Auto-assign severity label when a CVE is requested to secalert
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 62/100
Direzione di ricerca
Nell’issue non sono indicati file o test. Inizia individuando il punto di ingresso che gestisce i commenti delle secalert requests e l’applicazione esistente degli issue-label; il lavoro è completo quando vengono abbinate le forme CVSS indicate, vengono mantenute le Severity-Labels esistenti e le labels richieste vengono applicate solo ai commenti secalert.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Description
When the team requests a CVE to secalert (via a comment containing the secalert email template), the bot should parse the CVSS score from the comment and automatically assign the corresponding severity/* label to the issue. This closes the gap where issues get a CVE requested but the severity label is never applied.
Value Proposition
The team consistently includes a CVSS score in secalert request emails. Secalert almost always adopts the team's score. Despite this, severity labels are frequently forgotten, leaving triaged issues without proper severity classification. Automating this removes a manual step that is easy to forget and ensures every CVE request results in a correctly labeled issue.
Goals
- Detect when a comment contains a secalert email template (look for the
* **CVSS:**field or a CVSS:3.1 vector string) - Parse the CVSS score and severity from the vector string or the parenthetical (e.g.,
4.3 Medium,9.1 Critical) - Map the severity to the corresponding label:
- Critical (9.0-10.0) →
severity/critical - High (7.0-8.9) →
severity/high - Medium (4.0-6.9) →
severity/medium - Low (0.1-3.9) →
severity/low
- Critical (9.0-10.0) →
- Apply the label automatically to the issue
- If a
severity/*label is already present, do not override it (the existing label was set intentionally) - Automatically apply the label status/embargoed
Non-Goals
- Validating the CVSS vector or recalculating the score — trust the score as written
- Assigning severity based on non-secalert comments
- Removing or changing existing severity labels
Discussion
No response
Notes
- The secalert email template always contains a line like:
* **CVSS:** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N (4.3 Medium) - A regex matching
CVSS:3\.1/[A-Z/:]+\s*\((\d+\.\d+)\s+(Critical|High|Medium|Low)\)should reliably extract both score and severity - The bot should also handle plain-text variants without bold formatting (e.g.,
* CVSS:without**) since the template is sometimes pasted as plain text - Consider also applying the
kind/cvelabel if not already present, since requesting a CVE to secalert implies CVE classification
Discussion
No response
Motivation
No response
Details
No response
- Lingua principale
- Java
- Stelle
- 9
- Fork
- 11
- Merge medio
- 2g 1h
- PR unite (30g)
- 3
Preparare l'ambiente
Non abbiamo ancora controllato i file di configurazione di questo progetto. Parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di keycloak/keycloak-github-bot
-
kind/enhancement status/triage
Difficoltà 3/5 1-2 giorni Idoneità per principianti 58/100
-
kind/bug status/triage
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
keycloak/keycloak-github-bot#78 · 1 commento ·
-
kind/enhancement status/triage
Difficoltà 4/5 3-5 giorni Idoneità per principianti 65/100
keycloak/keycloak-github-bot#76 · 5 commenti ·
-
kind/bug status/triage
Difficoltà 3/5 1-2 giorni Idoneità per principianti 55/100
keycloak/keycloak-github-bot#74 · 1 commento ·
-
kind/feature status/triage
Difficoltà 4/5 3-5 giorni Idoneità per principianti 38/100
Tutte le issue di keycloak/keycloak-github-bot
Issue simili
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
-
feature triaged
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 75/100
Graylog2/graylog2-server#27549 ·
I maintainer di solito rispondono entro 1 giorno
-
component/zeebe kind/bug
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
UniversalMediaServer/UniversalMediaServer#6356 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
googleapis/google-cloud-java#14533 ·
I maintainer di solito rispondono entro 1 giorno