Modifications needed for AppSecWorkflow automations
Having worked triage rotation this week for appsec and used the new traiger dashboard, I observed the following behavior that should be investigated and corrected:
-
This MR is for PSIRT but is using a template that asks them to add AppSecWorkflow::newwhich leads to these issues appearing in ourAPPSEC->Pinged (New)queue in the dashboard when they are for PSIRT.- Additionally, this should not be an SLA breach because Kat responded within our SLA.
-
This MR Is showing in both Pinged (New)andCustom SASTqueues in the dashboard, not sure why When the thread that pinged AppSec for SAST rule violations isresolved, automation should changeappsec-sast-pingtoresolvedand, if theAppSecWorkflowlabel is set, this label should be moved tocomplete -
[This MR](https://docs.google.com/document/d/1nBCwW7zTEmXdwUipj9LdSoPUXAxoEksRP8iS82old18/edit#2087 - feat: add OAuth2 authentication flow for MCP server connections) has AppSecResolutoinSLA::breachedso it is showing under Pinged (new) -> Breached. TheAppSecWorkflow::completelabel has been applied, so I would expect it to disappear from thePinged (new)queue in the dashboard. -
The following Issues were marked AppSecWorkflow::completebut are still inPinged (New)queue in the dashboard. I believe they should no longer show up in this queue: