CARRY: ci: format CVE scans and add Slack notification - #7
eviehoward wants to merge 1 commit into
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueNo actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe advisory workflow adds a Slack alert for failures. The image scan workflow separates RPM and Rust crate failure rules, records scan reports and results, and adds a Slack alert for scan failures. ChangesAdvisory failure notification
Image scan reporting and alerts
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Feature Suggested reviewers: Merge Risk: ⚪ Minimal · up to The workflows preserve crate severity gates, report noncritical RPM findings without failing, and notify Slack only for failed scans in the designated repository. No actionable merge-blocking issue was found; live workflow and Slack delivery remain untested. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
3ec7c4c to
66ce8d6
Compare
Signed-off-by: Evie Howard <evhoward@redhat.com>
66ce8d6 to
25a4b2b
Compare
Summary
Add failure-only Slack notifications to daily CVE scans and improve readability of Trivy scans.
Jira ticket
RHOAIENG-96955
Changes
red-hat-data-services/openshellso the ODH-to-RHDS sync produces one notification per failed workflow run.SLACK_WEBHOOK_URLGitHub secret.Testing
git diff --checkactionlint -shellcheck= -pyflakes= .github/workflows/odh-trivy-images.yml .github/workflows/odh-cargo-deny-advisories.ymlmise run -c pre-commit— all passes except pre-existing missing SPDX headers issueChecklist
Summary by CodeRabbit