From 16f600356f22edb58f8564743730c78d74a67521 Mon Sep 17 00:00:00 2001 From: Pratik Patil Date: Thu, 17 Sep 2026 16:50:45 +0530 Subject: [PATCH 1/2] ci: notify Slack when the nightly govulncheck fails The nightly job has no failure signal, so seven standard-library advisories sat red for five days while nightly-race failures were triaged the same day from #code-releases. Mirrors the notify step heimdall-v2 uses, including the workflow_dispatch ref input for scanning master or a release branch on demand. Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: Pratik Patil --- .github/workflows/nightly-govulncheck.yml | 22 ++++++++++++++++++++-- 1 file changed, 20 insertions(+), 2 deletions(-) diff --git a/.github/workflows/nightly-govulncheck.yml b/.github/workflows/nightly-govulncheck.yml index 7f21a150d5..bfbabb7e04 100644 --- a/.github/workflows/nightly-govulncheck.yml +++ b/.github/workflows/nightly-govulncheck.yml @@ -4,6 +4,10 @@ on: schedule: - cron: '0 2 * * *' workflow_dispatch: + inputs: + ref: + description: Branch to scan + default: develop concurrency: group: nightly-govulncheck-${{ github.ref }} @@ -11,15 +15,17 @@ concurrency: jobs: govulncheck: - name: Run govulncheck on develop + name: Run govulncheck on ${{ inputs.ref || 'develop' }} runs-on: ubuntu24.04-16core-64GB-600SSD-bor permissions: contents: read + env: + HAS_SLACK_WEBHOOK: ${{ secrets.SLACK_WEBHOOK != '' }} steps: - uses: actions/checkout@v5 with: - ref: develop + ref: ${{ inputs.ref || 'develop' }} - uses: actions/setup-go@v6 with: @@ -36,3 +42,15 @@ jobs: - name: Run govulncheck run: make vulncheck + + - name: Notify Slack on failure + if: failure() && env.HAS_SLACK_WEBHOOK == 'true' + continue-on-error: true + uses: slackapi/slack-github-action@fcfb566f8b0aab22203f066d80ca1d7e4b5d05b3 # v1 + with: + payload: | + { + "text": ":warning: Nightly govulncheck failed on ${{ github.repository }} (${{ inputs.ref || 'develop' }})\n<${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}|View Run>" + } + env: + SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK }} From b203013255e8732640f536f133bd9407a421cd30 Mon Sep 17 00:00:00 2001 From: Pratik Patil Date: Fri, 18 Sep 2026 10:14:01 +0530 Subject: [PATCH 2/2] ci: key nightly govulncheck concurrency on the scanned ref Two review findings on the dispatch input. The concurrency group used github.ref, which is the branch the run was dispatched from rather than the branch the input selects for checkout. A manual scan of main dispatched from develop shared a group with the scheduled develop scan and, with cancel-in-progress, cancelled it. The Slack payload interpolated the ref straight into a JSON string literal. git check-ref-format permits a double quote in a branch name, so such a ref produced malformed JSON, and continue-on-error then swallowed the failure -- losing the notification this workflow exists to send. The message is now built with format and JSON-encoded whole. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/nightly-govulncheck.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/nightly-govulncheck.yml b/.github/workflows/nightly-govulncheck.yml index bfbabb7e04..81b8289dc2 100644 --- a/.github/workflows/nightly-govulncheck.yml +++ b/.github/workflows/nightly-govulncheck.yml @@ -10,7 +10,7 @@ on: default: develop concurrency: - group: nightly-govulncheck-${{ github.ref }} + group: nightly-govulncheck-${{ inputs.ref || 'develop' }} cancel-in-progress: true jobs: @@ -50,7 +50,7 @@ jobs: with: payload: | { - "text": ":warning: Nightly govulncheck failed on ${{ github.repository }} (${{ inputs.ref || 'develop' }})\n<${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}|View Run>" + "text": ${{ toJSON(format(':warning: Nightly govulncheck failed on {0} ({1}){2}<{3}/{0}/actions/runs/{4}|View Run>', github.repository, inputs.ref || 'develop', fromJSON('"\n"'), github.server_url, github.run_id)) }} } env: SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK }}