ci: notify Slack when the nightly govulncheck fails - #2421
Conversation
The nightly job has no failure signal, so seven standard-library advisories sat red for five days while nightly-race failures were triaged the same day from #code-releases. Mirrors the notify step heimdall-v2 uses, including the workflow_dispatch ref input for scanning master or a release branch on demand. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Signed-off-by: Pratik Patil <pratikspatil024@gmail.com>
There was a problem hiding this comment.
Claude Code Review
This repository is configured for manual code reviews. Comment @claude review for a one-time review, or @claude review always to subscribe this PR to a review on every future push.
Tip: disable this comment in your organization's Code Review settings.
There was a problem hiding this comment.
🟡 Changes recommended
Two moderate workflow issues remain unresolved.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Adds Slack notifications for failed nightly govulncheck runs and supports manually selecting the scanned branch.
Changes:
- Adds a configurable
refinput for manual scans. - Sends guarded, pinned-action Slack alerts.
- Preserves scan failures when notification delivery fails.
File summaries
| File | Summary | Findings |
|---|---|---|
.github/workflows/nightly-govulncheck.yml |
Updates branch selection and Slack failure reporting. | Concurrency should use the effective scan ref; the Slack payload should safely JSON-encode the ref. |
Review details
- Files reviewed: 1/1 changed files
- Comments generated: 2
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #2421 +/- ##
========================================
Coverage 55.61% 55.61%
========================================
Files 918 918
Lines 167138 167138
========================================
+ Hits 92947 92958 +11
+ Misses 68722 68718 -4
+ Partials 5469 5462 -7 see 23 files with indirect coverage changes 🚀 New features to boost your workflow:
|
Two review findings on the dispatch input. The concurrency group used github.ref, which is the branch the run was dispatched from rather than the branch the input selects for checkout. A manual scan of main dispatched from develop shared a group with the scheduled develop scan and, with cancel-in-progress, cancelled it. The Slack payload interpolated the ref straight into a JSON string literal. git check-ref-format permits a double quote in a branch name, so such a ref produced malformed JSON, and continue-on-error then swallowed the failure -- losing the notification this workflow exists to send. The message is now built with format and JSON-encoded whole. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
b203013
Summary
Adds a Slack failure notification to
Nightly Govulncheck, so a red nightlyreaches
#code-releasesinstead of sitting unseen in the Actions tab.The job has run nightly since it was added but has never had a failure signal.
It went red on 2026-09-13 with seven standard-library advisories on go1.26.5 and
stayed red for five nights without anyone noticing, while
Nightly Race Testsfailures — same repo, same webhook, same channel — get triaged the same morning
they land. The only difference was the notify step.
This mirrors what heimdall-v2 does in its own
nightly-govulncheck.yml, so thetwo repos report the same way:
HAS_SLACK_WEBHOOKguard at job level, sincesecretscannot be referencedfrom a step-level
if.continue-on-error: trueon the notify step, so a webhook problem nevermasks the real result of the scan.
@v1.workflow_dispatchrefinput defaulting todevelop, which keepsmasterand release branches scannable on demand without editing theworkflow.
developstays the only scheduled scope — its dependency set is asuperset of
master's in steady state, and scanning both just doubles theSlack volume (ci: scope nightly govulncheck to develop heimdall-v2#648 has the full reasoning).
Executed tests
step last.
SLACK_WEBHOOKis present on this repo, and that the webhook islive:
Nightly Race Testsfailures posted through it to#code-releaseson2026-08-25, 08-29, 09-02, 09-06 and 09-07, so the guard evaluates true and
the destination is the intended channel.
inputsis available in bothjobs.<id>.nameand
jobs.<id>.steps.with, and is empty for ascheduleevent, soinputs.ref || 'develop'falls back todevelopon the nightly trigger.Not exercised: the scheduled trigger itself and the notify step firing, neither
of which can be observed until a nightly run fails after this merges. The same
inputs.reffallback merged in heimdall-v2 today and has its first scheduledrun on the same nightly, so if the fallback is wrong it will show up in both at
once — worth a glance at tomorrow's runs.
Rollout notes
CI-only. No consensus, protocol, or operator-facing impact. Expect one Slack
message per failed nightly on
#code-releases; with #2420 merged the jobshould be green and silent.
🤖 Generated with Claude Code