Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
30 changes: 30 additions & 0 deletions .github/workflows/release-tag.yml
Original file line number Diff line number Diff line change
Expand Up @@ -777,6 +777,36 @@ jobs:

echo "Published qualification summary to \`${ref}\`." >> "${GITHUB_STEP_SUMMARY}"

notify-prerelease-failure:
name: Notify Prerelease Failure
needs: [release-helm, publish-qualification]
if: failure() && contains(inputs.tag || github.ref_name, '-pre.')
runs-on: ubuntu-latest
timeout-minutes: 2
permissions: {}
steps:
- name: Send Slack notification
continue-on-error: true
env:
SLACK_WEBHOOK_URL: ${{ secrets.SLACK_OPENSHELL_TRIAGE_WEBHOOK_URL }}
SLACK_MENTION: ${{ secrets.SLACK_OPENSHELL_TRIAGE_MENTION }}
RUN_URL: ${{ format('{0}/{1}/actions/runs/{2}/attempts/{3}', github.server_url, github.repository, github.run_id, github.run_attempt) }}
run: |
set -euo pipefail
if [[ -z "${SLACK_WEBHOOK_URL}" ]]; then
echo "::notice::SLACK_OPENSHELL_TRIAGE_WEBHOOK_URL is unset; skipping Slack notification."
exit 0
fi

message=":x: OpenShell prerelease ${RELEASE_TAG} failed (attempt ${GITHUB_RUN_ATTEMPT})."
if [[ -n "${SLACK_MENTION}" ]]; then
message+=" ${SLACK_MENTION}"
fi
jq -n --arg text "${message}" --arg run_url "${RUN_URL}" \
'{text: ($text + "\n<" + $run_url + "|View failed release run>"), unfurl_links: false, unfurl_media: false}' |
curl --fail --silent --show-error --connect-timeout 5 --max-time 15 \
--header 'Content-Type: application/json' --data-binary @- "${SLACK_WEBHOOK_URL}"

publish-fern-docs:
name: Sync and Publish Fern Docs
needs: [compute-versions, release, publish-sdk-typescript, release-helm, trigger-wheel-publish]
Expand Down
7 changes: 7 additions & 0 deletions CI.md
Original file line number Diff line number Diff line change
Expand Up @@ -194,6 +194,13 @@ temporarily informational for tagged releases: the existing findings were
reviewed and accepted for v0.1.0 and will be addressed in 0.1.x releases.
Scanner failures still fail qualification.

Failed pre-release builds send notifications via Slack using a webhook and
at-mentioning the triage engineer with a link to the failure. The webhook is
stored in the repository secret `SLACK_OPENSHELL_TRIAGE_WEBHOOK_URL` and the
mention is stored in the repository secret `SLACK_OPENSHELL_TRIAGE_MENTION`.
Notifications are non-blocking and do not affect release results; an unset
webhook skips sending; an unset mention sends without a mention.

```shell
gh workflow run security-scan.yml --ref main \
-f candidate_ref=v0.1.1-pre.1 \
Expand Down
Loading