Skip to content
This repository was archived by the owner on Sep 9, 2026. It is now read-only.

OSAC-1684: Temporarily mute Scan workflow logs Slack - #404

Merged
openshift-merge-bot[bot] merged 1 commit into
osac-project:mainfrom
minmzzhang:mute-scan-slack-temp
Jul 30, 2026
Merged

openshift-merge-bot[bot] merged 1 commit into
osac-project:mainfrom
minmzzhang:mute-scan-slack-temp

Conversation

@minmzzhang

@minmzzhang minmzzhang commented Jul 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Follow-up to #393: temporarily mute Slack from Scan workflow logs (mirror of osac-test-infra#280).
  • Unchanged: scan/purge and PR leak comments.
  • should-alert.value stays accurate; AppRole/Vault/notify gated on muted != true. Muted alerts still land in the job summary / ::notice::.
  • Bump cross-repo action pins to post-OSAC-769: Remove legacy SubnetRef field from ComputeInstance CRD #280 osac-test-infra main (9d3ac6c).
  • Re-enable: set MUTE_SLACK_ALERTS=false in .github/workflows/scan-workflow-logs.yml.

Test plan

  • Confirm AppRole/Vault/Notify Slack are skipped when muted
  • Confirm job summary shows Slack muted (temporary) on a leak/failure
  • Confirm a completed e2e still runs scan/purge
  • Confirm leak findings still get a PR comment when an open PR exists

Summary by CodeRabbit

  • Bug Fixes
    • Updated workflow log scanning and cleanup to use the latest scanning action.
    • Added a temporary fallback that records alert conditions in the job summary when Slack notifications are muted.
    • Preserved existing scan, cleanup, and pull request comment behavior.

Mirror osac-test-infra#280: gate AppRole/Vault/notify only while e2e
logs still commonly leak. Keep scan/purge, PR comments, and job
summary. Bump action pins to post-#280 osac-test-infra main.
Flip MUTE_SLACK_ALERTS=false to restore Slack.

Assisted-by: Cursor <noreply@cursor.com>
@openshift-ci-robot

openshift-ci-robot commented Jul 30, 2026 •

Copy link
Copy Markdown

@minmzzhang: This pull request references OSAC-1684 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "5.0.0" version, but no target version was set.

Details

In response to this:

Summary

  • Follow-up to #393: temporarily mute Slack from Scan workflow logs (mirror of osac-test-infra#280).
  • Unchanged: scan/purge and PR leak comments.
  • should-alert.value stays accurate; AppRole/Vault/notify gated on muted != true. Muted alerts still land in the job summary / ::notice::.
  • Bump cross-repo action pins to post-OSAC-769: Remove legacy SubnetRef field from ComputeInstance CRD #280 osac-test-infra main (9d3ac6c).
  • Re-enable: set MUTE_SLACK_ALERTS=false in .github/workflows/scan-workflow-logs.yml.

Test plan

  • Confirm AppRole/Vault/Notify Slack are skipped when muted
  • Confirm job summary shows Slack muted (temporary) on a leak/failure
  • Confirm a completed e2e still runs scan/purge
  • Confirm leak findings still get a PR comment when an open PR exists

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@coderabbitai

coderabbitai Bot commented Jul 30, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: 0b4f98c9-3ab1-4bcd-9562-d0fde11fb3cd

📥 Commits

Reviewing files that changed from the base of the PR and between 7a053d7 and 6ec8519.

📒 Files selected for processing (1)
  • .github/workflows/scan-workflow-logs.yml

Walkthrough

The log-scanning workflow pins its shared scan action, temporarily mutes Slack alerts, skips related credential and notification steps, and records qualifying alerts with upstream links in the GitHub job summary.

Changes

Log alert muting

Layer / File(s) Summary
Alert decision and Slack gating
.github/workflows/scan-workflow-logs.yml
The workflow sets the temporary mute output, preserves alert-condition evaluation, and gates Vault credential access, Slack notification, and unavailable-notification handling on that output. The shared scan action reference is also updated to a new pinned SHA.
Muted alert job summary
.github/workflows/scan-workflow-logs.yml
A conditional step records qualifying muted alerts and the upstream run link in the GitHub step summary, including instructions for re-enabling Slack alerts.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 11
✅ Passed checks (11 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly matches the main change: temporarily muting Slack notifications for the Scan workflow logs.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No-Hardcoded-Secrets ✅ Passed No hardcoded secrets were added; the diff only introduces SHA pins, a temp mute flag, and Vault-derived Slack creds remain external.
No-Weak-Crypto ✅ Passed Changed workflow only adds Slack-muting gating and summary text; no MD5/SHA1/DES/RC4/3DES/Blowfish/ECB or secret/token comparisons found.
No-Injection-Vectors ✅ Passed PASS: The only changes are Slack-muting guards and summary echoes; no SQL, eval/exec, shell=True, yaml.load, os.system, or unsafe HTML sinks were added.
Container-Privileges ✅ Passed Only .github/workflows/scan-workflow-logs.yml changed; it contains no container/K8s privilege flags like privileged, hostPID, hostNetwork, hostIPC, SYS_ADMIN, or allowPrivilegeEscalation.
No-Sensitive-Data-In-Logs ✅ Passed The new logs only surface alert status, run URLs, branch/SHA, and mute notices; no passwords, tokens, PII, or webhook values are echoed, and secret-id is masked.
Ai-Attribution ✅ Passed HEAD commit uses the required Assisted-by trailer for Cursor; no Co-Authored-By AI attribution was found.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@minmzzhang
minmzzhang requested a review from eliorerz July 30, 2026 20:57
@openshift-ci

openshift-ci Bot commented Jul 30, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: eliorerz, minmzzhang

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit 0d91105 into osac-project:main Jul 30, 2026
14 checks passed

This branch was previously deployed

1 inactive deployment
e2e-test — 6ec85190 Deployed Jul 30, 2026 by minmzzhang via e2e-bmaas-full-install / e2e #162
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants