feat(ci): tag triaged Linear issues with the source repository - #1345

Merged
brendan-kellam merged 1 commit into
mainfrom
brendan/vuln-triage-repo-label
Jun 18, 2026
Merged

feat(ci): tag triaged Linear issues with the source repository#1345
brendan-kellam merged 1 commit into
mainfrom
brendan/vuln-triage-repo-label

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Summary

Tags each Linear issue created by the vulnerability-triage workflow with a label named after the source repository (e.g. sourcebot-dev/sourcebot), in addition to the existing CVE label. This makes triaged issues filterable by repo in Linear.

How

  • In the Match existing Linear issues step, after resolving the team/CVE-label/state/viewer, resolve a team label whose name equals ${{ github.repository }}. If it doesn't exist yet, create it via issueLabelCreate (team-scoped, like the CVE label). Expose it as a repo_label_id step output.
  • In the Create Linear issues step, attach both the CVE label and the repository label (any that failed to resolve are dropped).

The label is created at most once — subsequent runs find the existing one. Reopened issues are unchanged (they already carry their labels).

Notes

  • The label uses the full github.repository (owner/repo) to match the [owner/repo] title-prefix scoping already used, which keeps it unambiguous across sibling repos (e.g. sourcebot-dev/sourcebot-helm-chart). Easy to switch to the short repo name if you'd prefer.
  • No CHANGELOG entry — internal CI/security-automation change, not user-facing.

Testing

Verified the label-array construction in jq (both labels present, repo label missing → only CVE, both missing → no labelIds sent) and that the workflow YAML parses.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Improved vulnerability issue tracking workflow to include repository-specific labeling in addition to existing categorization. Enhanced label resolution and assignment logic for better organization of security-related issues.

Resolve (or create) a team label named after the repository and attach it to
each created CVE issue alongside the existing "CVE" label, so issues are
filterable by their source repo in Linear.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@brendan-kellam your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

Pull request was closed or merged during review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: f1b15233-e845-48d5-b726-c0a86ece9066

📥 Commits

Reviewing files that changed from the base of the PR and between 18d41ba and 09e6caa.

📒 Files selected for processing (1)
  • .github/workflows/vulnerability-triage.yml

Walkthrough

The vulnerability triage workflow's "Match existing Linear issues" step is extended to query or create a Linear label named after github.repository and export its id. The "Create Linear issues" step consumes that id, warns if unavailable, and assigns both the CVE label and the repository label when creating new issues.

Changes

Repository-scoped Linear label resolution and assignment

Layer / File(s)Summary
Resolve/create repo label in matching step and export id
.github/workflows/vulnerability-triage.yml
The matching step queries Linear for a label named after github.repository, creates it if it does not exist, and writes repo_label_id to GITHUB_OUTPUT.
Consume repo label id and apply to new issues
.github/workflows/vulnerability-triage.yml
The creation step reads REPO_LABEL_ID from the match step outputs, logs a warning when it is unavailable, and builds a filtered labelIds array combining the CVE label id and the repository label id before passing it to issue creation.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#1334: Updates the same "Match existing Linear issues" and "Create Linear issues" steps in vulnerability-triage.yml to rewire Linear metadata resolution, directly preceding the label changes introduced here.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately reflects the main change: adding repository-scoped labels to Linear issues in the vulnerability-triage workflow.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/vuln-triage-repo-label

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@brendan-kellam
brendan-kellam merged commit 5bd62b3 into mainJun 18, 2026
7 of 8 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/vuln-triage-repo-label branch June 18, 2026 00:18
@github-actionsgithub-actionsBot mentioned this pull request Jun 18, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(ci): tag triaged Linear issues with the source repository - #1345

Merged
brendan-kellam merged 1 commit into
mainfrom
brendan/vuln-triage-repo-label
Jun 18, 2026
Merged

feat(ci): tag triaged Linear issues with the source repository#1345
brendan-kellam merged 1 commit into
mainfrom
brendan/vuln-triage-repo-label

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Summary

Tags each Linear issue created by the vulnerability-triage workflow with a label named after the source repository (e.g. sourcebot-dev/sourcebot), in addition to the existing CVE label. This makes triaged issues filterable by repo in Linear.

How

  • In the Match existing Linear issues step, after resolving the team/CVE-label/state/viewer, resolve a team label whose name equals ${{ github.repository }}. If it doesn't exist yet, create it via issueLabelCreate (team-scoped, like the CVE label). Expose it as a repo_label_id step output.
  • In the Create Linear issues step, attach both the CVE label and the repository label (any that failed to resolve are dropped).

The label is created at most once — subsequent runs find the existing one. Reopened issues are unchanged (they already carry their labels).

Notes

  • The label uses the full github.repository (owner/repo) to match the [owner/repo] title-prefix scoping already used, which keeps it unambiguous across sibling repos (e.g. sourcebot-dev/sourcebot-helm-chart). Easy to switch to the short repo name if you'd prefer.
  • No CHANGELOG entry — internal CI/security-automation change, not user-facing.

Testing

Verified the label-array construction in jq (both labels present, repo label missing → only CVE, both missing → no labelIds sent) and that the workflow YAML parses.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Improved vulnerability issue tracking workflow to include repository-specific labeling in addition to existing categorization. Enhanced label resolution and assignment logic for better organization of security-related issues.

Resolve (or create) a team label named after the repository and attach it to
each created CVE issue alongside the existing "CVE" label, so issues are
filterable by their source repo in Linear.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@brendan-kellam your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

Pull request was closed or merged during review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: f1b15233-e845-48d5-b726-c0a86ece9066

📥 Commits

Reviewing files that changed from the base of the PR and between 18d41ba and 09e6caa.

📒 Files selected for processing (1)
  • .github/workflows/vulnerability-triage.yml

Walkthrough

The vulnerability triage workflow's "Match existing Linear issues" step is extended to query or create a Linear label named after github.repository and export its id. The "Create Linear issues" step consumes that id, warns if unavailable, and assigns both the CVE label and the repository label when creating new issues.

Changes

Repository-scoped Linear label resolution and assignment

Layer / File(s)Summary
Resolve/create repo label in matching step and export id
.github/workflows/vulnerability-triage.yml
The matching step queries Linear for a label named after github.repository, creates it if it does not exist, and writes repo_label_id to GITHUB_OUTPUT.
Consume repo label id and apply to new issues
.github/workflows/vulnerability-triage.yml
The creation step reads REPO_LABEL_ID from the match step outputs, logs a warning when it is unavailable, and builds a filtered labelIds array combining the CVE label id and the repository label id before passing it to issue creation.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#1334: Updates the same "Match existing Linear issues" and "Create Linear issues" steps in vulnerability-triage.yml to rewire Linear metadata resolution, directly preceding the label changes introduced here.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately reflects the main change: adding repository-scoped labels to Linear issues in the vulnerability-triage workflow.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/vuln-triage-repo-label

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@brendan-kellam
brendan-kellam merged commit 5bd62b3 into mainJun 18, 2026
7 of 8 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/vuln-triage-repo-label branch June 18, 2026 00:18
@github-actionsgithub-actionsBot mentioned this pull request Jun 18, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(ci): tag triaged Linear issues with the source repository - #1345

Merged
brendan-kellam merged 1 commit into
mainfrom
brendan/vuln-triage-repo-label
Jun 18, 2026
Merged

feat(ci): tag triaged Linear issues with the source repository#1345
brendan-kellam merged 1 commit into
mainfrom
brendan/vuln-triage-repo-label

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Summary

Tags each Linear issue created by the vulnerability-triage workflow with a label named after the source repository (e.g. sourcebot-dev/sourcebot), in addition to the existing CVE label. This makes triaged issues filterable by repo in Linear.

How

  • In the Match existing Linear issues step, after resolving the team/CVE-label/state/viewer, resolve a team label whose name equals ${{ github.repository }}. If it doesn't exist yet, create it via issueLabelCreate (team-scoped, like the CVE label). Expose it as a repo_label_id step output.
  • In the Create Linear issues step, attach both the CVE label and the repository label (any that failed to resolve are dropped).

The label is created at most once — subsequent runs find the existing one. Reopened issues are unchanged (they already carry their labels).

Notes

  • The label uses the full github.repository (owner/repo) to match the [owner/repo] title-prefix scoping already used, which keeps it unambiguous across sibling repos (e.g. sourcebot-dev/sourcebot-helm-chart). Easy to switch to the short repo name if you'd prefer.
  • No CHANGELOG entry — internal CI/security-automation change, not user-facing.

Testing

Verified the label-array construction in jq (both labels present, repo label missing → only CVE, both missing → no labelIds sent) and that the workflow YAML parses.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Improved vulnerability issue tracking workflow to include repository-specific labeling in addition to existing categorization. Enhanced label resolution and assignment logic for better organization of security-related issues.

Resolve (or create) a team label named after the repository and attach it to
each created CVE issue alongside the existing "CVE" label, so issues are
filterable by their source repo in Linear.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@brendan-kellam your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

Pull request was closed or merged during review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: f1b15233-e845-48d5-b726-c0a86ece9066

📥 Commits

Reviewing files that changed from the base of the PR and between 18d41ba and 09e6caa.

📒 Files selected for processing (1)
  • .github/workflows/vulnerability-triage.yml

Walkthrough

The vulnerability triage workflow's "Match existing Linear issues" step is extended to query or create a Linear label named after github.repository and export its id. The "Create Linear issues" step consumes that id, warns if unavailable, and assigns both the CVE label and the repository label when creating new issues.

Changes

Repository-scoped Linear label resolution and assignment

Layer / File(s)Summary
Resolve/create repo label in matching step and export id
.github/workflows/vulnerability-triage.yml
The matching step queries Linear for a label named after github.repository, creates it if it does not exist, and writes repo_label_id to GITHUB_OUTPUT.
Consume repo label id and apply to new issues
.github/workflows/vulnerability-triage.yml
The creation step reads REPO_LABEL_ID from the match step outputs, logs a warning when it is unavailable, and builds a filtered labelIds array combining the CVE label id and the repository label id before passing it to issue creation.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#1334: Updates the same "Match existing Linear issues" and "Create Linear issues" steps in vulnerability-triage.yml to rewire Linear metadata resolution, directly preceding the label changes introduced here.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately reflects the main change: adding repository-scoped labels to Linear issues in the vulnerability-triage workflow.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/vuln-triage-repo-label

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@brendan-kellam
brendan-kellam merged commit 5bd62b3 into mainJun 18, 2026
7 of 8 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/vuln-triage-repo-label branch June 18, 2026 00:18
@github-actionsgithub-actionsBot mentioned this pull request Jun 18, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(ci): tag triaged Linear issues with the source repository - #1345

Merged
brendan-kellam merged 1 commit into
mainfrom
brendan/vuln-triage-repo-label
Jun 18, 2026
Merged

feat(ci): tag triaged Linear issues with the source repository#1345
brendan-kellam merged 1 commit into
mainfrom
brendan/vuln-triage-repo-label

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Summary

Tags each Linear issue created by the vulnerability-triage workflow with a label named after the source repository (e.g. sourcebot-dev/sourcebot), in addition to the existing CVE label. This makes triaged issues filterable by repo in Linear.

How

  • In the Match existing Linear issues step, after resolving the team/CVE-label/state/viewer, resolve a team label whose name equals ${{ github.repository }}. If it doesn't exist yet, create it via issueLabelCreate (team-scoped, like the CVE label). Expose it as a repo_label_id step output.
  • In the Create Linear issues step, attach both the CVE label and the repository label (any that failed to resolve are dropped).

The label is created at most once — subsequent runs find the existing one. Reopened issues are unchanged (they already carry their labels).

Notes

  • The label uses the full github.repository (owner/repo) to match the [owner/repo] title-prefix scoping already used, which keeps it unambiguous across sibling repos (e.g. sourcebot-dev/sourcebot-helm-chart). Easy to switch to the short repo name if you'd prefer.
  • No CHANGELOG entry — internal CI/security-automation change, not user-facing.

Testing

Verified the label-array construction in jq (both labels present, repo label missing → only CVE, both missing → no labelIds sent) and that the workflow YAML parses.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Improved vulnerability issue tracking workflow to include repository-specific labeling in addition to existing categorization. Enhanced label resolution and assignment logic for better organization of security-related issues.

Resolve (or create) a team label named after the repository and attach it to
each created CVE issue alongside the existing "CVE" label, so issues are
filterable by their source repo in Linear.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@brendan-kellam your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

Pull request was closed or merged during review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: f1b15233-e845-48d5-b726-c0a86ece9066

📥 Commits

Reviewing files that changed from the base of the PR and between 18d41ba and 09e6caa.

📒 Files selected for processing (1)
  • .github/workflows/vulnerability-triage.yml

Walkthrough

The vulnerability triage workflow's "Match existing Linear issues" step is extended to query or create a Linear label named after github.repository and export its id. The "Create Linear issues" step consumes that id, warns if unavailable, and assigns both the CVE label and the repository label when creating new issues.

Changes

Repository-scoped Linear label resolution and assignment

Layer / File(s)Summary
Resolve/create repo label in matching step and export id
.github/workflows/vulnerability-triage.yml
The matching step queries Linear for a label named after github.repository, creates it if it does not exist, and writes repo_label_id to GITHUB_OUTPUT.
Consume repo label id and apply to new issues
.github/workflows/vulnerability-triage.yml
The creation step reads REPO_LABEL_ID from the match step outputs, logs a warning when it is unavailable, and builds a filtered labelIds array combining the CVE label id and the repository label id before passing it to issue creation.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#1334: Updates the same "Match existing Linear issues" and "Create Linear issues" steps in vulnerability-triage.yml to rewire Linear metadata resolution, directly preceding the label changes introduced here.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately reflects the main change: adding repository-scoped labels to Linear issues in the vulnerability-triage workflow.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/vuln-triage-repo-label

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@brendan-kellam
brendan-kellam merged commit 5bd62b3 into mainJun 18, 2026
7 of 8 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/vuln-triage-repo-label branch June 18, 2026 00:18
@github-actionsgithub-actionsBot mentioned this pull request Jun 18, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(ci): tag triaged Linear issues with the source repository - #1345

Merged
brendan-kellam merged 1 commit into
mainfrom
brendan/vuln-triage-repo-label
Jun 18, 2026
Merged

feat(ci): tag triaged Linear issues with the source repository#1345
brendan-kellam merged 1 commit into
mainfrom
brendan/vuln-triage-repo-label

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Summary

Tags each Linear issue created by the vulnerability-triage workflow with a label named after the source repository (e.g. sourcebot-dev/sourcebot), in addition to the existing CVE label. This makes triaged issues filterable by repo in Linear.

How

  • In the Match existing Linear issues step, after resolving the team/CVE-label/state/viewer, resolve a team label whose name equals ${{ github.repository }}. If it doesn't exist yet, create it via issueLabelCreate (team-scoped, like the CVE label). Expose it as a repo_label_id step output.
  • In the Create Linear issues step, attach both the CVE label and the repository label (any that failed to resolve are dropped).

The label is created at most once — subsequent runs find the existing one. Reopened issues are unchanged (they already carry their labels).

Notes

  • The label uses the full github.repository (owner/repo) to match the [owner/repo] title-prefix scoping already used, which keeps it unambiguous across sibling repos (e.g. sourcebot-dev/sourcebot-helm-chart). Easy to switch to the short repo name if you'd prefer.
  • No CHANGELOG entry — internal CI/security-automation change, not user-facing.

Testing

Verified the label-array construction in jq (both labels present, repo label missing → only CVE, both missing → no labelIds sent) and that the workflow YAML parses.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Improved vulnerability issue tracking workflow to include repository-specific labeling in addition to existing categorization. Enhanced label resolution and assignment logic for better organization of security-related issues.

Resolve (or create) a team label named after the repository and attach it to
each created CVE issue alongside the existing "CVE" label, so issues are
filterable by their source repo in Linear.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@brendan-kellam your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

Pull request was closed or merged during review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: f1b15233-e845-48d5-b726-c0a86ece9066

📥 Commits

Reviewing files that changed from the base of the PR and between 18d41ba and 09e6caa.

📒 Files selected for processing (1)
  • .github/workflows/vulnerability-triage.yml

Walkthrough

The vulnerability triage workflow's "Match existing Linear issues" step is extended to query or create a Linear label named after github.repository and export its id. The "Create Linear issues" step consumes that id, warns if unavailable, and assigns both the CVE label and the repository label when creating new issues.

Changes

Repository-scoped Linear label resolution and assignment

Layer / File(s)Summary
Resolve/create repo label in matching step and export id
.github/workflows/vulnerability-triage.yml
The matching step queries Linear for a label named after github.repository, creates it if it does not exist, and writes repo_label_id to GITHUB_OUTPUT.
Consume repo label id and apply to new issues
.github/workflows/vulnerability-triage.yml
The creation step reads REPO_LABEL_ID from the match step outputs, logs a warning when it is unavailable, and builds a filtered labelIds array combining the CVE label id and the repository label id before passing it to issue creation.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#1334: Updates the same "Match existing Linear issues" and "Create Linear issues" steps in vulnerability-triage.yml to rewire Linear metadata resolution, directly preceding the label changes introduced here.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately reflects the main change: adding repository-scoped labels to Linear issues in the vulnerability-triage workflow.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/vuln-triage-repo-label

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@brendan-kellam
brendan-kellam merged commit 5bd62b3 into mainJun 18, 2026
7 of 8 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/vuln-triage-repo-label branch June 18, 2026 00:18
@github-actionsgithub-actionsBot mentioned this pull request Jun 18, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(ci): tag triaged Linear issues with the source repository - #1345

Merged
brendan-kellam merged 1 commit into
mainfrom
brendan/vuln-triage-repo-label
Jun 18, 2026
Merged

feat(ci): tag triaged Linear issues with the source repository#1345
brendan-kellam merged 1 commit into
mainfrom
brendan/vuln-triage-repo-label

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Summary

Tags each Linear issue created by the vulnerability-triage workflow with a label named after the source repository (e.g. sourcebot-dev/sourcebot), in addition to the existing CVE label. This makes triaged issues filterable by repo in Linear.

How

  • In the Match existing Linear issues step, after resolving the team/CVE-label/state/viewer, resolve a team label whose name equals ${{ github.repository }}. If it doesn't exist yet, create it via issueLabelCreate (team-scoped, like the CVE label). Expose it as a repo_label_id step output.
  • In the Create Linear issues step, attach both the CVE label and the repository label (any that failed to resolve are dropped).

The label is created at most once — subsequent runs find the existing one. Reopened issues are unchanged (they already carry their labels).

Notes

  • The label uses the full github.repository (owner/repo) to match the [owner/repo] title-prefix scoping already used, which keeps it unambiguous across sibling repos (e.g. sourcebot-dev/sourcebot-helm-chart). Easy to switch to the short repo name if you'd prefer.
  • No CHANGELOG entry — internal CI/security-automation change, not user-facing.

Testing

Verified the label-array construction in jq (both labels present, repo label missing → only CVE, both missing → no labelIds sent) and that the workflow YAML parses.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Improved vulnerability issue tracking workflow to include repository-specific labeling in addition to existing categorization. Enhanced label resolution and assignment logic for better organization of security-related issues.

Resolve (or create) a team label named after the repository and attach it to
each created CVE issue alongside the existing "CVE" label, so issues are
filterable by their source repo in Linear.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@brendan-kellam your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

Pull request was closed or merged during review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: f1b15233-e845-48d5-b726-c0a86ece9066

📥 Commits

Reviewing files that changed from the base of the PR and between 18d41ba and 09e6caa.

📒 Files selected for processing (1)
  • .github/workflows/vulnerability-triage.yml

Walkthrough

The vulnerability triage workflow's "Match existing Linear issues" step is extended to query or create a Linear label named after github.repository and export its id. The "Create Linear issues" step consumes that id, warns if unavailable, and assigns both the CVE label and the repository label when creating new issues.

Changes

Repository-scoped Linear label resolution and assignment

Layer / File(s)Summary
Resolve/create repo label in matching step and export id
.github/workflows/vulnerability-triage.yml
The matching step queries Linear for a label named after github.repository, creates it if it does not exist, and writes repo_label_id to GITHUB_OUTPUT.
Consume repo label id and apply to new issues
.github/workflows/vulnerability-triage.yml
The creation step reads REPO_LABEL_ID from the match step outputs, logs a warning when it is unavailable, and builds a filtered labelIds array combining the CVE label id and the repository label id before passing it to issue creation.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#1334: Updates the same "Match existing Linear issues" and "Create Linear issues" steps in vulnerability-triage.yml to rewire Linear metadata resolution, directly preceding the label changes introduced here.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately reflects the main change: adding repository-scoped labels to Linear issues in the vulnerability-triage workflow.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/vuln-triage-repo-label

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@brendan-kellam
brendan-kellam merged commit 5bd62b3 into mainJun 18, 2026
7 of 8 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/vuln-triage-repo-label branch June 18, 2026 00:18
@github-actionsgithub-actionsBot mentioned this pull request Jun 18, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(ci): tag triaged Linear issues with the source repository - #1345

Merged
brendan-kellam merged 1 commit into
mainfrom
brendan/vuln-triage-repo-label
Jun 18, 2026
Merged

feat(ci): tag triaged Linear issues with the source repository#1345
brendan-kellam merged 1 commit into
mainfrom
brendan/vuln-triage-repo-label

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Summary

Tags each Linear issue created by the vulnerability-triage workflow with a label named after the source repository (e.g. sourcebot-dev/sourcebot), in addition to the existing CVE label. This makes triaged issues filterable by repo in Linear.

How

  • In the Match existing Linear issues step, after resolving the team/CVE-label/state/viewer, resolve a team label whose name equals ${{ github.repository }}. If it doesn't exist yet, create it via issueLabelCreate (team-scoped, like the CVE label). Expose it as a repo_label_id step output.
  • In the Create Linear issues step, attach both the CVE label and the repository label (any that failed to resolve are dropped).

The label is created at most once — subsequent runs find the existing one. Reopened issues are unchanged (they already carry their labels).

Notes

  • The label uses the full github.repository (owner/repo) to match the [owner/repo] title-prefix scoping already used, which keeps it unambiguous across sibling repos (e.g. sourcebot-dev/sourcebot-helm-chart). Easy to switch to the short repo name if you'd prefer.
  • No CHANGELOG entry — internal CI/security-automation change, not user-facing.

Testing

Verified the label-array construction in jq (both labels present, repo label missing → only CVE, both missing → no labelIds sent) and that the workflow YAML parses.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Improved vulnerability issue tracking workflow to include repository-specific labeling in addition to existing categorization. Enhanced label resolution and assignment logic for better organization of security-related issues.

Resolve (or create) a team label named after the repository and attach it to
each created CVE issue alongside the existing "CVE" label, so issues are
filterable by their source repo in Linear.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@brendan-kellam your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

Pull request was closed or merged during review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: f1b15233-e845-48d5-b726-c0a86ece9066

📥 Commits

Reviewing files that changed from the base of the PR and between 18d41ba and 09e6caa.

📒 Files selected for processing (1)
  • .github/workflows/vulnerability-triage.yml

Walkthrough

The vulnerability triage workflow's "Match existing Linear issues" step is extended to query or create a Linear label named after github.repository and export its id. The "Create Linear issues" step consumes that id, warns if unavailable, and assigns both the CVE label and the repository label when creating new issues.

Changes

Repository-scoped Linear label resolution and assignment

Layer / File(s)Summary
Resolve/create repo label in matching step and export id
.github/workflows/vulnerability-triage.yml
The matching step queries Linear for a label named after github.repository, creates it if it does not exist, and writes repo_label_id to GITHUB_OUTPUT.
Consume repo label id and apply to new issues
.github/workflows/vulnerability-triage.yml
The creation step reads REPO_LABEL_ID from the match step outputs, logs a warning when it is unavailable, and builds a filtered labelIds array combining the CVE label id and the repository label id before passing it to issue creation.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#1334: Updates the same "Match existing Linear issues" and "Create Linear issues" steps in vulnerability-triage.yml to rewire Linear metadata resolution, directly preceding the label changes introduced here.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately reflects the main change: adding repository-scoped labels to Linear issues in the vulnerability-triage workflow.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/vuln-triage-repo-label

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@brendan-kellam
brendan-kellam merged commit 5bd62b3 into mainJun 18, 2026
7 of 8 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/vuln-triage-repo-label branch June 18, 2026 00:18
@github-actionsgithub-actionsBot mentioned this pull request Jun 18, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(ci): tag triaged Linear issues with the source repository - #1345

Merged
brendan-kellam merged 1 commit into
mainfrom
brendan/vuln-triage-repo-label
Jun 18, 2026
Merged

feat(ci): tag triaged Linear issues with the source repository#1345
brendan-kellam merged 1 commit into
mainfrom
brendan/vuln-triage-repo-label

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Summary

Tags each Linear issue created by the vulnerability-triage workflow with a label named after the source repository (e.g. sourcebot-dev/sourcebot), in addition to the existing CVE label. This makes triaged issues filterable by repo in Linear.

How

  • In the Match existing Linear issues step, after resolving the team/CVE-label/state/viewer, resolve a team label whose name equals ${{ github.repository }}. If it doesn't exist yet, create it via issueLabelCreate (team-scoped, like the CVE label). Expose it as a repo_label_id step output.
  • In the Create Linear issues step, attach both the CVE label and the repository label (any that failed to resolve are dropped).

The label is created at most once — subsequent runs find the existing one. Reopened issues are unchanged (they already carry their labels).

Notes

  • The label uses the full github.repository (owner/repo) to match the [owner/repo] title-prefix scoping already used, which keeps it unambiguous across sibling repos (e.g. sourcebot-dev/sourcebot-helm-chart). Easy to switch to the short repo name if you'd prefer.
  • No CHANGELOG entry — internal CI/security-automation change, not user-facing.

Testing

Verified the label-array construction in jq (both labels present, repo label missing → only CVE, both missing → no labelIds sent) and that the workflow YAML parses.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Improved vulnerability issue tracking workflow to include repository-specific labeling in addition to existing categorization. Enhanced label resolution and assignment logic for better organization of security-related issues.

Resolve (or create) a team label named after the repository and attach it to
each created CVE issue alongside the existing "CVE" label, so issues are
filterable by their source repo in Linear.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

@brendan-kellam your pull request is missing a changelog!

@coderabbitai

coderabbitaiBot commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

Pull request was closed or merged during review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: f1b15233-e845-48d5-b726-c0a86ece9066

📥 Commits

Reviewing files that changed from the base of the PR and between 18d41ba and 09e6caa.

📒 Files selected for processing (1)
  • .github/workflows/vulnerability-triage.yml

Walkthrough

The vulnerability triage workflow's "Match existing Linear issues" step is extended to query or create a Linear label named after github.repository and export its id. The "Create Linear issues" step consumes that id, warns if unavailable, and assigns both the CVE label and the repository label when creating new issues.

Changes

Repository-scoped Linear label resolution and assignment

Layer / File(s)Summary
Resolve/create repo label in matching step and export id
.github/workflows/vulnerability-triage.yml
The matching step queries Linear for a label named after github.repository, creates it if it does not exist, and writes repo_label_id to GITHUB_OUTPUT.
Consume repo label id and apply to new issues
.github/workflows/vulnerability-triage.yml
The creation step reads REPO_LABEL_ID from the match step outputs, logs a warning when it is unavailable, and builds a filtered labelIds array combining the CVE label id and the repository label id before passing it to issue creation.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#1334: Updates the same "Match existing Linear issues" and "Create Linear issues" steps in vulnerability-triage.yml to rewire Linear metadata resolution, directly preceding the label changes introduced here.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately reflects the main change: adding repository-scoped labels to Linear issues in the vulnerability-triage workflow.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/vuln-triage-repo-label

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@brendan-kellam
brendan-kellam merged commit 5bd62b3 into mainJun 18, 2026
7 of 8 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/vuln-triage-repo-label branch June 18, 2026 00:18
@github-actionsgithub-actionsBot mentioned this pull request Jun 18, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam