AbsaOSS / AbsaOSS/organizational-workflows
Redesign Teams notification as a single rich Adaptive Card
- Lingua principale
- Python
- Stelle
- 0
- Fork
- 0
- Merge medio
- 5g 3h
- PR unite (30g)
- 3
Descrizione
## Feature Description
Replace the current PoC Teams notification (up to two bare-markdown cards per run)
with **one rich Adaptive Card** that shows what changed in the run and how the
repository is doing overall.
The card should contain:
- Header with the scanned repository name
- Counters for child issues **opened / reopened / closed** in this run
- The affected child issues, individually linked, with a severity indicator
- A **severity changes** section (findings that escalated / de-escalated)
- A footer with the **current posture**: open child issues per severity
- Buttons linking to the workflow run, the repo's security issues, and AquaSec
Send only when the run actually changed something.
## Proposed Solution
A `security/notifications/` package splitting **what the card says** from **how it's delivered**:
- Pure rendering module — no I/O, logging or env access, so layout is unit-testable
- Small run-context model deriving links from the Actions default env vars (no
workflow wiring needed)
- `NotificationSender` reduced to transport: build, size-check, post
The sync run must additionally return the **child issues closed** during the run and
the **open child issues per severity** at the end.
Teams constraints need research up front — several **fail silently**: supported
markdown subset, list line-breaks, payload size limit, and the encoding required for
emoji.
## Dependencies / Related
- Needs closed-issue and posture data from the alert/issue sync
- Must work over the Power Automate Workflows webhook (O365 connectors are retiring)
## Additional Context
The AquaSec link should point at the general repositories view — per-repository deep links expose sensitive identifiers.
Guida per i contributori
Apri la guida per i contributori
Valutazione
Questa issue non è ancora stata valutata.