Skip to content

The Security run's Run notification #539

Description

@JacobStephens2

Parent

#427

What to build

When asked to, by the email word or the User config, a Security run sends one Run notification when it ends. It says how the audit ended, and lists each Security finding's severity (when it has one), title and the link to its private record. It never includes a finding's write-up, because the message passes through Resend, a third party. A skipped Security run sends none.

Acceptance criteria

  • A Security run asked to send one sends a single notification when it ends, through the Resend stand-in, however it ended short of being skipped.
  • The notification lists every finding the run recorded, with its severity when it has one, its title and its private link, and contains no part of a finding's description.
  • A skipped Security run sends none.
  • Failing to send it never changes the run's outcome.

Metadata

Metadata

Assignees

No one assigned

    Labels

    ready-for-agentFully specified, ready for an AFK agent

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions