Skip to content

ci: notify Slack when the nightly govulncheck fails - #2421

Merged
pratikspatil024 merged 2 commits into
developfrom
ppatil/govulncheck-slack-notify
Sep 18, 2026
Merged

pratikspatil024 merged 2 commits into
developfrom
ppatil/govulncheck-slack-notify

Conversation

@pratikspatil024

Copy link
Copy Markdown
Member

Summary

Adds a Slack failure notification to Nightly Govulncheck, so a red nightly
reaches #code-releases instead of sitting unseen in the Actions tab.

The job has run nightly since it was added but has never had a failure signal.
It went red on 2026-09-13 with seven standard-library advisories on go1.26.5 and
stayed red for five nights without anyone noticing, while Nightly Race Tests
failures — same repo, same webhook, same channel — get triaged the same morning
they land. The only difference was the notify step.

This mirrors what heimdall-v2 does in its own nightly-govulncheck.yml, so the
two repos report the same way:

  • HAS_SLACK_WEBHOOK guard at job level, since secrets cannot be referenced
    from a step-level if.
  • continue-on-error: true on the notify step, so a webhook problem never
    masks the real result of the scan.
  • The action pinned by commit SHA rather than a floating @v1.
  • A workflow_dispatch ref input defaulting to develop, which keeps
    master and release branches scannable on demand without editing the
    workflow. develop stays the only scheduled scope — its dependency set is a
    superset of master's in steady state, and scanning both just doubles the
    Slack volume (ci: scope nightly govulncheck to develop heimdall-v2#648 has the full reasoning).

Executed tests

  • Workflow parses as YAML, and the step list resolves in order with the notify
    step last.
  • Confirmed SLACK_WEBHOOK is present on this repo, and that the webhook is
    live: Nightly Race Tests failures posted through it to #code-releases on
    2026-08-25, 08-29, 09-02, 09-06 and 09-07, so the guard evaluates true and
    the destination is the intended channel.
  • Per GitHub's context reference, inputs is available in both jobs.<id>.name
    and jobs.<id>.steps.with, and is empty for a schedule event, so
    inputs.ref || 'develop' falls back to develop on the nightly trigger.

Not exercised: the scheduled trigger itself and the notify step firing, neither
of which can be observed until a nightly run fails after this merges. The same
inputs.ref fallback merged in heimdall-v2 today and has its first scheduled
run on the same nightly, so if the fallback is wrong it will show up in both at
once — worth a glance at tomorrow's runs.

Rollout notes

CI-only. No consensus, protocol, or operator-facing impact. Expect one Slack
message per failed nightly on #code-releases; with #2420 merged the job
should be green and silent.


🤖 Generated with Claude Code

The nightly job has no failure signal, so seven standard-library advisories
sat red for five days while nightly-race failures were triaged the same day
from #code-releases. Mirrors the notify step heimdall-v2 uses, including the
workflow_dispatch ref input for scanning master or a release branch on demand.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Pratik Patil <pratikspatil024@gmail.com>
@pratikspatil024
pratikspatil024 marked this pull request as ready for review September 17, 2026 11:32
Copilot AI lite review requested due to automatic review settings September 17, 2026 11:32

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

This repository is configured for manual code reviews. Comment @claude review for a one-time review, or @claude review always to subscribe this PR to a review on every future push.

Tip: disable this comment in your organization's Code Review settings.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Two moderate workflow issues remain unresolved.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Adds Slack notifications for failed nightly govulncheck runs and supports manually selecting the scanned branch.

Changes:

  • Adds a configurable ref input for manual scans.
  • Sends guarded, pinned-action Slack alerts.
  • Preserves scan failures when notification delivery fails.
File summaries
File Summary Findings
.github/workflows/nightly-govulncheck.yml Updates branch selection and Slack failure reporting. Concurrency should use the effective scan ref; the Slack payload should safely JSON-encode the ref.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 2
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/nightly-govulncheck.yml
Comment thread .github/workflows/nightly-govulncheck.yml Outdated
marcello33
marcello33 previously approved these changes Sep 17, 2026
@codecov

codecov Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 55.61%. Comparing base (53cb956) to head (b203013).
⚠️ Report is 1 commits behind head on develop.

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff            @@
##           develop    #2421   +/-   ##
========================================
  Coverage    55.61%   55.61%           
========================================
  Files          918      918           
  Lines       167138   167138           
========================================
+ Hits         92947    92958   +11     
+ Misses       68722    68718    -4     
+ Partials      5469     5462    -7     

see 23 files with indirect coverage changes
see 23 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

cffls
cffls previously approved these changes Sep 17, 2026
Two review findings on the dispatch input.

The concurrency group used github.ref, which is the branch the run was
dispatched from rather than the branch the input selects for checkout.
A manual scan of main dispatched from develop shared a group with the
scheduled develop scan and, with cancel-in-progress, cancelled it.

The Slack payload interpolated the ref straight into a JSON string
literal. git check-ref-format permits a double quote in a branch name,
so such a ref produced malformed JSON, and continue-on-error then
swallowed the failure -- losing the notification this workflow exists
to send. The message is now built with format and JSON-encoded whole.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 18, 2026 04:44
@pratikspatil024
pratikspatil024 dismissed stale reviews from cffls and marcello33 via b203013 September 18, 2026 04:44

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

No unresolved issues were identified.

Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@0xrukimedo
0xrukimedo self-requested a review September 18, 2026 05:23
@pratikspatil024
pratikspatil024 merged commit ab895a9 into develop Sep 18, 2026
22 checks passed
@pratikspatil024
pratikspatil024 deleted the ppatil/govulncheck-slack-notify branch September 18, 2026 05:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants