magpie-security-issue-import-from-pr

Solid

Open a tracking issue in <tracker> for a security-relevant fix that has already been opened (or merged) as a public PR in <upstream>, in the case where there is no inbound `<security-list>` report. The tracker lands in the `Assessed` board column with the scope label applied, `pr created` / `pr merged` reflecting the PR's state, and `Remediation developer` / `PR with the fix` body fields populated from the PR. Pairs with `security-cve-allocate` afterwards.

AI & Automation 104 stars 93 forks Updated today Apache-2.0

Install

View on GitHub

Quality Score: 84/100

Stars 20%
67
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

<!-- Placeholder convention (see AGENTS.md#placeholder-convention-used-in-skill-files): <project-config> → adopting project's `.apache-magpie/` directory <tracker> → value of `tracker_repo:` in <project-config>/project.md <upstream> → value of `upstream_repo:` in <project-config>/project.md Before running any bash command below, substitute these with the concrete values from the adopting project's <project-config>/project.md. --> # security-issue-import-from-pr <!-- BEGIN MAGPIE PREFLIGHT — generated from tools/dev/preflight-block.md --> <!-- START doctoc generated TOC please keep comment here to allow auto update --> <!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --> **Table of Contents** *generated with [DocToc](https://github.com/thlorenz/doctoc)* - [Pre-flight — is this project set up?](#pre-flight--is-this-project-set-up) <!-- END doctoc generated TOC please keep comment here to allow auto update --> <!-- SPDX-License-Identifier: Apache-2.0 https://www.apache.org/licenses/LICENSE-2.0 --> ## Pre-flight — is this project set up? Do this **first, before anything else in this skill**, and do it silently: a couple of file checks, or one CLI call for a marketplace install. 1. **Is a lock present?** If `.apache-magpie.lock` exists, read its `method`. 2. **A snapshot method** (`svn-zip` / `git-tag` / `git-branch`) → compare with `.apache-magpie.local.lock`: - local lock missing → the snapshot was never ...

Details

Author
apache
Repository
apache/magpie
Created
5 months ago
Last Updated
today
Language
Python
License
Apache-2.0

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category