Skip to content

chore(ci): auto-close resolved issues in the vulnerability triage pipeline#1501

Draft
brendan-kellam wants to merge 2 commits into
mainfrom
brendan/sou-1587-auto-close-resolved-issues-in-the-triage-pipeline-b2df
Draft

chore(ci): auto-close resolved issues in the vulnerability triage pipeline#1501
brendan-kellam wants to merge 2 commits into
mainfrom
brendan/sou-1587-auto-close-resolved-issues-in-the-triage-pipeline-b2df

Conversation

@brendan-kellam

Copy link
Copy Markdown
Contributor

The vulnerability triage pipeline created and reopened Linear issues for CVEs/alerts, but never closed them once the vulnerability was resolved. So a fix that landed (e.g. #1474) left the corresponding issue open and it kept breaching SLA.

This adds a reconciliation step that closes resolved issues:

  • After creating/reopening issues, fetch every open pipeline-created issue (those with the [<repository>] title prefix) and close any whose finding id no longer appears in the current scan results, moving it to the team's Done (completed) state.
  • The Linear Triage job now also runs on the canonical repo when scans come back clean, so reconciliation happens even when there are zero findings (the exact case where a resolved CVE would otherwise linger open).
  • The close step is guarded on both scanners succeeding, so a failed scan (which yields an empty findings set) can't mass-close every open issue.
  • Resolves a completed workflow state (done_state_id) alongside the existing Triage state to perform the close.

Since create/reopen only touch issues whose id is present in findings and close only touches issues whose id is absent, the two operate on disjoint sets and don't conflict.

The triage pipeline created/reopened Linear issues for vulnerabilities but
never closed them once resolved, so a fixed CVE could linger as an open,
SLA-breaching issue. Reconcile open pipeline-created issues against the
current findings each run and move any whose vulnerability is no longer
reported to Done. Run triage on the canonical repo even when scans are clean
so reconciliation happens, and guard the close step on successful scans to
avoid mass-closing on scan failure.

Co-authored-by: linear-code[bot] <222613912+linear-code[bot]@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: b387849b-7407-49cc-9151-38bbd29393fc

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/sou-1587-auto-close-resolved-issues-in-the-triage-pipeline-b2df

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Co-authored-by: linear-code[bot] <222613912+linear-code[bot]@users.noreply.github.com>
@mintlify

mintlify Bot commented Jul 24, 2026

Copy link
Copy Markdown

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated (UTC)
sourcebot 🟢 Ready View Preview Jul 24, 2026, 4:30 PM

💡 Tip: Enable Workflows to automatically generate PRs for you.

@github-actions

Copy link
Copy Markdown
Contributor

License Audit

⚠️ Status: PASS

Metric Count
Total packages 2200
Resolved (non-standard) 17
Unresolved 0
Strong copyleft 0
Weak copyleft 27

Weak Copyleft Packages (informational)

Package Version License
@img/sharp-libvips-darwin-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-wasm32 0.35.3 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm64 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
axe-core 4.10.3 MPL-2.0
lightningcss 1.32.0 MPL-2.0
lightningcss-android-arm64 1.32.0 MPL-2.0
lightningcss-darwin-arm64 1.32.0 MPL-2.0
lightningcss-darwin-x64 1.32.0 MPL-2.0
lightningcss-freebsd-x64 1.32.0 MPL-2.0
lightningcss-linux-arm-gnueabihf 1.32.0 MPL-2.0
lightningcss-linux-arm64-gnu 1.32.0 MPL-2.0
lightningcss-linux-arm64-musl 1.32.0 MPL-2.0
lightningcss-linux-x64-gnu 1.32.0 MPL-2.0
lightningcss-linux-x64-musl 1.32.0 MPL-2.0
lightningcss-win32-arm64-msvc 1.32.0 MPL-2.0
lightningcss-win32-x64-msvc 1.32.0 MPL-2.0
Resolved Packages (17)
Package Version Original Resolved Source
codemirror-lang-elixir 4.0.0 UNKNOWN Apache-2.0 npm registry (registry.npmjs.org license field)
khroma 2.1.0 UNKNOWN MIT GitHub repo LICENSE (fabiospampinato/khroma)
lezer-elixir 1.1.2 UNKNOWN Apache-2.0 npm registry (registry.npmjs.org license field)
map-stream 0.1.0 UNKNOWN MIT npm registry (registry.npmjs.org license field)
memorystream 0.3.1 UNKNOWN MIT GitHub repo LICENSE (JSBizon/node-memorystream)
valid-url 1.0.9 UNKNOWN MIT GitHub repo LICENSE + package.json (ogt/valid-url)
posthog-js 1.369.0 SEE LICENSE IN LICENSE (Apache-2.0 AND MIT) npm registry (registry.npmjs.org license field)
pause-stream 0.0.11 ["MIT","Apache2"] MIT extracted from object (dual MIT / Apache2; MIT chosen)
@sentry/cli 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry (Functional Source License 1.1, MIT future grant; source-available, non-copyleft)
@sentry/cli-darwin 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry (Functional Source License 1.1, MIT future grant; source-available, non-copyleft)
@sentry/cli-linux-arm 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry (Functional Source License 1.1, MIT future grant; source-available, non-copyleft)
@sentry/cli-linux-arm64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry (Functional Source License 1.1, MIT future grant; source-available, non-copyleft)
@sentry/cli-linux-i686 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry (Functional Source License 1.1, MIT future grant; source-available, non-copyleft)
@sentry/cli-linux-x64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry (Functional Source License 1.1, MIT future grant; source-available, non-copyleft)
@sentry/cli-win32-arm64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry (Functional Source License 1.1, MIT future grant; source-available, non-copyleft)
@sentry/cli-win32-i686 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry (Functional Source License 1.1, MIT future grant; source-available, non-copyleft)
@sentry/cli-win32-x64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry (Functional Source License 1.1, MIT future grant; source-available, non-copyleft)

@msukkari
msukkari force-pushed the brendan/sou-1587-auto-close-resolved-issues-in-the-triage-pipeline-b2df branch from 3a831de to 943c2e5 Compare July 24, 2026 16:39
@msukkari
msukkari force-pushed the brendan/sou-1587-auto-close-resolved-issues-in-the-triage-pipeline-b2df branch from 943c2e5 to 116cbb0 Compare July 24, 2026 16:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant