Slack

Connect Slack so LaunchSafe posts finished scans, new findings and fixes ready for approval to a channel you choose.

Edit on GitHub

Connect

Owners and admins connect Slack under Integrations. Slack asks you to install the LaunchSafe app in your workspace. Then choose a channel: any public channel, or a private one the app was invited to. Send test message checks it. LaunchSafe never reads messages in your workspace.

One Slack workspace belongs to one LaunchSafe organization at a time.

What it posts

  • When a scan finishes, with what a partial scan left out.
  • Each new finding at or above the severity you choose, up to 10 per scan.
  • When a fix is ready, with Review change and Approve and open pull request buttons.

Messages are updated in place as the finding or fix changes. Messages contain titles, severity, status, location and links that open behind your LaunchSafe sign-in. They never contain evidence, excerpts or secrets.

Projects with restricted access are left out unless you include them in the channel settings, because LaunchSafe cannot check who is in a channel.

Approving from Slack

The first time someone presses Approve and open pull request, they get a private message with a one-time link to link their Slack account to their LaunchSafe account. After that, a press approves the fix as that person, with their role and project access checked again. Someone who cannot approve fixes in LaunchSafe cannot approve from Slack.

Not part of this integration

There is no webhook-URL alternative and no per-scan Slack setting. To send events to your own systems, use signed outgoing webhooks under Settings → Webhooks.

On this page