chore: automate CVE remediation - #1538

Merged
brendan-kellam merged 5 commits into
mainfrom
brendan/sou-1830-automate-cve-resolution
Aug 5, 2026
Merged

chore: automate CVE remediation#1538
brendan-kellam merged 5 commits into
mainfrom
brendan/sou-1830-automate-cve-resolution

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Summary

  • add a reusable workflow that finds open repository CVEs in Linear without linked GitHub PRs
  • invoke Claude only when deterministic discovery finds work, with read-only Linear MCP access and guarded remediation instructions
  • add a nightly Sourcebot caller and CI coverage for pagination, filtering, and PR-link detection

Testing

  • .github/scripts/test-vulnerability-triage.sh
  • .github/scripts/test-cve-remediation.sh
  • workflow YAML parsing
  • actionlint
  • Bash syntax validation

Refs SOU-1830


Note

Medium Risk
The remediate job grants contents/PR write and runs an unattended agent with broad Bash and PR tooling; safeguards (read-only Linear MCP, disallowed merge/publish) reduce risk but automated dependency changes still need review.

Overview
Adds automated CVE remediation on top of existing vulnerability triage: open Linear CVEs for the repo that still lack a linked GitHub PR are discovered deterministically, then a Claude agent runs only when that list is non-empty.

Discovery paginates Linear (shared linear-graphql-request.sh), filters with filter-unlinked-cve-issues.jq (CVE label, no github.com/.../pull/... attachment, priority sort), and caps issues via max_issues. A reusable workflow (_cve-remediation.yml) runs discovery first and gates the remediate job on has_issues.

Remediation uses anthropics/claude-code-action with a checked-in system prompt (cve-remediation-system.md), read-only Linear MCP (--strict-mcp-config), and allow/disallow lists for git, gh pr, package managers, and tests—without merge, force-push, or publish.

A nightly workflow (cve-remediation.yml, schedule + workflow_dispatch) calls the reusable workflow with repo concurrency. CI expands the vulnerability job to vulnerability-automation and runs test-cve-remediation.sh alongside existing triage tests.

Reviewed by Cursor Bugbot for commit dcafc5a. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added scheduled and manually triggered CVE discovery and remediation workflows.
    • Added filtering and prioritization for CVE issues without valid linked pull requests.
    • Added configurable issue limits and discovery result reporting.
    • Added safeguards for credentials, repository access, and proposed remediation changes.
  • Tests

    • Added coverage for pagination, filtering, prioritization, workflow configuration, and remediation safeguards.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: b95595d9-550a-4532-ac58-4721e4089a05

📥 Commits

Reviewing files that changed from the base of the PR and between e16b75d and dcafc5a.

📒 Files selected for processing (2)
  • .github/scripts/test-cve-remediation.sh
  • .github/workflows/_cve-remediation.yml

Walkthrough

The change adds scheduled and manual CVE remediation workflows. It discovers unlinked CVE issues from Linear, filters and prioritizes them, and conditionally starts a constrained Claude remediation job. CI tests validate discovery and workflow configuration.

Changes

CVE remediation automation

Layer / File(s)Summary
CVE issue discovery and filtering
.github/scripts/*, .github/workflows/_cve-remediation.yml, .github/scripts/test-cve-remediation.sh
Queries paginated Linear issues, filters unlinked CVEs, sorts them by normalized priority, limits selected issues, and validates pagination and filtering.
Constrained remediation execution
.github/prompts/cve-remediation-system.md, .github/workflows/_cve-remediation.yml, .github/scripts/test-cve-remediation.sh
Defines remediation rules, read-only Linear MCP access, restricted Claude tools, verification steps, and pull-request creation behavior.
Scheduled execution and CI wiring
.github/workflows/cve-remediation.yml, .github/workflows/test.yml
Adds scheduled and manual workflow entry points and runs CVE remediation tests in CI.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
participant Scheduler
participant DiscoveryJob
participant Linear
participant Claude
participant Repository
Scheduler->>DiscoveryJob: Start scheduled or manual workflow
DiscoveryJob->>Linear: Query paginated open CVE issues
Linear-->>DiscoveryJob: Return issue data and cursors
DiscoveryJob->>Claude: Start remediation when issues exist
Claude->>Linear: Read issue data through read-only MCP
Claude->>Repository: Update dependencies, verify changes, and open pull requests
Loading

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the pull request's main change: automating CVE remediation workflows.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/sou-1830-automate-cve-resolution

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/_cve-remediation.yml:
- Around line 34-35: Update the checkout configuration in the reusable CVE
remediation workflow to use the available github.repository and github.sha
contexts instead of job.workflow_repository and job.workflow_sha. Preserve
same-repository caller behavior; only introduce explicit workflow inputs if
cross-repository reuse must be supported.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: d63f2d8d-14f9-41b6-b0ff-fcd0fb44a629

📥 Commits

Reviewing files that changed from the base of the PR and between f52ce7a and b85324b.

📒 Files selected for processing (7)
  • .github/prompts/cve-remediation-system.md
  • .github/scripts/filter-unlinked-cve-issues.jq
  • .github/scripts/find-unlinked-cve-issues.sh
  • .github/scripts/test-cve-remediation.sh
  • .github/workflows/_cve-remediation.yml
  • .github/workflows/cve-remediation.yml
  • .github/workflows/test.yml

Comment thread.github/workflows/_cve-remediation.yml Outdated
@brendan-kellam
brendan-kellam merged commit fcb1285 into mainAug 5, 2026
11 of 12 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/sou-1830-automate-cve-resolution branch August 5, 2026 01:53
@github-actionsgithub-actionsBot mentioned this pull request Aug 5, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit dcafc5a. Configure here.

--max-turns 80
--tools "Bash,Read,Edit,Write,Glob,Grep"
--allowedTools "Read,Edit,Write,Glob,Grep,Bash(git *),Bash(gh pr *),Bash(yarn *),Bash(npm *),Bash(npx *),Bash(pnpm *),Bash(bun *),Bash(go *),Bash(cargo *),Bash(uv *),Bash(pytest *),Bash(python -m pytest *),Bash(make *),Bash(just *),mcp__linear__get_issue,mcp__linear__list_comments"
--disallowedTools "Bash(gh pr merge *),Bash(git push *--force*),Bash(npm publish *),Bash(yarn npm publish *),Bash(pnpm publish *),Bash(cargo publish *)"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Force-push short flag still allowed

Medium Severity

disallowedTools blocks git push only when the command contains --force, while allowedTools permits all git commands under dontAsk. The common short form git push -f therefore stays auto-approved for this unattended agent, so the force-push safeguard does not cover the usual destructive path.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit dcafc5a. Configure here.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore: automate CVE remediation - #1538

Merged
brendan-kellam merged 5 commits into
mainfrom
brendan/sou-1830-automate-cve-resolution
Aug 5, 2026
Merged

chore: automate CVE remediation#1538
brendan-kellam merged 5 commits into
mainfrom
brendan/sou-1830-automate-cve-resolution

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Summary

  • add a reusable workflow that finds open repository CVEs in Linear without linked GitHub PRs
  • invoke Claude only when deterministic discovery finds work, with read-only Linear MCP access and guarded remediation instructions
  • add a nightly Sourcebot caller and CI coverage for pagination, filtering, and PR-link detection

Testing

  • .github/scripts/test-vulnerability-triage.sh
  • .github/scripts/test-cve-remediation.sh
  • workflow YAML parsing
  • actionlint
  • Bash syntax validation

Refs SOU-1830


Note

Medium Risk
The remediate job grants contents/PR write and runs an unattended agent with broad Bash and PR tooling; safeguards (read-only Linear MCP, disallowed merge/publish) reduce risk but automated dependency changes still need review.

Overview
Adds automated CVE remediation on top of existing vulnerability triage: open Linear CVEs for the repo that still lack a linked GitHub PR are discovered deterministically, then a Claude agent runs only when that list is non-empty.

Discovery paginates Linear (shared linear-graphql-request.sh), filters with filter-unlinked-cve-issues.jq (CVE label, no github.com/.../pull/... attachment, priority sort), and caps issues via max_issues. A reusable workflow (_cve-remediation.yml) runs discovery first and gates the remediate job on has_issues.

Remediation uses anthropics/claude-code-action with a checked-in system prompt (cve-remediation-system.md), read-only Linear MCP (--strict-mcp-config), and allow/disallow lists for git, gh pr, package managers, and tests—without merge, force-push, or publish.

A nightly workflow (cve-remediation.yml, schedule + workflow_dispatch) calls the reusable workflow with repo concurrency. CI expands the vulnerability job to vulnerability-automation and runs test-cve-remediation.sh alongside existing triage tests.

Reviewed by Cursor Bugbot for commit dcafc5a. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added scheduled and manually triggered CVE discovery and remediation workflows.
    • Added filtering and prioritization for CVE issues without valid linked pull requests.
    • Added configurable issue limits and discovery result reporting.
    • Added safeguards for credentials, repository access, and proposed remediation changes.
  • Tests

    • Added coverage for pagination, filtering, prioritization, workflow configuration, and remediation safeguards.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: b95595d9-550a-4532-ac58-4721e4089a05

📥 Commits

Reviewing files that changed from the base of the PR and between e16b75d and dcafc5a.

📒 Files selected for processing (2)
  • .github/scripts/test-cve-remediation.sh
  • .github/workflows/_cve-remediation.yml

Walkthrough

The change adds scheduled and manual CVE remediation workflows. It discovers unlinked CVE issues from Linear, filters and prioritizes them, and conditionally starts a constrained Claude remediation job. CI tests validate discovery and workflow configuration.

Changes

CVE remediation automation

Layer / File(s)Summary
CVE issue discovery and filtering
.github/scripts/*, .github/workflows/_cve-remediation.yml, .github/scripts/test-cve-remediation.sh
Queries paginated Linear issues, filters unlinked CVEs, sorts them by normalized priority, limits selected issues, and validates pagination and filtering.
Constrained remediation execution
.github/prompts/cve-remediation-system.md, .github/workflows/_cve-remediation.yml, .github/scripts/test-cve-remediation.sh
Defines remediation rules, read-only Linear MCP access, restricted Claude tools, verification steps, and pull-request creation behavior.
Scheduled execution and CI wiring
.github/workflows/cve-remediation.yml, .github/workflows/test.yml
Adds scheduled and manual workflow entry points and runs CVE remediation tests in CI.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
participant Scheduler
participant DiscoveryJob
participant Linear
participant Claude
participant Repository
Scheduler->>DiscoveryJob: Start scheduled or manual workflow
DiscoveryJob->>Linear: Query paginated open CVE issues
Linear-->>DiscoveryJob: Return issue data and cursors
DiscoveryJob->>Claude: Start remediation when issues exist
Claude->>Linear: Read issue data through read-only MCP
Claude->>Repository: Update dependencies, verify changes, and open pull requests
Loading

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the pull request's main change: automating CVE remediation workflows.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/sou-1830-automate-cve-resolution

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/_cve-remediation.yml:
- Around line 34-35: Update the checkout configuration in the reusable CVE
remediation workflow to use the available github.repository and github.sha
contexts instead of job.workflow_repository and job.workflow_sha. Preserve
same-repository caller behavior; only introduce explicit workflow inputs if
cross-repository reuse must be supported.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: d63f2d8d-14f9-41b6-b0ff-fcd0fb44a629

📥 Commits

Reviewing files that changed from the base of the PR and between f52ce7a and b85324b.

📒 Files selected for processing (7)
  • .github/prompts/cve-remediation-system.md
  • .github/scripts/filter-unlinked-cve-issues.jq
  • .github/scripts/find-unlinked-cve-issues.sh
  • .github/scripts/test-cve-remediation.sh
  • .github/workflows/_cve-remediation.yml
  • .github/workflows/cve-remediation.yml
  • .github/workflows/test.yml

Comment thread.github/workflows/_cve-remediation.yml Outdated
@brendan-kellam
brendan-kellam merged commit fcb1285 into mainAug 5, 2026
11 of 12 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/sou-1830-automate-cve-resolution branch August 5, 2026 01:53
@github-actionsgithub-actionsBot mentioned this pull request Aug 5, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit dcafc5a. Configure here.

--max-turns 80
--tools "Bash,Read,Edit,Write,Glob,Grep"
--allowedTools "Read,Edit,Write,Glob,Grep,Bash(git *),Bash(gh pr *),Bash(yarn *),Bash(npm *),Bash(npx *),Bash(pnpm *),Bash(bun *),Bash(go *),Bash(cargo *),Bash(uv *),Bash(pytest *),Bash(python -m pytest *),Bash(make *),Bash(just *),mcp__linear__get_issue,mcp__linear__list_comments"
--disallowedTools "Bash(gh pr merge *),Bash(git push *--force*),Bash(npm publish *),Bash(yarn npm publish *),Bash(pnpm publish *),Bash(cargo publish *)"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Force-push short flag still allowed

Medium Severity

disallowedTools blocks git push only when the command contains --force, while allowedTools permits all git commands under dontAsk. The common short form git push -f therefore stays auto-approved for this unattended agent, so the force-push safeguard does not cover the usual destructive path.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit dcafc5a. Configure here.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: automate CVE remediation - #1538

Merged
brendan-kellam merged 5 commits into
mainfrom
brendan/sou-1830-automate-cve-resolution
Aug 5, 2026
Merged

chore: automate CVE remediation#1538
brendan-kellam merged 5 commits into
mainfrom
brendan/sou-1830-automate-cve-resolution

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Summary

  • add a reusable workflow that finds open repository CVEs in Linear without linked GitHub PRs
  • invoke Claude only when deterministic discovery finds work, with read-only Linear MCP access and guarded remediation instructions
  • add a nightly Sourcebot caller and CI coverage for pagination, filtering, and PR-link detection

Testing

  • .github/scripts/test-vulnerability-triage.sh
  • .github/scripts/test-cve-remediation.sh
  • workflow YAML parsing
  • actionlint
  • Bash syntax validation

Refs SOU-1830


Note

Medium Risk
The remediate job grants contents/PR write and runs an unattended agent with broad Bash and PR tooling; safeguards (read-only Linear MCP, disallowed merge/publish) reduce risk but automated dependency changes still need review.

Overview
Adds automated CVE remediation on top of existing vulnerability triage: open Linear CVEs for the repo that still lack a linked GitHub PR are discovered deterministically, then a Claude agent runs only when that list is non-empty.

Discovery paginates Linear (shared linear-graphql-request.sh), filters with filter-unlinked-cve-issues.jq (CVE label, no github.com/.../pull/... attachment, priority sort), and caps issues via max_issues. A reusable workflow (_cve-remediation.yml) runs discovery first and gates the remediate job on has_issues.

Remediation uses anthropics/claude-code-action with a checked-in system prompt (cve-remediation-system.md), read-only Linear MCP (--strict-mcp-config), and allow/disallow lists for git, gh pr, package managers, and tests—without merge, force-push, or publish.

A nightly workflow (cve-remediation.yml, schedule + workflow_dispatch) calls the reusable workflow with repo concurrency. CI expands the vulnerability job to vulnerability-automation and runs test-cve-remediation.sh alongside existing triage tests.

Reviewed by Cursor Bugbot for commit dcafc5a. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added scheduled and manually triggered CVE discovery and remediation workflows.
    • Added filtering and prioritization for CVE issues without valid linked pull requests.
    • Added configurable issue limits and discovery result reporting.
    • Added safeguards for credentials, repository access, and proposed remediation changes.
  • Tests

    • Added coverage for pagination, filtering, prioritization, workflow configuration, and remediation safeguards.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: b95595d9-550a-4532-ac58-4721e4089a05

📥 Commits

Reviewing files that changed from the base of the PR and between e16b75d and dcafc5a.

📒 Files selected for processing (2)
  • .github/scripts/test-cve-remediation.sh
  • .github/workflows/_cve-remediation.yml

Walkthrough

The change adds scheduled and manual CVE remediation workflows. It discovers unlinked CVE issues from Linear, filters and prioritizes them, and conditionally starts a constrained Claude remediation job. CI tests validate discovery and workflow configuration.

Changes

CVE remediation automation

Layer / File(s)Summary
CVE issue discovery and filtering
.github/scripts/*, .github/workflows/_cve-remediation.yml, .github/scripts/test-cve-remediation.sh
Queries paginated Linear issues, filters unlinked CVEs, sorts them by normalized priority, limits selected issues, and validates pagination and filtering.
Constrained remediation execution
.github/prompts/cve-remediation-system.md, .github/workflows/_cve-remediation.yml, .github/scripts/test-cve-remediation.sh
Defines remediation rules, read-only Linear MCP access, restricted Claude tools, verification steps, and pull-request creation behavior.
Scheduled execution and CI wiring
.github/workflows/cve-remediation.yml, .github/workflows/test.yml
Adds scheduled and manual workflow entry points and runs CVE remediation tests in CI.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
participant Scheduler
participant DiscoveryJob
participant Linear
participant Claude
participant Repository
Scheduler->>DiscoveryJob: Start scheduled or manual workflow
DiscoveryJob->>Linear: Query paginated open CVE issues
Linear-->>DiscoveryJob: Return issue data and cursors
DiscoveryJob->>Claude: Start remediation when issues exist
Claude->>Linear: Read issue data through read-only MCP
Claude->>Repository: Update dependencies, verify changes, and open pull requests
Loading

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the pull request's main change: automating CVE remediation workflows.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/sou-1830-automate-cve-resolution

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/_cve-remediation.yml:
- Around line 34-35: Update the checkout configuration in the reusable CVE
remediation workflow to use the available github.repository and github.sha
contexts instead of job.workflow_repository and job.workflow_sha. Preserve
same-repository caller behavior; only introduce explicit workflow inputs if
cross-repository reuse must be supported.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: d63f2d8d-14f9-41b6-b0ff-fcd0fb44a629

📥 Commits

Reviewing files that changed from the base of the PR and between f52ce7a and b85324b.

📒 Files selected for processing (7)
  • .github/prompts/cve-remediation-system.md
  • .github/scripts/filter-unlinked-cve-issues.jq
  • .github/scripts/find-unlinked-cve-issues.sh
  • .github/scripts/test-cve-remediation.sh
  • .github/workflows/_cve-remediation.yml
  • .github/workflows/cve-remediation.yml
  • .github/workflows/test.yml

Comment thread.github/workflows/_cve-remediation.yml Outdated
@brendan-kellam
brendan-kellam merged commit fcb1285 into mainAug 5, 2026
11 of 12 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/sou-1830-automate-cve-resolution branch August 5, 2026 01:53
@github-actionsgithub-actionsBot mentioned this pull request Aug 5, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit dcafc5a. Configure here.

--max-turns 80
--tools "Bash,Read,Edit,Write,Glob,Grep"
--allowedTools "Read,Edit,Write,Glob,Grep,Bash(git *),Bash(gh pr *),Bash(yarn *),Bash(npm *),Bash(npx *),Bash(pnpm *),Bash(bun *),Bash(go *),Bash(cargo *),Bash(uv *),Bash(pytest *),Bash(python -m pytest *),Bash(make *),Bash(just *),mcp__linear__get_issue,mcp__linear__list_comments"
--disallowedTools "Bash(gh pr merge *),Bash(git push *--force*),Bash(npm publish *),Bash(yarn npm publish *),Bash(pnpm publish *),Bash(cargo publish *)"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Force-push short flag still allowed

Medium Severity

disallowedTools blocks git push only when the command contains --force, while allowedTools permits all git commands under dontAsk. The common short form git push -f therefore stays auto-approved for this unattended agent, so the force-push safeguard does not cover the usual destructive path.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit dcafc5a. Configure here.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: automate CVE remediation - #1538

Merged
brendan-kellam merged 5 commits into
mainfrom
brendan/sou-1830-automate-cve-resolution
Aug 5, 2026
Merged

chore: automate CVE remediation#1538
brendan-kellam merged 5 commits into
mainfrom
brendan/sou-1830-automate-cve-resolution

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Summary

  • add a reusable workflow that finds open repository CVEs in Linear without linked GitHub PRs
  • invoke Claude only when deterministic discovery finds work, with read-only Linear MCP access and guarded remediation instructions
  • add a nightly Sourcebot caller and CI coverage for pagination, filtering, and PR-link detection

Testing

  • .github/scripts/test-vulnerability-triage.sh
  • .github/scripts/test-cve-remediation.sh
  • workflow YAML parsing
  • actionlint
  • Bash syntax validation

Refs SOU-1830


Note

Medium Risk
The remediate job grants contents/PR write and runs an unattended agent with broad Bash and PR tooling; safeguards (read-only Linear MCP, disallowed merge/publish) reduce risk but automated dependency changes still need review.

Overview
Adds automated CVE remediation on top of existing vulnerability triage: open Linear CVEs for the repo that still lack a linked GitHub PR are discovered deterministically, then a Claude agent runs only when that list is non-empty.

Discovery paginates Linear (shared linear-graphql-request.sh), filters with filter-unlinked-cve-issues.jq (CVE label, no github.com/.../pull/... attachment, priority sort), and caps issues via max_issues. A reusable workflow (_cve-remediation.yml) runs discovery first and gates the remediate job on has_issues.

Remediation uses anthropics/claude-code-action with a checked-in system prompt (cve-remediation-system.md), read-only Linear MCP (--strict-mcp-config), and allow/disallow lists for git, gh pr, package managers, and tests—without merge, force-push, or publish.

A nightly workflow (cve-remediation.yml, schedule + workflow_dispatch) calls the reusable workflow with repo concurrency. CI expands the vulnerability job to vulnerability-automation and runs test-cve-remediation.sh alongside existing triage tests.

Reviewed by Cursor Bugbot for commit dcafc5a. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added scheduled and manually triggered CVE discovery and remediation workflows.
    • Added filtering and prioritization for CVE issues without valid linked pull requests.
    • Added configurable issue limits and discovery result reporting.
    • Added safeguards for credentials, repository access, and proposed remediation changes.
  • Tests

    • Added coverage for pagination, filtering, prioritization, workflow configuration, and remediation safeguards.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: b95595d9-550a-4532-ac58-4721e4089a05

📥 Commits

Reviewing files that changed from the base of the PR and between e16b75d and dcafc5a.

📒 Files selected for processing (2)
  • .github/scripts/test-cve-remediation.sh
  • .github/workflows/_cve-remediation.yml

Walkthrough

The change adds scheduled and manual CVE remediation workflows. It discovers unlinked CVE issues from Linear, filters and prioritizes them, and conditionally starts a constrained Claude remediation job. CI tests validate discovery and workflow configuration.

Changes

CVE remediation automation

Layer / File(s)Summary
CVE issue discovery and filtering
.github/scripts/*, .github/workflows/_cve-remediation.yml, .github/scripts/test-cve-remediation.sh
Queries paginated Linear issues, filters unlinked CVEs, sorts them by normalized priority, limits selected issues, and validates pagination and filtering.
Constrained remediation execution
.github/prompts/cve-remediation-system.md, .github/workflows/_cve-remediation.yml, .github/scripts/test-cve-remediation.sh
Defines remediation rules, read-only Linear MCP access, restricted Claude tools, verification steps, and pull-request creation behavior.
Scheduled execution and CI wiring
.github/workflows/cve-remediation.yml, .github/workflows/test.yml
Adds scheduled and manual workflow entry points and runs CVE remediation tests in CI.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
participant Scheduler
participant DiscoveryJob
participant Linear
participant Claude
participant Repository
Scheduler->>DiscoveryJob: Start scheduled or manual workflow
DiscoveryJob->>Linear: Query paginated open CVE issues
Linear-->>DiscoveryJob: Return issue data and cursors
DiscoveryJob->>Claude: Start remediation when issues exist
Claude->>Linear: Read issue data through read-only MCP
Claude->>Repository: Update dependencies, verify changes, and open pull requests
Loading

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the pull request's main change: automating CVE remediation workflows.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/sou-1830-automate-cve-resolution

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/_cve-remediation.yml:
- Around line 34-35: Update the checkout configuration in the reusable CVE
remediation workflow to use the available github.repository and github.sha
contexts instead of job.workflow_repository and job.workflow_sha. Preserve
same-repository caller behavior; only introduce explicit workflow inputs if
cross-repository reuse must be supported.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: d63f2d8d-14f9-41b6-b0ff-fcd0fb44a629

📥 Commits

Reviewing files that changed from the base of the PR and between f52ce7a and b85324b.

📒 Files selected for processing (7)
  • .github/prompts/cve-remediation-system.md
  • .github/scripts/filter-unlinked-cve-issues.jq
  • .github/scripts/find-unlinked-cve-issues.sh
  • .github/scripts/test-cve-remediation.sh
  • .github/workflows/_cve-remediation.yml
  • .github/workflows/cve-remediation.yml
  • .github/workflows/test.yml

Comment thread.github/workflows/_cve-remediation.yml Outdated
@brendan-kellam
brendan-kellam merged commit fcb1285 into mainAug 5, 2026
11 of 12 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/sou-1830-automate-cve-resolution branch August 5, 2026 01:53
@github-actionsgithub-actionsBot mentioned this pull request Aug 5, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit dcafc5a. Configure here.

--max-turns 80
--tools "Bash,Read,Edit,Write,Glob,Grep"
--allowedTools "Read,Edit,Write,Glob,Grep,Bash(git *),Bash(gh pr *),Bash(yarn *),Bash(npm *),Bash(npx *),Bash(pnpm *),Bash(bun *),Bash(go *),Bash(cargo *),Bash(uv *),Bash(pytest *),Bash(python -m pytest *),Bash(make *),Bash(just *),mcp__linear__get_issue,mcp__linear__list_comments"
--disallowedTools "Bash(gh pr merge *),Bash(git push *--force*),Bash(npm publish *),Bash(yarn npm publish *),Bash(pnpm publish *),Bash(cargo publish *)"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Force-push short flag still allowed

Medium Severity

disallowedTools blocks git push only when the command contains --force, while allowedTools permits all git commands under dontAsk. The common short form git push -f therefore stays auto-approved for this unattended agent, so the force-push safeguard does not cover the usual destructive path.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit dcafc5a. Configure here.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore: automate CVE remediation - #1538

Merged
brendan-kellam merged 5 commits into
mainfrom
brendan/sou-1830-automate-cve-resolution
Aug 5, 2026
Merged

chore: automate CVE remediation#1538
brendan-kellam merged 5 commits into
mainfrom
brendan/sou-1830-automate-cve-resolution

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Summary

  • add a reusable workflow that finds open repository CVEs in Linear without linked GitHub PRs
  • invoke Claude only when deterministic discovery finds work, with read-only Linear MCP access and guarded remediation instructions
  • add a nightly Sourcebot caller and CI coverage for pagination, filtering, and PR-link detection

Testing

  • .github/scripts/test-vulnerability-triage.sh
  • .github/scripts/test-cve-remediation.sh
  • workflow YAML parsing
  • actionlint
  • Bash syntax validation

Refs SOU-1830


Note

Medium Risk
The remediate job grants contents/PR write and runs an unattended agent with broad Bash and PR tooling; safeguards (read-only Linear MCP, disallowed merge/publish) reduce risk but automated dependency changes still need review.

Overview
Adds automated CVE remediation on top of existing vulnerability triage: open Linear CVEs for the repo that still lack a linked GitHub PR are discovered deterministically, then a Claude agent runs only when that list is non-empty.

Discovery paginates Linear (shared linear-graphql-request.sh), filters with filter-unlinked-cve-issues.jq (CVE label, no github.com/.../pull/... attachment, priority sort), and caps issues via max_issues. A reusable workflow (_cve-remediation.yml) runs discovery first and gates the remediate job on has_issues.

Remediation uses anthropics/claude-code-action with a checked-in system prompt (cve-remediation-system.md), read-only Linear MCP (--strict-mcp-config), and allow/disallow lists for git, gh pr, package managers, and tests—without merge, force-push, or publish.

A nightly workflow (cve-remediation.yml, schedule + workflow_dispatch) calls the reusable workflow with repo concurrency. CI expands the vulnerability job to vulnerability-automation and runs test-cve-remediation.sh alongside existing triage tests.

Reviewed by Cursor Bugbot for commit dcafc5a. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added scheduled and manually triggered CVE discovery and remediation workflows.
    • Added filtering and prioritization for CVE issues without valid linked pull requests.
    • Added configurable issue limits and discovery result reporting.
    • Added safeguards for credentials, repository access, and proposed remediation changes.
  • Tests

    • Added coverage for pagination, filtering, prioritization, workflow configuration, and remediation safeguards.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: b95595d9-550a-4532-ac58-4721e4089a05

📥 Commits

Reviewing files that changed from the base of the PR and between e16b75d and dcafc5a.

📒 Files selected for processing (2)
  • .github/scripts/test-cve-remediation.sh
  • .github/workflows/_cve-remediation.yml

Walkthrough

The change adds scheduled and manual CVE remediation workflows. It discovers unlinked CVE issues from Linear, filters and prioritizes them, and conditionally starts a constrained Claude remediation job. CI tests validate discovery and workflow configuration.

Changes

CVE remediation automation

Layer / File(s)Summary
CVE issue discovery and filtering
.github/scripts/*, .github/workflows/_cve-remediation.yml, .github/scripts/test-cve-remediation.sh
Queries paginated Linear issues, filters unlinked CVEs, sorts them by normalized priority, limits selected issues, and validates pagination and filtering.
Constrained remediation execution
.github/prompts/cve-remediation-system.md, .github/workflows/_cve-remediation.yml, .github/scripts/test-cve-remediation.sh
Defines remediation rules, read-only Linear MCP access, restricted Claude tools, verification steps, and pull-request creation behavior.
Scheduled execution and CI wiring
.github/workflows/cve-remediation.yml, .github/workflows/test.yml
Adds scheduled and manual workflow entry points and runs CVE remediation tests in CI.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
participant Scheduler
participant DiscoveryJob
participant Linear
participant Claude
participant Repository
Scheduler->>DiscoveryJob: Start scheduled or manual workflow
DiscoveryJob->>Linear: Query paginated open CVE issues
Linear-->>DiscoveryJob: Return issue data and cursors
DiscoveryJob->>Claude: Start remediation when issues exist
Claude->>Linear: Read issue data through read-only MCP
Claude->>Repository: Update dependencies, verify changes, and open pull requests
Loading

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the pull request's main change: automating CVE remediation workflows.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/sou-1830-automate-cve-resolution

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/_cve-remediation.yml:
- Around line 34-35: Update the checkout configuration in the reusable CVE
remediation workflow to use the available github.repository and github.sha
contexts instead of job.workflow_repository and job.workflow_sha. Preserve
same-repository caller behavior; only introduce explicit workflow inputs if
cross-repository reuse must be supported.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: d63f2d8d-14f9-41b6-b0ff-fcd0fb44a629

📥 Commits

Reviewing files that changed from the base of the PR and between f52ce7a and b85324b.

📒 Files selected for processing (7)
  • .github/prompts/cve-remediation-system.md
  • .github/scripts/filter-unlinked-cve-issues.jq
  • .github/scripts/find-unlinked-cve-issues.sh
  • .github/scripts/test-cve-remediation.sh
  • .github/workflows/_cve-remediation.yml
  • .github/workflows/cve-remediation.yml
  • .github/workflows/test.yml

Comment thread.github/workflows/_cve-remediation.yml Outdated
@brendan-kellam
brendan-kellam merged commit fcb1285 into mainAug 5, 2026
11 of 12 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/sou-1830-automate-cve-resolution branch August 5, 2026 01:53
@github-actionsgithub-actionsBot mentioned this pull request Aug 5, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit dcafc5a. Configure here.

--max-turns 80
--tools "Bash,Read,Edit,Write,Glob,Grep"
--allowedTools "Read,Edit,Write,Glob,Grep,Bash(git *),Bash(gh pr *),Bash(yarn *),Bash(npm *),Bash(npx *),Bash(pnpm *),Bash(bun *),Bash(go *),Bash(cargo *),Bash(uv *),Bash(pytest *),Bash(python -m pytest *),Bash(make *),Bash(just *),mcp__linear__get_issue,mcp__linear__list_comments"
--disallowedTools "Bash(gh pr merge *),Bash(git push *--force*),Bash(npm publish *),Bash(yarn npm publish *),Bash(pnpm publish *),Bash(cargo publish *)"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Force-push short flag still allowed

Medium Severity

disallowedTools blocks git push only when the command contains --force, while allowedTools permits all git commands under dontAsk. The common short form git push -f therefore stays auto-approved for this unattended agent, so the force-push safeguard does not cover the usual destructive path.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit dcafc5a. Configure here.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: automate CVE remediation - #1538

Merged
brendan-kellam merged 5 commits into
mainfrom
brendan/sou-1830-automate-cve-resolution
Aug 5, 2026
Merged

chore: automate CVE remediation#1538
brendan-kellam merged 5 commits into
mainfrom
brendan/sou-1830-automate-cve-resolution

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Summary

  • add a reusable workflow that finds open repository CVEs in Linear without linked GitHub PRs
  • invoke Claude only when deterministic discovery finds work, with read-only Linear MCP access and guarded remediation instructions
  • add a nightly Sourcebot caller and CI coverage for pagination, filtering, and PR-link detection

Testing

  • .github/scripts/test-vulnerability-triage.sh
  • .github/scripts/test-cve-remediation.sh
  • workflow YAML parsing
  • actionlint
  • Bash syntax validation

Refs SOU-1830


Note

Medium Risk
The remediate job grants contents/PR write and runs an unattended agent with broad Bash and PR tooling; safeguards (read-only Linear MCP, disallowed merge/publish) reduce risk but automated dependency changes still need review.

Overview
Adds automated CVE remediation on top of existing vulnerability triage: open Linear CVEs for the repo that still lack a linked GitHub PR are discovered deterministically, then a Claude agent runs only when that list is non-empty.

Discovery paginates Linear (shared linear-graphql-request.sh), filters with filter-unlinked-cve-issues.jq (CVE label, no github.com/.../pull/... attachment, priority sort), and caps issues via max_issues. A reusable workflow (_cve-remediation.yml) runs discovery first and gates the remediate job on has_issues.

Remediation uses anthropics/claude-code-action with a checked-in system prompt (cve-remediation-system.md), read-only Linear MCP (--strict-mcp-config), and allow/disallow lists for git, gh pr, package managers, and tests—without merge, force-push, or publish.

A nightly workflow (cve-remediation.yml, schedule + workflow_dispatch) calls the reusable workflow with repo concurrency. CI expands the vulnerability job to vulnerability-automation and runs test-cve-remediation.sh alongside existing triage tests.

Reviewed by Cursor Bugbot for commit dcafc5a. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added scheduled and manually triggered CVE discovery and remediation workflows.
    • Added filtering and prioritization for CVE issues without valid linked pull requests.
    • Added configurable issue limits and discovery result reporting.
    • Added safeguards for credentials, repository access, and proposed remediation changes.
  • Tests

    • Added coverage for pagination, filtering, prioritization, workflow configuration, and remediation safeguards.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: b95595d9-550a-4532-ac58-4721e4089a05

📥 Commits

Reviewing files that changed from the base of the PR and between e16b75d and dcafc5a.

📒 Files selected for processing (2)
  • .github/scripts/test-cve-remediation.sh
  • .github/workflows/_cve-remediation.yml

Walkthrough

The change adds scheduled and manual CVE remediation workflows. It discovers unlinked CVE issues from Linear, filters and prioritizes them, and conditionally starts a constrained Claude remediation job. CI tests validate discovery and workflow configuration.

Changes

CVE remediation automation

Layer / File(s)Summary
CVE issue discovery and filtering
.github/scripts/*, .github/workflows/_cve-remediation.yml, .github/scripts/test-cve-remediation.sh
Queries paginated Linear issues, filters unlinked CVEs, sorts them by normalized priority, limits selected issues, and validates pagination and filtering.
Constrained remediation execution
.github/prompts/cve-remediation-system.md, .github/workflows/_cve-remediation.yml, .github/scripts/test-cve-remediation.sh
Defines remediation rules, read-only Linear MCP access, restricted Claude tools, verification steps, and pull-request creation behavior.
Scheduled execution and CI wiring
.github/workflows/cve-remediation.yml, .github/workflows/test.yml
Adds scheduled and manual workflow entry points and runs CVE remediation tests in CI.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
participant Scheduler
participant DiscoveryJob
participant Linear
participant Claude
participant Repository
Scheduler->>DiscoveryJob: Start scheduled or manual workflow
DiscoveryJob->>Linear: Query paginated open CVE issues
Linear-->>DiscoveryJob: Return issue data and cursors
DiscoveryJob->>Claude: Start remediation when issues exist
Claude->>Linear: Read issue data through read-only MCP
Claude->>Repository: Update dependencies, verify changes, and open pull requests
Loading

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the pull request's main change: automating CVE remediation workflows.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/sou-1830-automate-cve-resolution

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/_cve-remediation.yml:
- Around line 34-35: Update the checkout configuration in the reusable CVE
remediation workflow to use the available github.repository and github.sha
contexts instead of job.workflow_repository and job.workflow_sha. Preserve
same-repository caller behavior; only introduce explicit workflow inputs if
cross-repository reuse must be supported.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: d63f2d8d-14f9-41b6-b0ff-fcd0fb44a629

📥 Commits

Reviewing files that changed from the base of the PR and between f52ce7a and b85324b.

📒 Files selected for processing (7)
  • .github/prompts/cve-remediation-system.md
  • .github/scripts/filter-unlinked-cve-issues.jq
  • .github/scripts/find-unlinked-cve-issues.sh
  • .github/scripts/test-cve-remediation.sh
  • .github/workflows/_cve-remediation.yml
  • .github/workflows/cve-remediation.yml
  • .github/workflows/test.yml

Comment thread.github/workflows/_cve-remediation.yml Outdated
@brendan-kellam
brendan-kellam merged commit fcb1285 into mainAug 5, 2026
11 of 12 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/sou-1830-automate-cve-resolution branch August 5, 2026 01:53
@github-actionsgithub-actionsBot mentioned this pull request Aug 5, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit dcafc5a. Configure here.

--max-turns 80
--tools "Bash,Read,Edit,Write,Glob,Grep"
--allowedTools "Read,Edit,Write,Glob,Grep,Bash(git *),Bash(gh pr *),Bash(yarn *),Bash(npm *),Bash(npx *),Bash(pnpm *),Bash(bun *),Bash(go *),Bash(cargo *),Bash(uv *),Bash(pytest *),Bash(python -m pytest *),Bash(make *),Bash(just *),mcp__linear__get_issue,mcp__linear__list_comments"
--disallowedTools "Bash(gh pr merge *),Bash(git push *--force*),Bash(npm publish *),Bash(yarn npm publish *),Bash(pnpm publish *),Bash(cargo publish *)"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Force-push short flag still allowed

Medium Severity

disallowedTools blocks git push only when the command contains --force, while allowedTools permits all git commands under dontAsk. The common short form git push -f therefore stays auto-approved for this unattended agent, so the force-push safeguard does not cover the usual destructive path.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit dcafc5a. Configure here.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: automate CVE remediation - #1538

Merged
brendan-kellam merged 5 commits into
mainfrom
brendan/sou-1830-automate-cve-resolution
Aug 5, 2026
Merged

chore: automate CVE remediation#1538
brendan-kellam merged 5 commits into
mainfrom
brendan/sou-1830-automate-cve-resolution

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Summary

  • add a reusable workflow that finds open repository CVEs in Linear without linked GitHub PRs
  • invoke Claude only when deterministic discovery finds work, with read-only Linear MCP access and guarded remediation instructions
  • add a nightly Sourcebot caller and CI coverage for pagination, filtering, and PR-link detection

Testing

  • .github/scripts/test-vulnerability-triage.sh
  • .github/scripts/test-cve-remediation.sh
  • workflow YAML parsing
  • actionlint
  • Bash syntax validation

Refs SOU-1830


Note

Medium Risk
The remediate job grants contents/PR write and runs an unattended agent with broad Bash and PR tooling; safeguards (read-only Linear MCP, disallowed merge/publish) reduce risk but automated dependency changes still need review.

Overview
Adds automated CVE remediation on top of existing vulnerability triage: open Linear CVEs for the repo that still lack a linked GitHub PR are discovered deterministically, then a Claude agent runs only when that list is non-empty.

Discovery paginates Linear (shared linear-graphql-request.sh), filters with filter-unlinked-cve-issues.jq (CVE label, no github.com/.../pull/... attachment, priority sort), and caps issues via max_issues. A reusable workflow (_cve-remediation.yml) runs discovery first and gates the remediate job on has_issues.

Remediation uses anthropics/claude-code-action with a checked-in system prompt (cve-remediation-system.md), read-only Linear MCP (--strict-mcp-config), and allow/disallow lists for git, gh pr, package managers, and tests—without merge, force-push, or publish.

A nightly workflow (cve-remediation.yml, schedule + workflow_dispatch) calls the reusable workflow with repo concurrency. CI expands the vulnerability job to vulnerability-automation and runs test-cve-remediation.sh alongside existing triage tests.

Reviewed by Cursor Bugbot for commit dcafc5a. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added scheduled and manually triggered CVE discovery and remediation workflows.
    • Added filtering and prioritization for CVE issues without valid linked pull requests.
    • Added configurable issue limits and discovery result reporting.
    • Added safeguards for credentials, repository access, and proposed remediation changes.
  • Tests

    • Added coverage for pagination, filtering, prioritization, workflow configuration, and remediation safeguards.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: b95595d9-550a-4532-ac58-4721e4089a05

📥 Commits

Reviewing files that changed from the base of the PR and between e16b75d and dcafc5a.

📒 Files selected for processing (2)
  • .github/scripts/test-cve-remediation.sh
  • .github/workflows/_cve-remediation.yml

Walkthrough

The change adds scheduled and manual CVE remediation workflows. It discovers unlinked CVE issues from Linear, filters and prioritizes them, and conditionally starts a constrained Claude remediation job. CI tests validate discovery and workflow configuration.

Changes

CVE remediation automation

Layer / File(s)Summary
CVE issue discovery and filtering
.github/scripts/*, .github/workflows/_cve-remediation.yml, .github/scripts/test-cve-remediation.sh
Queries paginated Linear issues, filters unlinked CVEs, sorts them by normalized priority, limits selected issues, and validates pagination and filtering.
Constrained remediation execution
.github/prompts/cve-remediation-system.md, .github/workflows/_cve-remediation.yml, .github/scripts/test-cve-remediation.sh
Defines remediation rules, read-only Linear MCP access, restricted Claude tools, verification steps, and pull-request creation behavior.
Scheduled execution and CI wiring
.github/workflows/cve-remediation.yml, .github/workflows/test.yml
Adds scheduled and manual workflow entry points and runs CVE remediation tests in CI.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
participant Scheduler
participant DiscoveryJob
participant Linear
participant Claude
participant Repository
Scheduler->>DiscoveryJob: Start scheduled or manual workflow
DiscoveryJob->>Linear: Query paginated open CVE issues
Linear-->>DiscoveryJob: Return issue data and cursors
DiscoveryJob->>Claude: Start remediation when issues exist
Claude->>Linear: Read issue data through read-only MCP
Claude->>Repository: Update dependencies, verify changes, and open pull requests
Loading

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the pull request's main change: automating CVE remediation workflows.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/sou-1830-automate-cve-resolution

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/_cve-remediation.yml:
- Around line 34-35: Update the checkout configuration in the reusable CVE
remediation workflow to use the available github.repository and github.sha
contexts instead of job.workflow_repository and job.workflow_sha. Preserve
same-repository caller behavior; only introduce explicit workflow inputs if
cross-repository reuse must be supported.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: d63f2d8d-14f9-41b6-b0ff-fcd0fb44a629

📥 Commits

Reviewing files that changed from the base of the PR and between f52ce7a and b85324b.

📒 Files selected for processing (7)
  • .github/prompts/cve-remediation-system.md
  • .github/scripts/filter-unlinked-cve-issues.jq
  • .github/scripts/find-unlinked-cve-issues.sh
  • .github/scripts/test-cve-remediation.sh
  • .github/workflows/_cve-remediation.yml
  • .github/workflows/cve-remediation.yml
  • .github/workflows/test.yml

Comment thread.github/workflows/_cve-remediation.yml Outdated
@brendan-kellam
brendan-kellam merged commit fcb1285 into mainAug 5, 2026
11 of 12 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/sou-1830-automate-cve-resolution branch August 5, 2026 01:53
@github-actionsgithub-actionsBot mentioned this pull request Aug 5, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit dcafc5a. Configure here.

--max-turns 80
--tools "Bash,Read,Edit,Write,Glob,Grep"
--allowedTools "Read,Edit,Write,Glob,Grep,Bash(git *),Bash(gh pr *),Bash(yarn *),Bash(npm *),Bash(npx *),Bash(pnpm *),Bash(bun *),Bash(go *),Bash(cargo *),Bash(uv *),Bash(pytest *),Bash(python -m pytest *),Bash(make *),Bash(just *),mcp__linear__get_issue,mcp__linear__list_comments"
--disallowedTools "Bash(gh pr merge *),Bash(git push *--force*),Bash(npm publish *),Bash(yarn npm publish *),Bash(pnpm publish *),Bash(cargo publish *)"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Force-push short flag still allowed

Medium Severity

disallowedTools blocks git push only when the command contains --force, while allowedTools permits all git commands under dontAsk. The common short form git push -f therefore stays auto-approved for this unattended agent, so the force-push safeguard does not cover the usual destructive path.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit dcafc5a. Configure here.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore: automate CVE remediation - #1538

Merged
brendan-kellam merged 5 commits into
mainfrom
brendan/sou-1830-automate-cve-resolution
Aug 5, 2026
Merged

chore: automate CVE remediation#1538
brendan-kellam merged 5 commits into
mainfrom
brendan/sou-1830-automate-cve-resolution

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Summary

  • add a reusable workflow that finds open repository CVEs in Linear without linked GitHub PRs
  • invoke Claude only when deterministic discovery finds work, with read-only Linear MCP access and guarded remediation instructions
  • add a nightly Sourcebot caller and CI coverage for pagination, filtering, and PR-link detection

Testing

  • .github/scripts/test-vulnerability-triage.sh
  • .github/scripts/test-cve-remediation.sh
  • workflow YAML parsing
  • actionlint
  • Bash syntax validation

Refs SOU-1830


Note

Medium Risk
The remediate job grants contents/PR write and runs an unattended agent with broad Bash and PR tooling; safeguards (read-only Linear MCP, disallowed merge/publish) reduce risk but automated dependency changes still need review.

Overview
Adds automated CVE remediation on top of existing vulnerability triage: open Linear CVEs for the repo that still lack a linked GitHub PR are discovered deterministically, then a Claude agent runs only when that list is non-empty.

Discovery paginates Linear (shared linear-graphql-request.sh), filters with filter-unlinked-cve-issues.jq (CVE label, no github.com/.../pull/... attachment, priority sort), and caps issues via max_issues. A reusable workflow (_cve-remediation.yml) runs discovery first and gates the remediate job on has_issues.

Remediation uses anthropics/claude-code-action with a checked-in system prompt (cve-remediation-system.md), read-only Linear MCP (--strict-mcp-config), and allow/disallow lists for git, gh pr, package managers, and tests—without merge, force-push, or publish.

A nightly workflow (cve-remediation.yml, schedule + workflow_dispatch) calls the reusable workflow with repo concurrency. CI expands the vulnerability job to vulnerability-automation and runs test-cve-remediation.sh alongside existing triage tests.

Reviewed by Cursor Bugbot for commit dcafc5a. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added scheduled and manually triggered CVE discovery and remediation workflows.
    • Added filtering and prioritization for CVE issues without valid linked pull requests.
    • Added configurable issue limits and discovery result reporting.
    • Added safeguards for credentials, repository access, and proposed remediation changes.
  • Tests

    • Added coverage for pagination, filtering, prioritization, workflow configuration, and remediation safeguards.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: b95595d9-550a-4532-ac58-4721e4089a05

📥 Commits

Reviewing files that changed from the base of the PR and between e16b75d and dcafc5a.

📒 Files selected for processing (2)
  • .github/scripts/test-cve-remediation.sh
  • .github/workflows/_cve-remediation.yml

Walkthrough

The change adds scheduled and manual CVE remediation workflows. It discovers unlinked CVE issues from Linear, filters and prioritizes them, and conditionally starts a constrained Claude remediation job. CI tests validate discovery and workflow configuration.

Changes

CVE remediation automation

Layer / File(s)Summary
CVE issue discovery and filtering
.github/scripts/*, .github/workflows/_cve-remediation.yml, .github/scripts/test-cve-remediation.sh
Queries paginated Linear issues, filters unlinked CVEs, sorts them by normalized priority, limits selected issues, and validates pagination and filtering.
Constrained remediation execution
.github/prompts/cve-remediation-system.md, .github/workflows/_cve-remediation.yml, .github/scripts/test-cve-remediation.sh
Defines remediation rules, read-only Linear MCP access, restricted Claude tools, verification steps, and pull-request creation behavior.
Scheduled execution and CI wiring
.github/workflows/cve-remediation.yml, .github/workflows/test.yml
Adds scheduled and manual workflow entry points and runs CVE remediation tests in CI.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
participant Scheduler
participant DiscoveryJob
participant Linear
participant Claude
participant Repository
Scheduler->>DiscoveryJob: Start scheduled or manual workflow
DiscoveryJob->>Linear: Query paginated open CVE issues
Linear-->>DiscoveryJob: Return issue data and cursors
DiscoveryJob->>Claude: Start remediation when issues exist
Claude->>Linear: Read issue data through read-only MCP
Claude->>Repository: Update dependencies, verify changes, and open pull requests
Loading

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the pull request's main change: automating CVE remediation workflows.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/sou-1830-automate-cve-resolution

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/_cve-remediation.yml:
- Around line 34-35: Update the checkout configuration in the reusable CVE
remediation workflow to use the available github.repository and github.sha
contexts instead of job.workflow_repository and job.workflow_sha. Preserve
same-repository caller behavior; only introduce explicit workflow inputs if
cross-repository reuse must be supported.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: d63f2d8d-14f9-41b6-b0ff-fcd0fb44a629

📥 Commits

Reviewing files that changed from the base of the PR and between f52ce7a and b85324b.

📒 Files selected for processing (7)
  • .github/prompts/cve-remediation-system.md
  • .github/scripts/filter-unlinked-cve-issues.jq
  • .github/scripts/find-unlinked-cve-issues.sh
  • .github/scripts/test-cve-remediation.sh
  • .github/workflows/_cve-remediation.yml
  • .github/workflows/cve-remediation.yml
  • .github/workflows/test.yml

Comment thread.github/workflows/_cve-remediation.yml Outdated
@brendan-kellam
brendan-kellam merged commit fcb1285 into mainAug 5, 2026
11 of 12 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/sou-1830-automate-cve-resolution branch August 5, 2026 01:53
@github-actionsgithub-actionsBot mentioned this pull request Aug 5, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit dcafc5a. Configure here.

--max-turns 80
--tools "Bash,Read,Edit,Write,Glob,Grep"
--allowedTools "Read,Edit,Write,Glob,Grep,Bash(git *),Bash(gh pr *),Bash(yarn *),Bash(npm *),Bash(npx *),Bash(pnpm *),Bash(bun *),Bash(go *),Bash(cargo *),Bash(uv *),Bash(pytest *),Bash(python -m pytest *),Bash(make *),Bash(just *),mcp__linear__get_issue,mcp__linear__list_comments"
--disallowedTools "Bash(gh pr merge *),Bash(git push *--force*),Bash(npm publish *),Bash(yarn npm publish *),Bash(pnpm publish *),Bash(cargo publish *)"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Force-push short flag still allowed

Medium Severity

disallowedTools blocks git push only when the command contains --force, while allowedTools permits all git commands under dontAsk. The common short form git push -f therefore stays auto-approved for this unattended agent, so the force-push safeguard does not cover the usual destructive path.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit dcafc5a. Configure here.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam