AbsaOSS / AbsaOSS/organizational-workflows

Redesign Teams notification as a single rich Adaptive Card

未关闭
#111 0 条评论 0 个 reaction 已指派 1 人 已被 @tmikula-dev 认领 在 GitHub 查看
enhancement
主要语言
Python
星标
0
派生
0
平均合并
5 天 3 小时
30 天内合并 PR
3

描述

## Feature Description

Replace the current PoC Teams notification (up to two bare-markdown cards per run)
with **one rich Adaptive Card** that shows what changed in the run and how the
repository is doing overall.

The card should contain:

- Header with the scanned repository name
- Counters for child issues **opened / reopened / closed** in this run
- The affected child issues, individually linked, with a severity indicator
- A **severity changes** section (findings that escalated / de-escalated)
- A footer with the **current posture**: open child issues per severity
- Buttons linking to the workflow run, the repo's security issues, and AquaSec

Send only when the run actually changed something.

## Proposed Solution

A `security/notifications/` package splitting **what the card says** from **how it's delivered**:

- Pure rendering module — no I/O, logging or env access, so layout is unit-testable
- Small run-context model deriving links from the Actions default env vars (no
workflow wiring needed)
- `NotificationSender` reduced to transport: build, size-check, post

The sync run must additionally return the **child issues closed** during the run and
the **open child issues per severity** at the end.

Teams constraints need research up front — several **fail silently**: supported
markdown subset, list line-breaks, payload size limit, and the encoding required for
emoji.

## Dependencies / Related

- Needs closed-issue and posture data from the alert/issue sync
- Must work over the Power Automate Workflows webhook (O365 connectors are retiring)

## Additional Context

The AquaSec link should point at the general repositories view — per-repository deep links expose sensitive identifiers.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。