AbsaOSS / AbsaOSS/organizational-workflows

Redesign Teams notification as a single rich Adaptive Card

Abierto
#111 0 comentarios 0 reacciones 1 asignado Reclamado por @tmikula-dev Ver en GitHub
enhancement
Lenguaje dominante
Python
Estrellas
0
Forks
0
Merge medio
5 d 3 h
PR fusionados (30 d)
3

Descripción

## Feature Description

Replace the current PoC Teams notification (up to two bare-markdown cards per run)
with **one rich Adaptive Card** that shows what changed in the run and how the
repository is doing overall.

The card should contain:

- Header with the scanned repository name
- Counters for child issues **opened / reopened / closed** in this run
- The affected child issues, individually linked, with a severity indicator
- A **severity changes** section (findings that escalated / de-escalated)
- A footer with the **current posture**: open child issues per severity
- Buttons linking to the workflow run, the repo's security issues, and AquaSec

Send only when the run actually changed something.

## Proposed Solution

A `security/notifications/` package splitting **what the card says** from **how it's delivered**:

- Pure rendering module — no I/O, logging or env access, so layout is unit-testable
- Small run-context model deriving links from the Actions default env vars (no
workflow wiring needed)
- `NotificationSender` reduced to transport: build, size-check, post

The sync run must additionally return the **child issues closed** during the run and
the **open child issues per severity** at the end.

Teams constraints need research up front — several **fail silently**: supported
markdown subset, list line-breaks, payload size limit, and the encoding required for
emoji.

## Dependencies / Related

- Needs closed-issue and posture data from the alert/issue sync
- Must work over the Power Automate Workflows webhook (O365 connectors are retiring)

## Additional Context

The AquaSec link should point at the general repositories view — per-repository deep links expose sensitive identifiers.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.