From 0ff1fac45a2e03b7ad87e8545461c9f3900fdcce Mon Sep 17 00:00:00 2001 From: Bruno Oliveira da Silva Date: Thu, 24 Sep 2026 10:00:49 -0300 Subject: [PATCH 1/2] Rename status/cve-request to status/cve-requested and add status/cve-assigned Aligns CVE lifecycle labels for clearer triage visibility. Renames the CVE_REQUEST enum to CVE_REQUESTED to reflect a dispatched request, and introduces CVE_ASSIGNED applied by MailProcessor when SecAlert replies with an assigned CVE ID. Updates all references and tests across SecAlertCommand and MailProcessor. Closes #86 --- .../java/org/keycloak/gh/bot/labels/Status.java | 3 ++- .../gh/bot/security/command/SecAlertCommand.java | 2 +- .../gh/bot/security/email/MailProcessor.java | 9 ++++++--- .../bot/security/command/SecAlertCommandTest.java | 4 ++-- .../gh/bot/security/email/MailProcessorTest.java | 13 ++++++++----- 5 files changed, 19 insertions(+), 12 deletions(-) diff --git a/src/main/java/org/keycloak/gh/bot/labels/Status.java b/src/main/java/org/keycloak/gh/bot/labels/Status.java index 1bf5113..317484a 100644 --- a/src/main/java/org/keycloak/gh/bot/labels/Status.java +++ b/src/main/java/org/keycloak/gh/bot/labels/Status.java @@ -9,7 +9,8 @@ public enum Status { BUMPED_BY_BOT, TRIAGE, REOPENED, - CVE_REQUEST; + CVE_REQUESTED, + CVE_ASSIGNED; @Override public String toString() { diff --git a/src/main/java/org/keycloak/gh/bot/security/command/SecAlertCommand.java b/src/main/java/org/keycloak/gh/bot/security/command/SecAlertCommand.java index a3b4e68..0780716 100644 --- a/src/main/java/org/keycloak/gh/bot/security/command/SecAlertCommand.java +++ b/src/main/java/org/keycloak/gh/bot/security/command/SecAlertCommand.java @@ -78,7 +78,7 @@ private void createNewThread(GHEventPayload.IssueComment payload, String subject if (currentLabels.contains(Status.TRIAGE.toLabel())) { issue.removeLabels(Status.TRIAGE.toLabel()); } - issue.addLabels(Status.CVE_REQUEST.toLabel()); + issue.addLabels(Status.CVE_REQUESTED.toLabel()); String title = issue.getTitle(); if (title != null && !title.startsWith(Constants.CVE_TBD_PREFIX)) { diff --git a/src/main/java/org/keycloak/gh/bot/security/email/MailProcessor.java b/src/main/java/org/keycloak/gh/bot/security/email/MailProcessor.java index 193bfcb..c7b2fb1 100644 --- a/src/main/java/org/keycloak/gh/bot/security/email/MailProcessor.java +++ b/src/main/java/org/keycloak/gh/bot/security/email/MailProcessor.java @@ -340,11 +340,14 @@ void applyCveIdFromSecAlert(GHIssue issue, String subject, String body) throws I .map(GHLabel::getName) .toList(); - if (labelNames.contains(Status.CVE_REQUEST.toLabel())) { - issue.removeLabels(Status.CVE_REQUEST.toLabel()); - LOGGER.infof("Removed %s label from issue #%d", Status.CVE_REQUEST.toLabel(), issue.getNumber()); + if (labelNames.contains(Status.CVE_REQUESTED.toLabel())) { + issue.removeLabels(Status.CVE_REQUESTED.toLabel()); + LOGGER.infof("Removed %s label from issue #%d", Status.CVE_REQUESTED.toLabel(), issue.getNumber()); } + issue.addLabels(Status.CVE_ASSIGNED.toLabel()); + LOGGER.infof("Added %s label to issue #%d", Status.CVE_ASSIGNED.toLabel(), issue.getNumber()); + if (!labelNames.contains(Kind.CVE.toLabel())) { issue.addLabels(Kind.CVE.toLabel()); LOGGER.infof("Added %s label to issue #%d", Kind.CVE.toLabel(), issue.getNumber()); diff --git a/src/test/java/org/keycloak/gh/bot/security/command/SecAlertCommandTest.java b/src/test/java/org/keycloak/gh/bot/security/command/SecAlertCommandTest.java index 02e80b7..8e325af 100644 --- a/src/test/java/org/keycloak/gh/bot/security/command/SecAlertCommandTest.java +++ b/src/test/java/org/keycloak/gh/bot/security/command/SecAlertCommandTest.java @@ -77,7 +77,7 @@ void newThread_sendsEmailWithGhiTaggedSubject() throws Exception { "CVE-2026-1234 XSS in admin console - #GHI-42", "Please triage this vulnerability."); verify(issue, never()).comment(anyString()); verify(issue).removeLabels(Status.TRIAGE.toLabel()); - verify(issue).addLabels(Status.CVE_REQUEST.toLabel()); + verify(issue).addLabels(Status.CVE_REQUESTED.toLabel()); verify(issue).setTitle("[CVE-TBD] Wildcard Redirect URI vulnerability"); verify(comment).createReaction(ReactionContent.PLUS_ONE); } @@ -111,7 +111,7 @@ void newThread_skipsRemoveTriageLabelWhenNotPresent() throws Exception { command.run(payload); verify(issue, never()).removeLabels(any(String[].class)); - verify(issue).addLabels(Status.CVE_REQUEST.toLabel()); + verify(issue).addLabels(Status.CVE_REQUESTED.toLabel()); verify(issue).setTitle("[CVE-TBD] Some issue title"); verify(comment).createReaction(ReactionContent.PLUS_ONE); } diff --git a/src/test/java/org/keycloak/gh/bot/security/email/MailProcessorTest.java b/src/test/java/org/keycloak/gh/bot/security/email/MailProcessorTest.java index 66328a7..387d3b7 100644 --- a/src/test/java/org/keycloak/gh/bot/security/email/MailProcessorTest.java +++ b/src/test/java/org/keycloak/gh/bot/security/email/MailProcessorTest.java @@ -82,14 +82,15 @@ void applyCveIdFromSecAlert_replacesTitleAndRemovesCveRequestLabel() throws Exce when(issue.getNumber()).thenReturn(42); GHLabel cveRequestLabel = mock(GHLabel.class); - when(cveRequestLabel.getName()).thenReturn(Status.CVE_REQUEST.toLabel()); + when(cveRequestLabel.getName()).thenReturn(Status.CVE_REQUESTED.toLabel()); when(issue.getLabels()).thenReturn(List.of(cveRequestLabel)); MailProcessor processor = new MailProcessor(); processor.applyCveIdFromSecAlert(issue, "Re: CVE-2026-9999 XSS in admin console", "body"); verify(issue).setTitle("[CVE-2026-9999] XSS in admin console"); - verify(issue).removeLabels(Status.CVE_REQUEST.toLabel()); + verify(issue).removeLabels(Status.CVE_REQUESTED.toLabel()); + verify(issue).addLabels(Status.CVE_ASSIGNED.toLabel()); verify(issue).addLabels(Kind.CVE.toLabel()); } @@ -104,7 +105,8 @@ void applyCveIdFromSecAlert_doesNotRemoveLabelWhenNotPresent() throws Exception processor.applyCveIdFromSecAlert(issue, "Re: CVE-2026-9999 XSS in admin console", "body"); verify(issue).setTitle("[CVE-2026-9999] XSS in admin console"); - verify(issue, never()).removeLabels(Status.CVE_REQUEST.toLabel()); + verify(issue, never()).removeLabels(Status.CVE_REQUESTED.toLabel()); + verify(issue).addLabels(Status.CVE_ASSIGNED.toLabel()); verify(issue).addLabels(Kind.CVE.toLabel()); } @@ -128,14 +130,15 @@ void applyCveIdFromSecAlert_extractsCveFromBodyWhenNotInSubject() throws Excepti when(issue.getNumber()).thenReturn(10); GHLabel cveRequestLabel = mock(GHLabel.class); - when(cveRequestLabel.getName()).thenReturn(Status.CVE_REQUEST.toLabel()); + when(cveRequestLabel.getName()).thenReturn(Status.CVE_REQUESTED.toLabel()); when(issue.getLabels()).thenReturn(List.of(cveRequestLabel)); MailProcessor processor = new MailProcessor(); processor.applyCveIdFromSecAlert(issue, "No CVE in subject", "Assigned CVE-2026-5555 for this issue."); verify(issue).setTitle("[CVE-2026-5555] SSRF vulnerability"); - verify(issue).removeLabels(Status.CVE_REQUEST.toLabel()); + verify(issue).removeLabels(Status.CVE_REQUESTED.toLabel()); + verify(issue).addLabels(Status.CVE_ASSIGNED.toLabel()); verify(issue).addLabels(Kind.CVE.toLabel()); } From ef2e6753e17c436615a65207998c603afdb1b989 Mon Sep 17 00:00:00 2001 From: stianst Date: Fri, 25 Sep 2026 09:04:56 +0200 Subject: [PATCH 2/2] Fix test Signed-off-by: stianst --- .../org/keycloak/gh/bot/security/email/MailProcessorTest.java | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/test/java/org/keycloak/gh/bot/security/email/MailProcessorTest.java b/src/test/java/org/keycloak/gh/bot/security/email/MailProcessorTest.java index 387d3b7..c2666db 100644 --- a/src/test/java/org/keycloak/gh/bot/security/email/MailProcessorTest.java +++ b/src/test/java/org/keycloak/gh/bot/security/email/MailProcessorTest.java @@ -228,7 +228,7 @@ void applyCveIdFromSecAlert_picksNewCveOverOldInSubject() throws Exception { when(issue.getNumber()).thenReturn(992); GHLabel cveRequestLabel = mock(GHLabel.class); - when(cveRequestLabel.getName()).thenReturn(Status.CVE_REQUEST.toLabel()); + when(cveRequestLabel.getName()).thenReturn(Status.CVE_REQUESTED.toLabel()); when(issue.getLabels()).thenReturn(List.of(cveRequestLabel)); MailProcessor processor = new MailProcessor(); @@ -236,7 +236,7 @@ void applyCveIdFromSecAlert_picksNewCveOverOldInSubject() throws Exception { "*Reference : CVE-2026-19729\n*Embargo status : Public"); verify(issue).setTitle("[CVE-2026-19729] Incomplete fix for CVE-2026-9083"); - verify(issue).removeLabels(Status.CVE_REQUEST.toLabel()); + verify(issue).removeLabels(Status.CVE_REQUESTED.toLabel()); verify(issue).addLabels(Kind.CVE.toLabel()); }