Skip to content

Commit bf2ed5a

Browse files
authored
Add note about sensitive content in notifications (#66)
1 parent b96470b commit bf2ed5a

File tree

2 files changed

+11
-1
lines changed

2 files changed

+11
-1
lines changed

CHANGES.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,7 @@
1+
# UNRELEASED
2+
3+
- [NEW] Added warning for possible sensitive information contained within notifications.
4+
15
# 1.3.0
26

37
- [IMPROVED] Simplified `controls.json` format. Original format is also supported.

doc-source/notifiers.rst

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,13 +6,19 @@ Notifiers
66
=========
77

88
The last phase in a typical framework check run is the notification
9-
system. Multiple notifiers can be targeted as part of this phase by using
9+
system. Multiple notifiers can be targeted as part of this phase by using
1010
the ``--notify`` option on the ``compliance --check`` command. Valid
1111
notifier options are ``stdout``, ``slack``, ``pagerduty``, ``findings``,
1212
``gh_issues`` and, ``locker``. The general idea behind the notification
1313
system is that each ``test_`` can generate a short notification that has the
1414
following components:
1515

16+
**NOTE:** When configuring notifiers, you should be aware of the
17+
possibilitythat notifications may contain sensitive information that can be
18+
sent to less trusted stores like Slack or public git issue trackers. So be
19+
mindful of check notification content as well as the nature of the forum
20+
you intend to send these notifications to.
21+
1622
* title (mandatory): should be a ``property`` of the
1723
``ComplianceCheck``:
1824

0 commit comments

Comments
 (0)