Skip to content
This repository was archived by the owner on Sep 9, 2026. It is now read-only.

OSAC-1684: Add scan-workflow-logs listener - #393

Merged
openshift-merge-bot[bot] merged 2 commits into
osac-project:mainfrom
minmzzhang:OSAC-1684-scan-e2e-logs
Jul 30, 2026
Merged

openshift-merge-bot[bot] merged 2 commits into
osac-project:mainfrom
minmzzhang:OSAC-1684-scan-e2e-logs

Conversation

@minmzzhang

@minmzzhang minmzzhang commented Jul 27, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Mirrors the osac-test-infra scan-workflow-logs listener via the cross-repo composite action.
  • Listens for E2E VMaaS Full Install and E2E BMaaS Full Install.
  • Comments sanitized findings on the triggering PR; Slack warns when credential-only findings were purged from artifacts.
  • Cross-repo actions are SHA-pinned; job has timeout-minutes: 15.

Dependencies

Test plan

  • Confirm workflow triggers on completed VMaaS/BMaaS Full Install runs (including cancelled).
  • Verify PR comment appears with sanitized findings when leaks are detected.
  • Confirm Slack notification wording matches osac-test-infra artifact scan/purge behavior.
  • After osac-test-infra#262 merges, bump action pins to that merge commit and spot-check purged credential-only path.

Summary by CodeRabbit

  • New Features
    • Added a “Scan workflow logs” workflow that monitors completed E2E VMaaS/BMaaS install runs and scans generated logs for sensitive-data leaks.
    • When leaks are found, it purges impacted artifacts and posts a sanitized findings summary to the associated pull request when available.
    • Sends Slack notifications indicating whether leak detection and cleanup succeeded.
  • Security
    • Strengthened workflow permissions to follow least-privilege, deny-by-default access patterns.
    • Improves failure visibility by recording notification issues in the run summary when Slack can’t be reached.

@openshift-ci-robot

openshift-ci-robot commented Jul 27, 2026 •

Copy link
Copy Markdown

@minmzzhang: This pull request references OSAC-1684 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "5.0.0" version, but no target version was set.

Details

In response to this:

Summary

  • Mirrors the osac-test-infra scan-e2e-logs listener via the cross-repo composite action.
  • Listens for E2E VMaaS Full Install and E2E BMaaS Full Install.
  • Comments sanitized findings on the triggering PR; Slack warns when credential-only findings were purged from artifacts.
  • Depends on osac-test-infra#262 for artifact purge inside the composite action @main.

Test plan

  • Confirm workflow triggers on completed VMaaS/BMaaS Full Install runs (including cancelled).
  • Verify PR comment appears with sanitized findings when leaks are detected.
  • Confirm Slack notification wording matches osac-test-infra artifact scan/purge behavior.
  • After osac-test-infra#262 merges, pin/use composite @main and spot-check purged credential-only path.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@coderabbitai

coderabbitai Bot commented Jul 27, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Adds a GitHub Actions workflow triggered after selected E2E runs. It scans and purges logs, optionally comments on the matching pull request, retrieves a Slack webhook from Vault when needed, and sends leak or failure notifications.

Changes

E2E log monitoring

Layer / File(s) Summary
Workflow trigger and log scan
.github/workflows/scan-e2e-logs.yml
Triggers on completion of the two E2E workflows, applies scoped permissions and concurrency, and runs the shared scan-and-purge action.
Pull request leak reporting
.github/workflows/scan-e2e-logs.yml
Finds exactly one open pull request for the E2E head SHA, sanitizes findings, and posts a best-effort markdown comment when leaks are detected.
Alert evaluation and Slack notification
.github/workflows/scan-e2e-logs.yml
Evaluates scan and purge outcomes, retrieves the Slack webhook from Vault when alerting is required, sends prioritized status metadata to Slack, and records notification failures.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
  participant UpstreamE2E
  participant ScanWorkflow
  participant ScanAndPurgeLogs
  participant GitHubPRAPI
  participant Vault
  participant NotifySlack
  UpstreamE2E->>ScanWorkflow: workflow_run completion
  ScanWorkflow->>ScanAndPurgeLogs: scan and purge run logs
  ScanAndPurgeLogs-->>ScanWorkflow: scan and purge results
  ScanWorkflow->>GitHubPRAPI: resolve PR and post findings when leaks are found
  ScanWorkflow->>Vault: retrieve Slack webhook when alerting
  Vault-->>ScanWorkflow: Slack webhook URL
  ScanWorkflow->>NotifySlack: send alert with outcome and run metadata
Loading

Possibly related PRs

Suggested reviewers: rgolangh, eranco74

🚥 Pre-merge checks | ✅ 11
✅ Passed checks (11 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No-Hardcoded-Secrets ✅ Passed No hardcoded secrets found; the workflow only references GITHUB_TOKEN and Vault-fetched secret-id/webhook values at runtime.
No-Weak-Crypto ✅ Passed Changed workflow contains no MD5/SHA1/DES/RC4/3DES/Blowfish/ECB or custom crypto; only status/output string checks, not secret comparisons.
No-Injection-Vectors ✅ Passed No unsafe SQL/shell/eval/pickle/yaml patterns found; shell interpolations are quoted and the jq use is static/sanitized.
Container-Privileges ✅ Passed No changed manifest adds privileged settings; the new workflow contains no privileged, hostPID/Network/IPC, SYS_ADMIN, or allowPrivilegeEscalation:true flags.
No-Sensitive-Data-In-Logs ✅ Passed Workflow only logs masked secret-id and sanitized findings; echoed metadata is run/PR info, not passwords, tokens, PII, or customer data.
Ai-Attribution ✅ Passed HEAD commit includes Assisted-by: Cursor <noreply@cursor.com> and no Co-Authored-By trailer appears, satisfying the AI attribution rule.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the new log-scanning listener workflow added in this PR.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/scan-e2e-logs.yml:
- Line 48: Replace the floating `@main` references for scan-and-purge-logs and
notify-slack with the full commit SHA containing the required
osac-test-infra#262 changes. Keep both cross-repository composite actions pinned
to that specific SHA, then update to the tagged release SHA once the change is
merged.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: ec5d38c9-cb96-460e-b0fe-d343d14b7d76

📥 Commits

Reviewing files that changed from the base of the PR and between d864adb and 7256742.

📒 Files selected for processing (1)
  • .github/workflows/scan-e2e-logs.yml

Comment thread .github/workflows/scan-e2e-logs.yml Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/scan-e2e-logs.yml (1)

104-145: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Escape Markdown syntax in sanitized finding cells.

The transforms escape HTML and |, but leave link/code/backslash syntax active. A value such as `[login](https://attacker.example)` can render as a clickable link, and a backslash before | can defeat table escaping. Escape Markdown metacharacters and backslashes in both transforms, ideally through one tested shared helper.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/scan-e2e-logs.yml around lines 104 - 145, Update the
md_cell helper and the jq findings cell helper used when generating the PR
comment to escape Markdown metacharacters and backslashes in addition to HTML
characters and pipe delimiters. Ensure values such as links, code spans, and
backslash-prefixed pipes render as inert table text, and consolidate the
escaping logic through one tested shared helper where the workflow supports it.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In @.github/workflows/scan-e2e-logs.yml:
- Around line 104-145: Update the md_cell helper and the jq findings cell helper
used when generating the PR comment to escape Markdown metacharacters and
backslashes in addition to HTML characters and pipe delimiters. Ensure values
such as links, code spans, and backslash-prefixed pipes render as inert table
text, and consolidate the escaping logic through one tested shared helper where
the workflow supports it.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: d3a2ac01-fdf5-46e4-b041-5af46aed266e

📥 Commits

Reviewing files that changed from the base of the PR and between 258697f and 9cc09b2.

📒 Files selected for processing (1)
  • .github/workflows/scan-e2e-logs.yml

@minmzzhang

Copy link
Copy Markdown
Contributor Author

/retest

@github-actions

Copy link
Copy Markdown

Re-triggered failed runs:

  • E2E VMaaS Full Install (#30383031638)

@minmzzhang minmzzhang changed the title OSAC-1684: Add scan-e2e-logs listener OSAC-1684: Add scan-workflow-logs listener Jul 30, 2026
@minmzzhang
minmzzhang force-pushed the OSAC-1684-scan-e2e-logs branch from 017241d to 4eee046 Compare July 30, 2026 15:12
Mirror osac-test-infra scan-workflow-logs via cross-repo composite
actions. Listen for VMaaS/BMaaS Full Install. Comment sanitized
findings on the triggering PR; Slack warns on purged
credential-only findings.

Hardening: SHA-pin actions, timeout, shared should-alert gate,
bash Slack payload, vault/notify/AppRole success gates,
::error::/summary fallback, fail-fast AppRole reads, and
zizmor dangerous-triggers suppress (no PR-head checkout).

Assisted-by: Cursor <noreply@cursor.com>

@omer-vishlitzky omer-vishlitzky left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm
/approve

@openshift-ci

openshift-ci Bot commented Jul 30, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: eliorerz, minmzzhang, omer-vishlitzky

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit cba56ff into osac-project:main Jul 30, 2026
14 checks passed

This branch was previously deployed

1 inactive deployment
e2e-test — a50f3baa Deployed Jul 30, 2026 by minmzzhang via e2e-vmaas-full-install / e2e #384
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants