Skip to content

chore: automate CVE remediation - #1538

Merged
brendan-kellam merged 5 commits into
mainfrom
brendan/sou-1830-automate-cve-resolution
Aug 5, 2026
Merged

chore: automate CVE remediation#1538
brendan-kellam merged 5 commits into
mainfrom
brendan/sou-1830-automate-cve-resolution

Conversation

@brendan-kellam

@brendan-kellam brendan-kellam commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Summary

  • add a reusable workflow that finds open repository CVEs in Linear without linked GitHub PRs
  • invoke Claude only when deterministic discovery finds work, with read-only Linear MCP access and guarded remediation instructions
  • add a nightly Sourcebot caller and CI coverage for pagination, filtering, and PR-link detection

Testing

  • .github/scripts/test-vulnerability-triage.sh
  • .github/scripts/test-cve-remediation.sh
  • workflow YAML parsing
  • actionlint
  • Bash syntax validation

Refs SOU-1830


Note

Medium Risk
The remediate job grants contents/PR write and runs an unattended agent with broad Bash and PR tooling; safeguards (read-only Linear MCP, disallowed merge/publish) reduce risk but automated dependency changes still need review.

Overview
Adds automated CVE remediation on top of existing vulnerability triage: open Linear CVEs for the repo that still lack a linked GitHub PR are discovered deterministically, then a Claude agent runs only when that list is non-empty.

Discovery paginates Linear (shared linear-graphql-request.sh), filters with filter-unlinked-cve-issues.jq (CVE label, no github.com/.../pull/... attachment, priority sort), and caps issues via max_issues. A reusable workflow (_cve-remediation.yml) runs discovery first and gates the remediate job on has_issues.

Remediation uses anthropics/claude-code-action with a checked-in system prompt (cve-remediation-system.md), read-only Linear MCP (--strict-mcp-config), and allow/disallow lists for git, gh pr, package managers, and tests—without merge, force-push, or publish.

A nightly workflow (cve-remediation.yml, schedule + workflow_dispatch) calls the reusable workflow with repo concurrency. CI expands the vulnerability job to vulnerability-automation and runs test-cve-remediation.sh alongside existing triage tests.

Reviewed by Cursor Bugbot for commit dcafc5a. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added scheduled and manually triggered CVE discovery and remediation workflows.
    • Added filtering and prioritization for CVE issues without valid linked pull requests.
    • Added configurable issue limits and discovery result reporting.
    • Added safeguards for credentials, repository access, and proposed remediation changes.
  • Tests

    • Added coverage for pagination, filtering, prioritization, workflow configuration, and remediation safeguards.

@github-actions

This comment has been minimized.

@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: b95595d9-550a-4532-ac58-4721e4089a05

📥 Commits

Reviewing files that changed from the base of the PR and between e16b75d and dcafc5a.

📒 Files selected for processing (2)
  • .github/scripts/test-cve-remediation.sh
  • .github/workflows/_cve-remediation.yml

Walkthrough

The change adds scheduled and manual CVE remediation workflows. It discovers unlinked CVE issues from Linear, filters and prioritizes them, and conditionally starts a constrained Claude remediation job. CI tests validate discovery and workflow configuration.

Changes

CVE remediation automation

Layer / File(s) Summary
CVE issue discovery and filtering
.github/scripts/*, .github/workflows/_cve-remediation.yml, .github/scripts/test-cve-remediation.sh
Queries paginated Linear issues, filters unlinked CVEs, sorts them by normalized priority, limits selected issues, and validates pagination and filtering.
Constrained remediation execution
.github/prompts/cve-remediation-system.md, .github/workflows/_cve-remediation.yml, .github/scripts/test-cve-remediation.sh
Defines remediation rules, read-only Linear MCP access, restricted Claude tools, verification steps, and pull-request creation behavior.
Scheduled execution and CI wiring
.github/workflows/cve-remediation.yml, .github/workflows/test.yml
Adds scheduled and manual workflow entry points and runs CVE remediation tests in CI.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Scheduler
  participant DiscoveryJob
  participant Linear
  participant Claude
  participant Repository
  Scheduler->>DiscoveryJob: Start scheduled or manual workflow
  DiscoveryJob->>Linear: Query paginated open CVE issues
  Linear-->>DiscoveryJob: Return issue data and cursors
  DiscoveryJob->>Claude: Start remediation when issues exist
  Claude->>Linear: Read issue data through read-only MCP
  Claude->>Repository: Update dependencies, verify changes, and open pull requests
Loading

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the pull request's main change: automating CVE remediation workflows.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/sou-1830-automate-cve-resolution

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/_cve-remediation.yml:
- Around line 34-35: Update the checkout configuration in the reusable CVE
remediation workflow to use the available github.repository and github.sha
contexts instead of job.workflow_repository and job.workflow_sha. Preserve
same-repository caller behavior; only introduce explicit workflow inputs if
cross-repository reuse must be supported.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: d63f2d8d-14f9-41b6-b0ff-fcd0fb44a629

📥 Commits

Reviewing files that changed from the base of the PR and between f52ce7a and b85324b.

📒 Files selected for processing (7)
  • .github/prompts/cve-remediation-system.md
  • .github/scripts/filter-unlinked-cve-issues.jq
  • .github/scripts/find-unlinked-cve-issues.sh
  • .github/scripts/test-cve-remediation.sh
  • .github/workflows/_cve-remediation.yml
  • .github/workflows/cve-remediation.yml
  • .github/workflows/test.yml

Comment thread .github/workflows/_cve-remediation.yml Outdated
@brendan-kellam
brendan-kellam merged commit fcb1285 into main Aug 5, 2026
11 of 12 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/sou-1830-automate-cve-resolution branch August 5, 2026 01:53

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit dcafc5a. Configure here.

--max-turns 80
--tools "Bash,Read,Edit,Write,Glob,Grep"
--allowedTools "Read,Edit,Write,Glob,Grep,Bash(git *),Bash(gh pr *),Bash(yarn *),Bash(npm *),Bash(npx *),Bash(pnpm *),Bash(bun *),Bash(go *),Bash(cargo *),Bash(uv *),Bash(pytest *),Bash(python -m pytest *),Bash(make *),Bash(just *),mcp__linear__get_issue,mcp__linear__list_comments"
--disallowedTools "Bash(gh pr merge *),Bash(git push *--force*),Bash(npm publish *),Bash(yarn npm publish *),Bash(pnpm publish *),Bash(cargo publish *)"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Force-push short flag still allowed

Medium Severity

disallowedTools blocks git push only when the command contains --force, while allowedTools permits all git commands under dontAsk. The common short form git push -f therefore stays auto-approved for this unattended agent, so the force-push safeguard does not cover the usual destructive path.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit dcafc5a. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant