AbsaOSS / AbsaOSS/organizational-workflows

Investigate and fix severity-to-priority mapping for enterprise repositories

Aperta
#20 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
enhancement
Lingua principale
Python
Stelle
0
Fork
0
Merge medio
5g 3h
PR unite (30g)
3

Descrizione

### Feature Description

Investigate why severity-to-priority mapping works for AbsaOSS-to-AbsaOSS repositories but fails for enterprise repositories, and provide a fix or a documented workaround.

### Problem / Opportunity

The GraphQL call used for severity-to-priority mapping fails on enterprise repositories with:

```
WARNING - GraphQL call failed: gh: Resource protected by organization SAML enforcement. You must grant your Personal Access token access to this organization.
```

This blocks adoption of the workflow for enterprise-protected repositories.

### Acceptance Criteria

1. Root cause of the SAML enforcement failure is identified and documented.
2. Either a fix is implemented that supports enterprise repositories, OR
3. An alternative solution is provided: a standalone mapping script where users supply their own SAML-authorized token and target API endpoint.
4. The workaround/solution is documented in the repository.

### Proposed Solution

Investigate whether the GraphQL query can be adapted to pass a user-supplied token scoped to the enterprise org.
As an alternative, provide a standalone Python/shell script that accepts `--token` and `--api-url` parameters for mapping severity to priority without relying on the shared workflow token.

### Dependencies / Related

_No response_

### Additional Context

_No response_

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.