Skip to content

CARRY: ci: format CVE scans and add Slack notification - #7

Draft
eviehoward wants to merge 1 commit into
odh-mainfrom
rhoaieng-96564-trivy-slack-summary
Draft

eviehoward wants to merge 1 commit into
odh-mainfrom
rhoaieng-96564-trivy-slack-summary

Conversation

@eviehoward

@eviehoward eviehoward commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Summary

Add failure-only Slack notifications to daily CVE scans and improve readability of Trivy scans.

Jira ticket

RHOAIENG-96955

Changes

  • Add one failure-only Slack notification job to Cargo Deny; leave the scan unchanged.
  • Add per-image RPM and crate scan results to Trivy logs and the GitHub Step Summary.
  • Keep Rust crate findings failing on Medium, High, and Critical severities.
  • Fail RPM scans only for Critical findings.
  • Report RPM Medium/High findings without failing, with the ProdSec best-effort explanation.
  • Preserve missing crate metadata warning.
  • Restrict Slack delivery to red-hat-data-services/openshell so the ODH-to-RHDS sync produces one notification per failed workflow run.
  • Read the Slack webhook from the SLACK_WEBHOOK_URL GitHub secret.

Testing

  • git diff --check
  • actionlint -shellcheck= -pyflakes= .github/workflows/odh-trivy-images.yml .github/workflows/odh-cargo-deny-advisories.yml
  • mise run -c pre-commit — all passes except pre-existing missing SPDX headers issue
  • Workflows exercised on a test branch and test Slack channel.

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Cargo Deny scan behavior is unchanged.
  • Slack secret is referenced from GitHub Actions and is not committed.

Summary by CodeRabbit

  • Security Scanning
    • Scan results now include per-image summaries of RPM and Rust crate vulnerabilities. Critical RPM findings and medium-or-higher Rust crate findings fail the scan; medium and high RPM findings are reported without failing it.
    • Missing Rust scan metadata generates a warning but does not fail an otherwise clean scan.
  • Notifications
    • Slack notifications are sent when advisory checks or image scans fail.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: e976970f-4502-49bc-a44e-2fe616b76421

📥 Commits

Reviewing files that changed from the base of the PR and between 23ac1e1 and 2904a62.

📒 Files selected for processing (2)
  • .github/workflows/odh-cargo-deny-advisories.yml
  • .github/workflows/odh-trivy-images.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The advisory workflow adds a Slack alert for failures. The image scan workflow separates RPM and Rust crate failure rules, records scan reports and results, and adds a Slack alert for scan failures.

Changes

Advisory failure notification

Layer / File(s) Summary
Notify Slack after advisory failure
.github/workflows/odh-cargo-deny-advisories.yml
When the advisories job fails in red-hat-data-services/openshell, the workflow posts the result and run URL to Slack. HTTP and request errors fail the notification step.

Image scan reporting and alerts

Layer / File(s) Summary
Define scan results and report RPM findings
.github/workflows/odh-trivy-images.yml
The workflow separates RPM and crate severity settings and records scan results. Critical RPM findings, scan errors, and report-rendering errors fail the workflow; medium and high RPM findings do not.
Report Rust crate findings
.github/workflows/odh-trivy-images.yml
The workflow fails for medium, high, or critical crate findings, scan errors, and report-rendering errors. Missing auditable metadata produces a warning and does not fail an otherwise clean crate scan.
Notify Slack after scan failure
.github/workflows/odh-trivy-images.yml
When the scan job fails in red-hat-data-services/openshell, the workflow posts the result and run URL to Slack.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature

Suggested reviewers: christianzaccaria

Merge Risk: ⚪ Minimal · up to 2904a

The workflows preserve crate severity gates, report noncritical RPM findings without failing, and notify Slack only for failed scans in the designated repository. No actionable merge-blocking issue was found; live workflow and Slack delivery remain untested.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main changes: formatting CVE scan results and adding Slack notifications.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@eviehoward
eviehoward force-pushed the rhoaieng-96564-trivy-slack-summary branch 3 times, most recently from 3ec7c4c to 66ce8d6 Compare October 1, 2026 09:33
Signed-off-by: Evie Howard <evhoward@redhat.com>
@eviehoward
eviehoward force-pushed the rhoaieng-96564-trivy-slack-summary branch from 66ce8d6 to 25a4b2b Compare October 1, 2026 10:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant