Skip to content

Post the per-image Grype scan table to Slack on PR and weekly runs - #175

Merged
jsokol merged 1 commit into
testingfrom
FIX-grype-slack-always-post-summary
Sep 30, 2026
Merged

jsokol merged 1 commit into
testingfrom
FIX-grype-slack-always-post-summary

Conversation

@jsokol

@jsokol jsokol commented Sep 29, 2026

Copy link
Copy Markdown
Member

Description

Follow-up to #174. A clean run posted nothing to Slack, so there was no way to tell a clean run from a run that never happened. PR validation and the weekly scan now always post the per-image table.

  • New always_post input on the grype-report action (default false). When true, the Slack message includes one status line per scanned image: ✅ No findings, ⚠️ N findings (by severity), or ❌ scan did not complete. With findings, the table appears above the vulnerability list.
  • Enabled for container-validation.yml (PR runs) and scheduled-grype-scan.yml (weekly). The publish-time report keeps the findings-only behaviour.
  • grype-scan-summary.sh gains a SUMMARY_FORMAT=slack mode; grype-slack-digest.sh accepts an optional SUMMARY and emits a payload even with no findings when it is set. Without SUMMARY it still emits nothing on a clean run.
  • Fixed the digest script's empty-report-directory case under set -u, so a run where no scan produced a report still posts the all-❌ table instead of failing.

Release Notes

N/A (CI only).

Testing

  • Ran the digest script against sample report sets for: all clean, mixed clean/did-not-complete, findings plus summary, no summary + clean (emits nothing), and no reports + summary (all ❌). Output checked with jq.
  • ShellCheck and actionlint clean (aside from the existing create_new_tag.yml note); YAML parses.
  • Not tested until it runs on GitHub: the composite action's new Slack step. This PR's own validation run posts to the channel, so that run is the check.

Notes for reviewers

Every PR run will now post one message to the channel, including from later pushes to the same PR. Fork PRs skip the post (no secret).

…n with no findings

Adds an always_post input to the grype-report action. When true, the Slack
message carries one status line per scanned image (clean, findings by severity,
or scan did not complete), so a quiet run still proves its scans ran.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@jsokol
jsokol marked this pull request as ready for review September 30, 2026 01:01
@jsokol
jsokol merged commit 49dfe39 into testing Sep 30, 2026
8 checks passed
@jsokol
jsokol deleted the FIX-grype-slack-always-post-summary branch September 30, 2026 01:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant