From 6fe5e92afa72a427945cc63b6cd2c1f9ce34f605 Mon Sep 17 00:00:00 2001 From: Josh Sokol Date: Tue, 29 Sep 2026 18:07:56 -0500 Subject: [PATCH] ci: post the per-image scan table to Slack on PR and weekly runs, even with no findings Adds an always_post input to the grype-report action. When true, the Slack message carries one status line per scanned image (clean, findings by severity, or scan did not complete), so a quiet run still proves its scans ran. Co-Authored-By: Claude Sonnet 5.5 --- .github/actions/grype-report/action.yml | 14 +++++++++++++ .github/scripts/grype-scan-summary.sh | 18 +++++++++++----- .github/scripts/grype-slack-digest.sh | 24 ++++++++++++++++++---- .github/workflows/container-validation.yml | 1 + .github/workflows/scheduled-grype-scan.yml | 1 + 5 files changed, 49 insertions(+), 9 deletions(-) diff --git a/.github/actions/grype-report/action.yml b/.github/actions/grype-report/action.yml index af34948..0282ed8 100644 --- a/.github/actions/grype-report/action.yml +++ b/.github/actions/grype-report/action.yml @@ -13,6 +13,12 @@ inputs: description: Slack incoming webhook. When empty, the Slack post is skipped. required: false default: '' + always_post: + description: > + 'true' posts the per-image table to Slack even when there are no findings, so a + quiet run still shows that its scans ran. Otherwise Slack only hears about findings. + required: false + default: 'false' context: description: Text shown in the Slack message (workflow name and branch). required: false @@ -45,7 +51,15 @@ runs: SLACK_WEBHOOK_URL: ${{ inputs.slack_webhook_url }} RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} REF: ${{ inputs.context }} + RESULTS: ${{ inputs.results }} + ALWAYS_POST: ${{ inputs.always_post }} run: | + if [ "$ALWAYS_POST" = "true" ]; then + mkdir -p grype-reports + mapfile -t pairs < <(printf '%s\n' "$RESULTS" | sed '/^[[:space:]]*$/d') + SUMMARY="$(SUMMARY_FORMAT=slack "${{ github.action_path }}/../../scripts/grype-scan-summary.sh" grype-reports "${pairs[@]}")" + export SUMMARY + fi payload="$("${{ github.action_path }}/../../scripts/grype-slack-digest.sh" grype-reports)" if [ -z "$payload" ]; then echo "No Grype findings in any image; nothing to post." diff --git a/.github/scripts/grype-scan-summary.sh b/.github/scripts/grype-scan-summary.sh index fa8fdf9..ee7cfa8 100755 --- a/.github/scripts/grype-scan-summary.sh +++ b/.github/scripts/grype-scan-summary.sh @@ -15,10 +15,14 @@ set -euo pipefail dir="${1:?usage: $0