Select Actions in the left menu. Then select Create Action. Fill in the form.
Name the action.
Add a trigger:
New image version is released
Vulnerability is fixed
Add your filters. You can combine as many filters as relevant:
When set to trigger for new image versions, you can filter by image properties:
Image name
Image category & compliance (Compliance may be FIPS or STIG compatibility)
When set to trigger by fixed vulnerabilities, you can filter by image properties (see above) and vulnerability properties:
Severity
Exploitability
Select the action Send Slack Alert.
Click the button Connect to Slack.
Allow the permissions requested in the popup window. If you are connected to several Slack workspaces, you can select the relevant one from the top right corner.
The form will now show the connected workspace.
List the channels to be notified. The Minimus app can send messages to public channels by default. For private channels, you will need to add the Minimus app to the channel in advance.
Test the action.
If the test is successful, select Create Action to enable it.
Select Actions in the left menu. Then select Create Action. Fill in the form.
Name the action.
Add a trigger:
New image version is released
Vulnerability is fixed
Add your filters. You can combine as many filters as relevant:
When set to trigger for new image versions, you can filter by image properties:
Image name
Image category & compliance (Compliance may be FIPS or STIG compatibility)
When set to trigger by fixed vulnerabilities, you can filter by image properties (see above) and vulnerability properties:
Severity
Exploitability
Select the action Trigger GitHub Actions.
Click the button Connect to GitHub.
Select the relevant GitHub owner or organization.
3. Specify the Owner and Repository.
For example, if your organization GitHub URL looks like https://github.com/myorganization/myproject/ - the owner is myorganization and the repository is myproject.\
4. Test the connection.
If the test is successful, select Create Action to enable it.
Scroll down if necessary
If you previously created an action that connected to your GitHub repo, the popup approval window will open in your general GitHub settings menu - https://github.com/settings/profile.
Scroll down until you see the section for configuring Repository access.
Select the relevant owner and repo as usual and save your selection.
Reset repository selection if necessary
Sometimes, if you previously created an action that connected to a private GitHub repo, the popup approval window will apply your previous selection. In this case, the Repository access section will appear to be “locked” on your previous selection with the Save button disabled.
To activate the Save button, first change the selection to All repositories.
Next, select the relevant owner and repository and save your selection.