Add support for creating and updating repository security advisories#2631
Open
advancedresearcharray wants to merge 1 commit into
Open
Conversation
709eff1 to
2a1584f
Compare
Author
|
Cleaned commit history and PR description (removed third-party attribution trailers). PR adds three CI workflows are awaiting maintainer approval for this fork PR. |
b1a3997 to
d011eee
Compare
…t tools Add MCP tools for the repository security advisory lifecycle: create_repository_security_advisory, update_repository_security_advisory, and request_cve_for_repository_security_advisory. Create requires exactly one of severity or cvssVectorString. Update uses presence detection so optional string fields can be cleared, validates GHSA IDs before path interpolation, and enforces MCP safety annotations.
d011eee to
55952fd
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
create_repository_security_advisory,update_repository_security_advisory, andrequest_cve_for_repository_security_advisorytools to thesecurity_advisoriestoolsetCloses #2506
Test plan
go test ./pkg/github -run 'Test_(Create|Update|RequestCVE|ParseAdvisory)'go test ./pkg/githubgo run ./cmd/github-mcp-server generate-docs