Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Repository Vulnerability Alert webhook is Deprecated and being Removed #68

Open
mhamill2 opened this issue Dec 11, 2023 · 1 comment
Open
Labels
bug Something isn't working

Comments

@mhamill2
Copy link

Describe the bug
The Repository Vulnerability Webhook is deprecated. Although it doesn't seem to have happened yet, the webhook was/is planned to be removed in 2023: https://github.blog/changelog/2022-10-06-new-dependabot-alerts-webhook

There is a new "Dependabot Alert" webhook that replaces the old Repository Vulnerability Alert hook. The app should be updated to support this new webhook. Currently, the data doesn't show up in the dashboards. The records that come into Splunk get tagged with CodeScanning as the eventtype and there are new actions that should be supported as well with this new hook:

Screenshot 2023-12-11 at 8 43 09 AM

To Reproduce
Steps to reproduce the behavior:

  1. Configure GitHub to send Dependabot Alert webhooks to Splunk
  2. See that they are not shown in the dependabot dashboards

Expected behavior
The app should support the Dependabot alert webhook in place of the repository vulnerability alerts hook.

Screenshots
N/A

Desktop (please complete the following information):

  • OS: Mac Ventura 13.6.1
  • Browser: Chrome
  • Version: App version 1.3.2

Additional context
N/A

@mhamill2 mhamill2 added the bug Something isn't working label Dec 11, 2023
@leftrightleft
Copy link
Collaborator

Thanks for brining this up, @mhamill2 ! I'll get on a fix early in the new year.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants