Skip to content

ci(scan): adopt static pin check for auto-exec MCP launchers (annotate-only) - #891

Draft
bryan-anthropic wants to merge 1 commit into
mainfrom
scan-pin-check-repin
Draft

ci(scan): adopt static pin check for auto-exec MCP launchers (annotate-only)#891
bryan-anthropic wants to merge 1 commit into
mainfrom
scan-pin-check-repin

Conversation

@bryan-anthropic

Copy link
Copy Markdown
Collaborator

What

Adopts the shared scan action's new deterministic static pin check on this marketplace, in annotate-only posture:

  • Re-pins scan-plugins to the head of ci(scan): deterministic static pin check for auto-exec MCP launchers (per-consumer severity) claude-plugins-community#2361, which adds an always-on, auth-free static classification of each scanned entry's declared .mcp.json MCP servers: a package-manager launcher (npx/bunx/uvx/pipx) with a floating spec (@latest/dist-tag, version range, or bare unversioned name) executes registry-resolved code at session start — code the entry's pinned source SHA does not fix.
  • This surface stays warn-only: fail-on-unpinned-autoexec is deliberately not set. Findings surface as ::warning annotations, a summary-table column, and unpinned_autoexec_* fields on the verdict output — for maintainer judgment, not an automatic block.
  • No waivers file here: this marketplace currently has no adjudicated pin exceptions (the sibling official-marketplace PR ships one seeded with its two existing grants).

Merge order

Hold until anthropics/claude-plugins-community#2361 merges, then update the pin here to its merge SHA (the current pin is #2361's review head, kept so CI on this PR exercises the real step).

Draft for review — please do not merge without a maintainer stamp.

…e-only)

Re-pin scan-plugins to the community#2361 head: deterministic detection
of floating npx/bunx/uvx/pipx MCP-server launcher specs (registry-resolved
at session start, not fixed by the pinned source SHA). This surface stays
annotate-only — fail-on-unpinned-autoexec is deliberately not set, and no
waivers file is shipped (no adjudicated pin exceptions here).

Re-pin to the merge SHA once community#2361 lands.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant