each component's environment is explicitly defined and managed separately. The root \requirements.txt\ and various runner-specific files (e.g., \orquesta\_runner\, \winrm\_runner\) are also updated to reflect these new, granular dependency constraints.
(dependencies) · high confidence
Updated Python dependencies and build configuration
Updated various Python dependencies to their latest stable versions, including requests, paramiko, and pymongo. The build system was refactored to use pip-compile for dependency management, and the Makefile was updated to separate requirements installation from virtualenv creation. Additionally, the project migrated from Travis CI to Circle CI for continuous integration.
(repo-wide) · medium confidence
Housekeeping
Version bump to 3.4dev
The st2reactor package version has been updated to 3.4dev.
st2reactor/st2reactor · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 44 → 53 (+9.1)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 77 → 85 (+7.8)
- Architecture 96 → 90 (-6.3)
- Maturity 51 → 51 (+0.0)
- Readiness 39 → 47 (+7.9)
- Security 34 → 49 (+15.3)
Resolved (94)
- Change coupling clique: garbagecollector.py, rulesengine.py, sensormanager.py (st2reactor/st2reactor/cmd/garbagecollector.py)
- Change coupling: action.py ↔ rule_enforcement.py (st2client/st2client/commands/action.py)
- Change coupling: action.py ↔ triggerinstance.py (st2client/st2client/commands/action.py)
- Change coupling: action_chain_runner.py ↔ noop_runner.py (contrib/runners/action_chain_runner/action_chain_runner/action_chain_runner.py)
- Change coupling: announcement_runner.py ↔ noop_runner.py (contrib/runners/announcement_runner/announcement_runner/announcement_runner.py)
- Change coupling: rule_enforcement.py ↔ trace.py (st2client/st2client/commands/rule_enforcement.py)
- Change coupling: rule_enforcement.py ↔ triggerinstance.py (st2client/st2client/commands/rule_enforcement.py)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (fixed-requirements.txt)
- Critical CVE: [GHSA redacted] (fixed-requirements.txt)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (st2api/st2api/controllers/v1/actionalias.py)
- Duplicated block (10 lines × 2) (st2auth/st2auth/backends/init.py)
- Duplicated block (10 lines × 2) (st2client/st2client/commands/action.py)
- Duplicated block (10 lines × 2) (st2client/st2client/commands/pack.py)
- Duplicated block (10 lines × 2) (st2client/st2client/commands/resource.py)
- Duplicated block (10 lines × 2) (st2client/st2client/commands/rule_enforcement.py)
- Duplicated block (10 lines × 2) (st2client/st2client/utils/interactive.py)
- Duplicated block (10 lines × 2) (st2common/st2common/services/sensor_watcher.py)
- Duplicated block (10 lines × 2) (st2common/st2common/services/workflows.py)
- …and 74 more
New (294)
- Boundary-crossing change coupling: action.py ↔ engine.py (st2common/st2common/services/action.py)
- Boundary-crossing change coupling: action_db.py ↔ engine.py (st2common/st2common/util/action_db.py)
- Change coupling clique: action.py, rule.py, triggerinstance.py (st2client/st2client/commands/action.py)
- Change coupling: entrypoint.py ↔ handler.py (st2actions/st2actions/scheduler/entrypoint.py)
- Change coupling: scheduler.py ↔ handler.py (st2actions/st2actions/cmd/scheduler.py)
- Critical CVE: [GHSA redacted] (fixed-requirements.txt)
- Critical CVE: [GHSA redacted] (fixed-requirements.txt)
- Dependency source pinned to a moving git ref
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 2) (st2actions/st2actions/cmd/st2resultstracker.py)
- Duplicated block (10 lines × 2) (st2api/st2api/cmd/api.py)
- Duplicated block (10 lines × 2) (st2api/st2api/controllers/v1/actionalias.py)
- Duplicated block (10 lines × 2) (st2client/st2client/commands/keyvalue.py)
- Duplicated block (10 lines × 2) (st2client/st2client/commands/pack.py)
- Duplicated block (10 lines × 2) (st2client/st2client/commands/pack.py)
- Duplicated block (10 lines × 2) (st2client/st2client/commands/resource.py)
- Duplicated block (10 lines × 2) (st2common/st2common/services/sensor_watcher.py)
- Duplicated block (10 lines × 5) (st2actions/st2actions/cmd/actionrunner.py)
- Duplicated block (10 lines × 5) (st2client/st2client/commands/action.py)
- …and 274 more
Architecture
- Unchanged — 0 containers · 1 contexts · 0 edges
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
winem/st2 was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 0e8ae756f30ffe2e017c64bff67830abdee7f7c9 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.