Skip to content

Don't re-open completed issues on email reply - #81

Closed
abstractj wants to merge 1 commit into
keycloak:mainfrom
abstractj:issue-77
Closed

abstractj wants to merge 1 commit into
keycloak:mainfrom
abstractj:issue-77

Conversation

@abstractj

Copy link
Copy Markdown
Contributor

When a mailing list reply arrives for a closed issue, check the state reason before re-opening. Issues closed as COMPLETED stay closed with an auto-reply posted to GitHub and sent via email. SecAlert emails are excluded and always re-open. Introduces an extensible auto-reply template system (AutoReplyType enum + properties file + CDI bean).

Closes #77

@abstractj
abstractj requested review from ahus1 and stianst September 1, 2026 14:58
@abstractj
abstractj marked this pull request as draft September 1, 2026 16:26
When a mailing list reply arrives for a closed issue, check the state
reason before re-opening. Issues closed as COMPLETED stay closed with
an auto-reply posted to GitHub and sent via email. SecAlert emails are
excluded and always re-open. Introduces an extensible auto-reply
template system (AutoReplyType enum + properties file + CDI bean).

Closes keycloak#77

Signed-off-by: Bruno Oliveira da Silva <bruno@abstractj.com>
@abstractj
abstractj marked this pull request as ready for review September 1, 2026 16:30

@ahus1 ahus1 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Some time has passed since this issue was opened.

While this sounds reasonable, all examples that I recall are usually replies where we missed sending out a notification to the reporter and the query about the status, we mixed up the attribution, etc.

So unless we have a good list of examples where not re-opening the issue would be the right thing, I would in doubt rather re-open the issue.

The do not re-open the issue when PSIRT sends the final "this issue is now closed" is a different issue.

@abstractj

Copy link
Copy Markdown
Contributor Author

@ahus1 I will defer to you and @stianst to decide how to proceed. My take is that: if an issue was marked as completed, means having the fix merged, the reporter should start a new thread. But I'm fine with whatever we agree.

@ahus1

ahus1 commented Sep 1, 2026

Copy link
Copy Markdown
Member

I agree with the following statement:

if an issue was marked as completed, means having the fix merged, the reporter should start a new thread.

Still, the cases where an issue was re-opened was related to we missing sending out a notification to the reporter, missing attribution, or something else after we moved.

@stianst - If we don't re-open the issue, we will ignore the message. The worst thing would be someone submitting a new CVE, but us ignoring it. To better be safe-than-sorry, I'd like those issues to be re-opened as they are today.

I'm ok to manually close the occasional very rare "thank you" from a reporter.

@stianst

stianst commented Sep 3, 2026

Copy link
Copy Markdown
Collaborator

I had the impression this was a bigger issue than it actually is; seems there's only 8 issues that was closed as completed and has the re-opened-by-bot label (well there was 9, but one was closed as completed by mistake).

6 will be fixed by #82; and the remaining two where as @ahus1 pointed out due to missing notifications to the reporter.

I suggest we get #82 deployed, and leave this one open for a while to monitor the issue before making a call.

@abstractj

Copy link
Copy Markdown
Contributor Author

@stianst @ahus1 np on waiting, let's merge what makes sense.

@abstractj
abstractj marked this pull request as draft September 3, 2026 13:15
@abstractj

Copy link
Copy Markdown
Contributor Author

Converted to draft so we get back into it if needed.

@abstractj

Copy link
Copy Markdown
Contributor Author

Closing it for now to reduce the noise, but we can always reopen if needed.

@abstractj abstractj closed this Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Replies to threads will re-open issues that are fixed

3 participants