Skip to content

Pick the latest CVE ID when parsing SecAlert response - #83

Merged
stianst merged 1 commit into
keycloak:mainfrom
abstractj:issue-80
Sep 4, 2026
Merged

stianst merged 1 commit into
keycloak:mainfrom
abstractj:issue-80

Conversation

@abstractj

Copy link
Copy Markdown
Contributor

When a SecAlert reply subject references an old CVE (e.g., "Incomplete fix for CVE-2026-9083") while the body contains the newly assigned CVE, the bot picked the wrong one. Now collects all CVE IDs from both subject and body, and selects the one with the highest sequence number.

Closes #80

@ahus1 ahus1 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you, reviewing the test and the code looks good to me.

When a SecAlert reply subject references an old CVE (e.g., "Incomplete
fix for CVE-2026-9083") while the body contains the newly assigned CVE,
the bot picked the wrong one. Now collects all CVE IDs from both subject
and body, and selects the one with the highest sequence number.

Closes keycloak#80

Signed-off-by: Bruno Oliveira da Silva <bruno@abstractj.com>
@stianst
stianst merged commit 13ab76a into keycloak:main Sep 4, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Picking up wrong CVE issue when parsing the response

3 participants