Skip to content

Replace vulnerable ast-grep MCP container - #51718

Merged
pelikhan merged 2 commits into
mainfrom
copilot/container-image-scan
Aug 10, 2026
Merged

pelikhan merged 2 commits into
mainfrom
copilot/container-image-scan

Conversation

Copilot AI commented Aug 10, 2026 •

Copy link
Copy Markdown
Contributor

The shared ast-grep MCP workflow import used mcp/ast-grep:latest, which was flagged with Critical/High container vulnerabilities and license findings. This change removes that container from workflow execution and embedded pin data.

  • MCP configuration

    • Switches ast-grep from the Docker image to the npm MCP server:
      mcp-servers:
        ast-grep:
          command: "npx"
          args: ["ast-grep-mcp@0.0.2"]
          allowed: ["*"]
  • Generated workflow locks

    • Recompiles workflows that import shared/mcp/ast-grep.md.
    • Removes mcp/ast-grep:latest from generated container manifests.
  • Pin data

    • Removes the stale mcp/ast-grep:latest@sha256:... entry from repository action/container pin data.
  • Regression coverage

    • Adds a focused test asserting the vulnerable ast-grep container is not embedded as a pinned container image.

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix vulnerabilities in mcp/ast-grep:latest Replace vulnerable ast-grep MCP container Aug 10, 2026
Copilot AI requested a review from pelikhan August 10, 2026 07:01
@pelikhan
pelikhan marked this pull request as ready for review August 10, 2026 10:05
Copilot AI balanced review requested due to automatic review settings August 10, 2026 10:05
@pelikhan
pelikhan merged commit 56d4f3b into main Aug 10, 2026
@pelikhan
pelikhan deleted the copilot/container-image-scan branch August 10, 2026 10:05

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Replaces the vulnerable ast-grep container with the npm MCP server and removes obsolete container pins.

Changes:

  • Uses ast-grep-mcp@0.0.2 through npx.
  • Regenerates affected workflow locks without the vulnerable image.
  • Adds regression coverage for removed pin data.
Show a summary per file
File Description
.github/workflows/shared/mcp/ast-grep.md Configures the npm MCP server.
.github/workflows/mcp-inspector.lock.yml Regenerates inspector workflow.
.github/workflows/go-pattern-detector.lock.yml Regenerates detector workflow.
.github/aw/actions-lock.json Removes the stale container pin.
pkg/actionpins/data/action_pins.json Removes the embedded pin.
pkg/workflow/data/action_pins.json Removes duplicate workflow pin data.
pkg/actionpins/actionpins_internal_test.go Verifies the pin remains absent.

Review details

Tip

Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

  • Files reviewed: 7/7 changed files
  • Comments generated: 1
  • Review effort level: Balanced

container: "mcp/ast-grep"
version: "latest"
command: "npx"
args: ["ast-grep-mcp@0.0.2"]
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.86.2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[container-image-scan] Container findings for mcp/ast-grep:latest

3 participants