Airflow maintainers use Magpie to investigate security reports and prepare fixes.
- Incoming external security reports
- Maintainer time without Magpie
- Maintainer time with Magpie
Shaded area: time back for maintainers
“Using Magpie helped us to do things that matter”
What does Magpie do here?
Magpie’s skills cover the whole process, from checking a security report to fixing the problem, releasing the fix, and closing the report.
A security report arrives in your project
You need to know whether the report is valid
The vulnerability is confirmed, so it’s time to fix it
The patch is merged, but users still need a release
Now users need to know how to protect themselves
The fix is public, and the report can be closed
ReportA security report arrives in your project
- You open one organized report
- You review the collected evidence
- You read the discussion in one place
Compare with doing it manually
- You find the report in your emails
- You copy logs and screenshots
- You piece together the discussion
TriageYou need to know whether the report is valid
- You review checks against the security rules
- You review matching past reports
- You review the suggested next step
Compare with doing it manually
- You read the project’s security rules
- You search for similar past reports
- You work out whether a fix is needed
Fix & testThe vulnerability is confirmed, so it’s time to fix it
- You review how to reproduce the bug
- You review the patch and test
- You review the check results
Compare with doing it manually
- You reproduce the bug
- You write the patch and test
- You run the checks
ReleaseThe patch is merged, but users still need a release
- You review the release checks
- You review the recorded version
- You review the collected release links
Compare with doing it manually
- You find the fix in the release
- You look up the published version
- You copy release links into the report
DiscloseNow users need to know how to protect themselves
- You review the drafted advisory and CVE
- You review the versions and update steps
- You review the reporter’s credit
Compare with doing it manually
- You write the advisory and CVE
- You list affected versions and fixes
- You add the reporter’s credit
CloseThe fix is public, and the report can be closed
- You review the advisory check
- You review the report prepared for closure
- You review the saved lessons
Compare with doing it manually
- You check the public advisory
- You gather the links to close the report
- You write down what you learned

