We include HTML in our System Message for Jenkins for readability purposes, but also sometimes include links as a convenience for users. This can include links to documentation, email, Jira projects, etc..
Recently, we tried adding a deep link to our support channel for Slack. However this is getting blocked by the OWASP Markup Formatter plugin since we have Safe HTML configured.
Since administrators are typically responsible for the System Message, it seems there should be an option to disable Safe HTML for the System Message, but leave it in place across the instance otherwise.
Is there an option somewhere in Jenkins that can disable OWASP formatting for the System Message and leave it in place elsewhere? Or possibly a custom groovy script that can be ran to accomplish something similar?
Maybe there's an OWASP option that allows us to specify the list of allowed apps for deep linking?