Magpie Security Issue Triage

For each open `<tracker>` issue carrying the `needs triage` label, read body + comments and classify the candidate disposition into one of six classes: VALID / DEFENSE-IN-DEPTH / INFO-ONLY / INVALID / PROBABLE-DUP / FIX-ALREADY-PUBLIC. On user confirmation, posts a triage-proposal comment that invites the security team to react. Read-only on tracker state — no label flips, closes, or CVE allocations. Supports `--retriage` for re-litigating passed-triage decisions when substantive new activity lands.

apache 717b53c 39.9 KB Updated

File contents

apache/airflow-steward/tree/main/skills/security-issue-triage commit 717b53c75a

Frequently asked questions

npx skillmds@latest add apache/magpie-security-issue-triage