Skip to content
This repository has been archived by the owner on Feb 7, 2025. It is now read-only.

Automate Notifying Slack when Snyk Discovers a High or Critical Vulnerability #976

Closed
4 tasks done
halprin opened this issue Mar 26, 2024 · 1 comment
Closed
4 tasks done
Assignees
Labels
devex/opex A development excellence or operational excellence backlog item. Stream 1

Comments

@halprin
Copy link
Contributor

halprin commented Mar 26, 2024

DevEx/OpEx

Write now, @halprin (and maybe others?) get a weekly e-mail of any existing dependency vulnerabilities (via SCA scanning). We should not depend on that. When a new high or critical vulnerability is discovered, let's have Snyk automatically notify our Slack alert channels so we hop on a fix ASAP.

Tasks

  • Wait until we have our CDC Snyk account
  • Integrate Snyk with Slack
    • Request permission from Slack app manager
    • Set up to notifications for alerts channel (Filter Snyk notifications to be high or critical vulnerability only)

Additional Context

Add any other context or screenshots about the work here.

@halprin halprin added the devex/opex A development excellence or operational excellence backlog item. label Mar 26, 2024
@scleary1cs scleary1cs changed the title Automate Notifying PagerDuty when Synk Discovers a High or Critical Vulnerability Automate Notifying PagerDuty when Snyk Discovers a High or Critical Vulnerability Jul 24, 2024
@pluckyswan pluckyswan self-assigned this Nov 26, 2024
@pluckyswan
Copy link
Contributor

@halprin See slack thread for question.

@pluckyswan pluckyswan changed the title Automate Notifying PagerDuty when Snyk Discovers a High or Critical Vulnerability Automate Notifying Slack when Snyk Discovers a High or Critical Vulnerability Nov 27, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
devex/opex A development excellence or operational excellence backlog item. Stream 1
Projects
None yet
Development

No branches or pull requests

3 participants