Skip to content

feat(triage-security): add release Jira orchestration and cross-CVE dedup - #322

Open
ruromero wants to merge 3 commits into
RHEcosystemAppEng:mainfrom
ruromero:TC-6724
Open

ruromero wants to merge 3 commits into
RHEcosystemAppEng:mainfrom
ruromero:TC-6724

Conversation

@ruromero

@ruromero ruromero commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Add Step 7.5 (Release Jira Orchestration) to triage-security skill: finds or creates a release Epic and release Task for the affected stream before remediation task creation, with individual engineer confirmation for version decisions
  • Add cross-CVE dedup logic (Step 7.5.3) that skips remediation task creation when an existing task already covers the same Upstream Affected Component, linking the new CVE instead
  • Add "dependency bump" remediation template for cargo update/npm update fixes, distinct from upstream backport (used when upstream already ships the fix)
  • Enhance discovery mode with release Jira summary showing remediation progress per release
  • Update flowchart, ecosystem classification table, pre-creation checklist, and post-triage summary to reflect new steps
  • Fix eval-20 time-dependent staleness check fixture by anchoring to explicit date (TC-6725)

Implements TC-6724
Implements TC-6725

Test plan

  • Verify Step 7.5.1 JQL finds existing release Epics matching "RHTPA x.y.z Release Tasks" pattern
  • Verify release Epic creation prompts for version and defaults to next patch bump
  • Verify release Task created as child of Epic with correct summary pattern
  • Verify dedup: second CVE with same Upstream Affected Component skips task creation and creates correct links
  • Verify non-dedup remediation Tasks are linked to release Task via Blocks
  • Verify dependency bump template produces correct description for cargo and npm
  • Verify discovery mode output groups by release Jira with progress counts
  • Verify existing templates (backport, propagation, system package) are unchanged
  • Verify skillsaw passes with no new errors
  • Verify eval-20 passes at 100% with the anchored date

🤖 Generated with Claude Code

…edup

Add pre-Step-8 release Jira orchestration (Step 7.5) that finds or creates
a release Epic and release Task for the affected stream, with cross-CVE
dedup to skip task creation when an existing remediation Task already covers
the same Upstream Affected Component.

Add dependency bump remediation template for cargo update/npm update fixes
as a distinct variant from upstream backport, used when Step 2.5 confirms
the upstream branch already ships the fixed version.

Update discovery mode to include a release Jira summary showing remediation
progress per release.

Implements TC-6724

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Assisted-by: Claude Code
@sourcery-ai

sourcery-ai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Reviewer's Guide

Adds a confirmed release Epic/Task orchestration layer around security triage, deduplicates remediation across CVEs sharing an upstream component, and introduces dependency-bump remediation templates while updating discovery reporting, workflow branching, Jira links, and summaries.

Sequence diagram for release Jira orchestration and CVE deduplication

sequenceDiagram
    participant Engineer
    participant Triage as Security_Triage
    participant Jira
    Engineer->>Triage: Start triage
    Triage->>Jira: search_jql release Epic
    alt Release Epic missing
        Triage->>Engineer: Confirm version
        Engineer-->>Triage: Accept or specify version
        Triage->>Jira: jira.create_issue release Epic
    end
    Triage->>Jira: search_jql release Task
    alt Release Task missing
        Triage->>Engineer: Confirm Task creation
        Engineer-->>Triage: Confirm or skip
        Triage->>Jira: jira.create_issue release Task
    end
    Triage->>Jira: jira.get_issue release Task with issuelinks
    Triage->>Jira: jira.get_issue linked remediation Tasks
    alt Existing Task covers upstream component
        Triage->>Jira: jira.create_link CVE to existing Task
        Triage->>Jira: jira.create_link CVE to release Task
        Triage->>Jira: jira.edit_issue add CVE label
    else No existing coverage
        Triage->>Jira: jira.create_issue remediation Tasks
        Triage->>Jira: jira.create_link Tasks to release Task
        Triage->>Jira: jira.create_link CVE to release Task
    end
Loading

Flow diagram for release orchestration and cross-CVE deduplication

flowchart TD
    TRIAGE["Concurrent triage complete"] --> RELEASE["Resolve release version"]
    RELEASE --> EPIC{"Release Epic exists?"}
    EPIC -->|Yes| TASK["Find release Task"]
    EPIC -->|No| CONFIRM_EPIC["Confirm version with engineer"]
    CONFIRM_EPIC --> CREATE_EPIC["jira.create_issue"]
    CREATE_EPIC --> TASK
    TASK --> TASK_EXISTS{"Release Task exists?"}
    TASK_EXISTS -->|Yes| DEDUP["Inspect linked remediation Tasks"]
    TASK_EXISTS -->|No| CONFIRM_TASK["Confirm Task creation"]
    CONFIRM_TASK --> CREATE_TASK["jira.create_issue"]
    CREATE_TASK --> DEDUP
    DEDUP --> MATCH{"Same upstream component covered?"}
    MATCH -->|Yes| LINK_EXISTING["jira.create_link and jira.edit_issue"]
    MATCH -->|No| REMEDIATION["Create remediation Tasks"]
    REMEDIATION --> RELEASE_LINK["Link remediation Tasks to release Task"]
Loading

File-Level Changes

Change Details Files
Introduces release-scoped Jira orchestration before remediation creation.
  • Adds Step 7.5 to resolve stream versions, find or create release Epics, and create child release Tasks with engineer confirmation for mutations.
  • Defines release naming, JQL searches, parent-child relationships, digest comments, and skip behavior when release Jira is declined.
  • Adds discovery-mode reporting of CVE and remediation progress grouped by release Jira.
plugins/sdlc-workflow/skills/triage-security/SKILL.md
plugins/sdlc-workflow/skills/triage-security/jira-triage-operations.md
Adds cross-CVE remediation deduplication based on the upstream affected component.
  • Inspects remediation Tasks linked to the release Task and matches components using labels with a library-name fallback.
  • Skips duplicate remediation creation, links the new CVE to the existing remediation Task and release Task, and adds the CVE label.
  • Propagates dedup state into the remediation flow, checklist, and post-triage summary.
plugins/sdlc-workflow/skills/triage-security/SKILL.md
plugins/sdlc-workflow/skills/triage-security/jira-triage-operations.md
Adds a dependency-bump remediation path when the upstream fix already exists.
  • Distinguishes dependency bump plus downstream propagation from upstream backport plus downstream propagation.
  • Provides Cargo and npm update commands, version and lockfile acceptance criteria, dependency-scope handling, and task creation instructions.
  • Preserves existing backport, propagation, and system-package templates.
plugins/sdlc-workflow/skills/triage-security/SKILL.md
plugins/sdlc-workflow/skills/triage-security/remediation-templates.md
Updates triage workflow documentation and Jira linkage requirements for release tracking.
  • Updates the flowchart, ecosystem classification, execution order, pre-creation checklist, and post-triage summary.
  • Links remediation Tasks to release Tasks with Blocks and CVEs to release Tasks with Related.
  • Documents release references and dedup outcomes in vulnerability comments.
plugins/sdlc-workflow/skills/triage-security/SKILL.md
plugins/sdlc-workflow/skills/triage-security/remediation-templates.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've found 1 issue

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path="plugins/sdlc-workflow/skills/triage-security/jira-triage-operations.md" line_range="621-627" />
<code_context>
+   check if its summary or description references the same upstream component
+   as the current CVE. Two matching strategies:
+
+   a. **Component field match** (primary): if the linked Task's labels include the
+      same component label (matching the Component label pattern from Security
+      Configuration, e.g., `pscomponent:org/repo`), it covers the same component.
+   b. **Summary fallback**: if the linked Task's summary contains the same library
+      name as the current CVE's vulnerable library (from Step 1), it covers the
+      same component.
+
+4. **If a covering remediation Task is found:**
+
</code_context>
<issue_to_address>
**issue (bug_risk):** The primary dedup strategy looks for the upstream component in remediation-task labels, but the new remediation task creation examples only add `ai-generated-jira`, `Security`, and the CVE ID; they do not add the component label or populate a task component field. Dedup therefore falls back to a library-name substring match, which both misses tasks whose summaries use different naming and incorrectly merges unrelated repositories or forks sharing a library name.

**Triggers:** When an existing remediation task lacks an exact component label and another component uses the same library name.

**Suggested fix:** Persist the exact Upstream Affected Component on every remediation task, and compare that value rather than using an unqualified library-name substring fallback.
</issue_to_address>

Sourcery assessment

Needs a human reviewer. 1 finding to address first, and a false-positive cross-CVE match based on a component label or library name could skip creation of the remediation tasks needed for a vulnerability, leaving it associated with a task that does not fix it. Reverting the workflow instructions would not recreate any remediation task that was missed, so the gap requires manual repair.

Blocking findings: plugins/sdlc-workflow/skills/triage-security/jira-triage-operations.md:627


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

Comment thread plugins/sdlc-workflow/skills/triage-security/jira-triage-operations.md Outdated
…atching

Replace label/summary matching in Step 7.5.3 with Depend-link traversal:
resolve each remediation Task's parent CVE via Depend links, then compare
Upstream Affected Component (customfield_10632) values. Summary matching
retained only as fallback when the Depend link or field is missing.

Implements TC-6724

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Assisted-by: Claude Code

@github-actions github-actions Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Eval Results

Eval Results: triage-security

Eval Passed Failed Pass Rate
eval-1 11/11 0 100%
eval-2 5/5 0 100%
eval-3 5/5 0 100%
eval-4 5/5 0 100%
eval-5 6/6 0 100%
eval-6 5/6 1 83%
eval-7 5/5 0 100%
eval-8 8/8 0 100%
eval-9 5/5 0 100%
eval-10 5/5 0 100%
eval-11 5/5 0 100%
eval-12 5/5 0 100%
eval-13 5/5 0 100%
eval-14 5/5 0 100%
eval-15 5/5 0 100%
eval-16 7/7 0 100%
eval-17 5/5 0 100%
eval-18 5/5 0 100%
eval-19 5/5 0 100%
eval-20 4/4 0 100%
eval-21 4/4 0 100%
eval-22 4/4 0 100%
eval-23 4/4 0 100%
eval-24 4/4 0 100%
eval-25 4/4 0 100%
eval-26 5/5 0 100%
eval-27 5/5 0 100%
eval-28 5/5 0 100%
eval-29 5/5 0 100%
eval-30 4/4 0 100%
eval-31 4/4 0 100%
eval-32 4/4 0 100%

Failed Assertions

eval-6: 1 failing assertion
  • Assertion: "Each listed issue shows: issue key, status, CVE ID (from labels), summary, and created date"
    Evidence: "Query 1 and Query 2 tables include all five fields (Issue, Status, CVE ID, Summary, Created) for all issues. However, Query 3&#x27;s filtering analysis table for TC-9023 and TC-9026 only shows Issue, Status, and CVE ID &mdash; missing Summary and Created columns. While status-handling.md provides Summary for TC-9023 (&#x27;rustls - Certificate validation bypass&#x27;) and TC-9026 (&#x27;openssl - Buffer overflow in X.509 parsing&#x27;), neither file provides a Created date for TC-9023 or TC-9026 anywhere in the outputs."

Pass rate: 99% · Tokens: 86,813 · Duration: 139s


Generated by sdlc-workflow/run-evals v0.13.9

@ruromero ruromero added the ok-to-test Enable verify-pr execution on PRs from forks label Oct 5, 2026
@ruromero

ruromero commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator Author

[sdlc-workflow/verify-pr] Re: @sourcery-ai[bot] review — Classified as code change request — the dedup strategy concern was addressed in commit fb7d9ee, which replaced label/summary matching with Depend-link traversal comparing Upstream Affected Component (customfield_10632) values on parent CVEs. No sub-task created.

@ruromero

ruromero commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator Author

Verification Report for TC-6724 (commit fb7d9ee)

Check Result Details
Review Feedback PASS 1 code change request from sourcery-ai — addressed in commit fb7d9ee
Root-Cause Investigation N/A No unresolved review sub-tasks
Scope Containment PASS 3 files modified, exact match with task spec
Diff Size PASS 438 additions across 3 Markdown files, proportionate to task scope
Commit Traceability PASS Both commits reference TC-6724
Sensitive Patterns PASS No secrets detected; all values are placeholders
CI Status PASS All 5 checks pass
Acceptance Criteria PASS 12 of 12 criteria met
Test Quality WARN Eval Quality: 97% (148/152). eval-17: 1 pre-existing. eval-20: 3 new (time-dependent fixture, not PR-caused). Sub-task TC-6725 created.
Test Change Classification N/A No test files in PR
Verification Commands N/A None specified

Overall: WARN

eval-20 has 3 regression failures caused by a hardcoded Last-Updated timestamp (2026-06-28) aging past the 14-day staleness threshold (now 99 days old). This is a pre-existing eval fixture issue exposed by time passage — not caused by PR changes. Sub-task TC-6725 created to fix the time-dependent fixture.


This comment was AI-generated by sdlc-workflow/verify-pr v0.13.9.

…ic staleness check

Add "treat today's date as 2026-06-29T10:00:00Z" instruction to eval-20
prompt so the staleness check against the fixture's Last-Updated timestamp
(2026-06-28) always computes 1 day old, well within the 14-day threshold.

This prevents the 3 assertion failures caused by the hardcoded fixture date
aging past the threshold over time.

Implements TC-6725

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Assisted-by: Claude Code
@ruromero

ruromero commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator Author

Verification Report for TC-6724 (commit be9508f)

Check Result Details
Review Feedback PASS 1 code change request from sourcery-ai — addressed in commit fb7d9ee
Root-Cause Investigation N/A No new sub-tasks created this run
Scope Containment WARN 4 files vs 3 in task spec; extra evals/triage-security/evals.json from sub-task TC-6725
Diff Size PASS 461 changes across 4 files, proportionate to scope
Commit Traceability PASS All 3 commits reference TC-6724 or TC-6725
Sensitive Patterns PASS No secrets detected
CI Status PASS All 5 checks pass
Acceptance Criteria PASS 12 of 12 criteria met
Test Quality PASS Eval Quality: 99% (161/162). eval-6: 1 pre-existing non-deterministic failure (same assertion fails in 2/10 historical baselines). eval-20: fixed (4/4). eval-17: fixed (5/5).
Test Change Classification N/A No test files in PR
Verification Commands N/A None specified

Overall: PASS

Scope Containment WARN is informational — extra file is from sub-task TC-6725 (eval fixture fix), not untracked scope creep. All acceptance criteria met, CI green, eval pass rate improved from 97% to 99%.


This comment was AI-generated by sdlc-workflow/verify-pr v0.13.9.

@ruromero
ruromero requested a review from mrizzi October 5, 2026 18:32

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ok-to-test Enable verify-pr execution on PRs from forks

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant