Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion src/main/java/org/keycloak/gh/bot/labels/Status.java
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,8 @@ public enum Status {
BUMPED_BY_BOT,
TRIAGE,
REOPENED,
CVE_REQUEST;
CVE_REQUESTED,
CVE_ASSIGNED;

@Override
public String toString() {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -78,7 +78,7 @@ private void createNewThread(GHEventPayload.IssueComment payload, String subject
if (currentLabels.contains(Status.TRIAGE.toLabel())) {
issue.removeLabels(Status.TRIAGE.toLabel());
}
issue.addLabels(Status.CVE_REQUEST.toLabel());
issue.addLabels(Status.CVE_REQUESTED.toLabel());

String title = issue.getTitle();
if (title != null && !title.startsWith(Constants.CVE_TBD_PREFIX)) {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -340,11 +340,14 @@ void applyCveIdFromSecAlert(GHIssue issue, String subject, String body) throws I
.map(GHLabel::getName)
.toList();

if (labelNames.contains(Status.CVE_REQUEST.toLabel())) {
issue.removeLabels(Status.CVE_REQUEST.toLabel());
LOGGER.infof("Removed %s label from issue #%d", Status.CVE_REQUEST.toLabel(), issue.getNumber());
if (labelNames.contains(Status.CVE_REQUESTED.toLabel())) {
issue.removeLabels(Status.CVE_REQUESTED.toLabel());
LOGGER.infof("Removed %s label from issue #%d", Status.CVE_REQUESTED.toLabel(), issue.getNumber());
}

issue.addLabels(Status.CVE_ASSIGNED.toLabel());
LOGGER.infof("Added %s label to issue #%d", Status.CVE_ASSIGNED.toLabel(), issue.getNumber());

if (!labelNames.contains(Kind.CVE.toLabel())) {
issue.addLabels(Kind.CVE.toLabel());
LOGGER.infof("Added %s label to issue #%d", Kind.CVE.toLabel(), issue.getNumber());
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -77,7 +77,7 @@ void newThread_sendsEmailWithGhiTaggedSubject() throws Exception {
"CVE-2026-1234 XSS in admin console - #GHI-42", "Please triage this vulnerability.");
verify(issue, never()).comment(anyString());
verify(issue).removeLabels(Status.TRIAGE.toLabel());
verify(issue).addLabels(Status.CVE_REQUEST.toLabel());
verify(issue).addLabels(Status.CVE_REQUESTED.toLabel());
verify(issue).setTitle("[CVE-TBD] Wildcard Redirect URI vulnerability");
verify(comment).createReaction(ReactionContent.PLUS_ONE);
}
Expand Down Expand Up @@ -111,7 +111,7 @@ void newThread_skipsRemoveTriageLabelWhenNotPresent() throws Exception {
command.run(payload);

verify(issue, never()).removeLabels(any(String[].class));
verify(issue).addLabels(Status.CVE_REQUEST.toLabel());
verify(issue).addLabels(Status.CVE_REQUESTED.toLabel());
verify(issue).setTitle("[CVE-TBD] Some issue title");
verify(comment).createReaction(ReactionContent.PLUS_ONE);
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -82,14 +82,15 @@ void applyCveIdFromSecAlert_replacesTitleAndRemovesCveRequestLabel() throws Exce
when(issue.getNumber()).thenReturn(42);

GHLabel cveRequestLabel = mock(GHLabel.class);
when(cveRequestLabel.getName()).thenReturn(Status.CVE_REQUEST.toLabel());
when(cveRequestLabel.getName()).thenReturn(Status.CVE_REQUESTED.toLabel());
when(issue.getLabels()).thenReturn(List.of(cveRequestLabel));

MailProcessor processor = new MailProcessor();
processor.applyCveIdFromSecAlert(issue, "Re: CVE-2026-9999 XSS in admin console", "body");

verify(issue).setTitle("[CVE-2026-9999] XSS in admin console");
verify(issue).removeLabels(Status.CVE_REQUEST.toLabel());
verify(issue).removeLabels(Status.CVE_REQUESTED.toLabel());
verify(issue).addLabels(Status.CVE_ASSIGNED.toLabel());
verify(issue).addLabels(Kind.CVE.toLabel());
}

Expand All @@ -104,7 +105,8 @@ void applyCveIdFromSecAlert_doesNotRemoveLabelWhenNotPresent() throws Exception
processor.applyCveIdFromSecAlert(issue, "Re: CVE-2026-9999 XSS in admin console", "body");

verify(issue).setTitle("[CVE-2026-9999] XSS in admin console");
verify(issue, never()).removeLabels(Status.CVE_REQUEST.toLabel());
verify(issue, never()).removeLabels(Status.CVE_REQUESTED.toLabel());
verify(issue).addLabels(Status.CVE_ASSIGNED.toLabel());
verify(issue).addLabels(Kind.CVE.toLabel());
}

Expand All @@ -128,14 +130,15 @@ void applyCveIdFromSecAlert_extractsCveFromBodyWhenNotInSubject() throws Excepti
when(issue.getNumber()).thenReturn(10);

GHLabel cveRequestLabel = mock(GHLabel.class);
when(cveRequestLabel.getName()).thenReturn(Status.CVE_REQUEST.toLabel());
when(cveRequestLabel.getName()).thenReturn(Status.CVE_REQUESTED.toLabel());
when(issue.getLabels()).thenReturn(List.of(cveRequestLabel));

MailProcessor processor = new MailProcessor();
processor.applyCveIdFromSecAlert(issue, "No CVE in subject", "Assigned CVE-2026-5555 for this issue.");

verify(issue).setTitle("[CVE-2026-5555] SSRF vulnerability");
verify(issue).removeLabels(Status.CVE_REQUEST.toLabel());
verify(issue).removeLabels(Status.CVE_REQUESTED.toLabel());
verify(issue).addLabels(Status.CVE_ASSIGNED.toLabel());
verify(issue).addLabels(Kind.CVE.toLabel());
}

Expand Down Expand Up @@ -225,15 +228,15 @@ void applyCveIdFromSecAlert_picksNewCveOverOldInSubject() throws Exception {
when(issue.getNumber()).thenReturn(992);

GHLabel cveRequestLabel = mock(GHLabel.class);
when(cveRequestLabel.getName()).thenReturn(Status.CVE_REQUEST.toLabel());
when(cveRequestLabel.getName()).thenReturn(Status.CVE_REQUESTED.toLabel());
when(issue.getLabels()).thenReturn(List.of(cveRequestLabel));

MailProcessor processor = new MailProcessor();
processor.applyCveIdFromSecAlert(issue, "Incomplete fix for CVE-2026-9083 - #GHI-992",
"*Reference : CVE-2026-19729\n*Embargo status : Public");

verify(issue).setTitle("[CVE-2026-19729] Incomplete fix for CVE-2026-9083");
verify(issue).removeLabels(Status.CVE_REQUEST.toLabel());
verify(issue).removeLabels(Status.CVE_REQUESTED.toLabel());
verify(issue).addLabels(Kind.CVE.toLabel());
}

Expand Down
Loading