Repository navigation
docs: clarify what the webhook event covers and warn about SCA duplicate deliveries - #2774
Conversation
quality.analysis.completed reports quality analysis (including SAST and SCA). It does not report coverage, DAST or container scanning, and there is no coverage webhook yet. Adds a "What the event doesn't cover" section and says "quality analysis" in the intro and description. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
|
Overall readability score: 54.3 (🟢 +0)
View detailed metrics🟢 - Shows an increase in readability
Averages:
View metric targets
|
Up to standards ✅🟢 Issues
|
There was a problem hiding this comment.
Pull Request Overview
No merge-blocking issues were identified by the code or quality reviews. Codacy is up to standards with no new issues.
The requested documentation behaviors lack automated validation, and the claims about scanner coverage rely on an external status list. Acceptance criteria should be verified before merging, particularly the API links and generated anchor.
About this PR
- Add documentation validation covering the updated metadata, introduction, exclusions, API/example links, and generated anchor.
Test suggestions
- Verify the page metadata and introduction say the webhook fires when quality analysis finishes.
- Verify the new section documents SAST/SCA coverage and excludes coverage, DAST, and container scanning.
- Verify the coverage API and identifying-commits example links are present and valid.
- Build the documentation with strict validation and verify the new anchor is generated.
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify the page metadata and introduction say the webhook fires when quality analysis finishes.
2. Verify the new section documents SAST/SCA coverage and excludes coverage, DAST, and container scanning.
3. Verify the coverage API and identifying-commits example links are present and valid.
4. Build the documentation with strict validation and verify the new anchor is generated.
Low confidence findings
- Confirm the SAST, SCA, DAST, and container-scanning claims against an authoritative source before relying on them in the documentation.
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
…ommit For organizations with SCA, the SCA run on the head commit of the main branch sends its own quality.analysis.completed delivery. Adds a row to the delivery table and an important note under Delivery behavior, and links to it from the "What the event doesn't cover" section. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Two clarifications on the webhooks page, both from the Slack thread with Amy on 2026-10-06 (https://codacy.slack.com/archives/C0B5EJJAVB3/p1791272301555039).
1. The event covers quality analysis only
The page says Codacy sends an event whenever it "finishes analyzing" a branch or pull request. That reads as all analysis. The event is
quality.analysis.completed, and coverage analysis is a separate analysis that sends nothing yet.getPullRequestCoverageReportsand the existing "identifying commits without coverage data" example for checking coverage in the meantime.2. Organizations with SCA must review how they handle duplicate deliveries
Under Delivery behavior: a new row in the "why you received another delivery" table, and an
importantnote.An SCA run on a commit sends its own
quality.analysis.completeddelivery. It has the samerepository.name,targetandcommitShaas the commit's regular delivery, a newX-Codacy-Deliveryand a latertimestamp, and nothing in the payload says it came from SCA. Itsstatusreflects only the SCA run. The page's current advice, keep the delivery with the latesttimestamp, can therefore replace the quality result with the SCA one. The note tells SCA organizations to review their handling of several deliveries for one commit and to use the API when the difference matters.Sourcing
quality.analysis.completedonly fromPullRequest.FinishedandCommit.RunningTasksEnded, and neither reads coverage.Project.SCAmessage (sent by analysis-scheduler @801ed37) schedules an SCA job for the head commit of the main branch (RepositoryListener.scheduleSCA).SCATaskCreator,AnalysisStatusStoreandTerminator(TaskPayloadFactory.scala:92).TaskTerminator.runpublishesCommit.RunningTasksEndedwith no job-type check, and computesstatusfrom the tasks of that job only (TaskTerminator.scala,filter(_.payload.jobType.contains(requestContext.jobType))).getPullRequestCoverageReportsand the example page already exist in these docs.Follow-up
When a coverage event ships (Linear project "Coverage analysis webhook event", OD-838 covers the docs), the coverage section is removed or rewritten and the new event documented.
Checks run
mkdocs build --strictexit 0.👀 Live preview
🚧 To do
🤖 Generated with Claude Code