Skip to content

Replace vulnerable mcp/context7 container with the hosted Context7 HTTP MCP server - #51727

Merged
pelikhan merged 5 commits into
mainfrom
copilot/container-image-scan-fix-issues
Aug 10, 2026
Merged

pelikhan merged 5 commits into
mainfrom
copilot/container-image-scan-fix-issues

Conversation

Copilot AI commented Aug 10, 2026 •

Copy link
Copy Markdown
Contributor

The daily container image scan flagged mcp/context7 with 88 CVEs (10 Critical, 78 High) and 23 license violations. It's a third-party Docker Hub image we don't build, so there's no patch we can apply — but Context7 publishes an official hosted MCP endpoint, which removes the image from our scanned surface entirely.

Changes

  • .github/workflows/shared/mcp/context7.md — switched from container: to type: http against https://mcp.context7.com/mcp, passing the existing CONTEXT7_API_KEY secret as an Authorization header instead of a container env var. Allowed tools (query-docs, resolve-library-id) are unchanged. Follows the same shape as shared/mcp/tavily.md.
  • .github/workflows/mcp-inspector.lock.yml — regenerated. mcp/context7 drops out of the manifest containers list and the docker pre-pull step; mcp.context7.com is picked up automatically into the firewall allow-list.
mcp-servers:
  context7:
    type: http
    url: "https://mcp.context7.com/mcp"
    headers:
      Authorization: "****** secrets.CONTEXT7_API_KEY }}"
    allowed:
      - query-docs
      - resolve-library-id

Notes for reviewers

  • mcp-inspector is the only workflow importing this file, so blast radius is limited to that workflow.
  • The stale mcp/context7 entry in action_pins.json / actions-lock.json is left in place — it's a pin cache, and scanning derives images from lock file manifests, so it's no longer scanned.
  • This trades a container-isolated server for a network call to a third party; the API key moves from container env to an outbound header. Worth an explicit ack if that's not an acceptable tradeoff for this server.

Generated by 👨‍🍳 PR Sous Chef · gpt54 · 7.58 AIC · ⌖ 8.09 AIC · ⊞ 8.5K · ◷
Comment /souschef to run again

…mage

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix vulnerabilities and license violations for mcp/context7 Replace vulnerable mcp/context7 container with the hosted Context7 HTTP MCP server Aug 10, 2026
Copilot AI requested a review from pelikhan August 10, 2026 07:56
@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot remove usage of context7 all together

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Aug 10, 2026

Copy link
Copy Markdown
Contributor Author

@copilot remove usage of context7 all together

Removed in e93d124. Deleted .github/workflows/shared/mcp/context7.md, dropped the import from mcp-inspector.md (replaced with an exclusion note matching the brave/markitdown/notion ones), and removed the mcp/context7 container pin from actions-lock.json plus both action_pins.json catalogs. Recompiled — no context7, CONTEXT7_API_KEY, or mcp.context7.com references remain in any lock file.

@pelikhan
pelikhan marked this pull request as ready for review August 10, 2026 10:24
Copilot AI balanced review requested due to automatic review settings August 10, 2026 10:24
@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot resolve the merge conflicts on this branch.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Aims to replace the vulnerable Context7 container, but currently removes Context7 entirely.

Changes:

  • Deletes the shared Context7 configuration and inspector import.
  • Regenerates the workflow without Context7.
  • Removes Context7 from pin caches.
Show a summary per file
File Description
.github/workflows/shared/mcp/context7.md Deletes the Context7 definition.
.github/workflows/mcp-inspector.md Removes the Context7 import.
.github/workflows/mcp-inspector.lock.yml Removes generated Context7 configuration.
pkg/workflow/data/action_pins.json Removes the Context7 image pin.
pkg/actionpins/data/action_pins.json Removes the Context7 image pin.
.github/aw/actions-lock.json Removes the Context7 image pin.

Review details

Tip

Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

  • Files reviewed: 6/6 changed files
  • Comments generated: 1
  • Review effort level: Balanced

# Note: brave.md excluded — docker.io/mcp/brave-search has Critical/High CVEs (see #48546)
# Note: markitdown.md excluded — docker.io/mcp/markitdown has Critical/High CVEs (see #49515)
- shared/mcp/context7.md
# Note: context7.md removed — docker.io/mcp/context7 has Critical/High CVEs (see #51715)
Copilot AI and others added 2 commits August 10, 2026 10:34
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Aug 10, 2026

Copy link
Copy Markdown
Contributor Author

@copilot resolve the merge conflicts on this branch.

Resolved in 06216e8 by merging origin/main and fixing all conflicts on this branch; then recompiled affected lock files in a4010fe to keep markdown/lock files in sync.

Copilot AI requested a review from pelikhan August 10, 2026 10:40
@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot Quick triage nudge for this PR.

Please refresh the branch if GitHub can update it cleanly, address the maintainer-facing feedback below, and run the pr-finisher skill before handing this back.

Open review context (newest first):

Branch refresh was requested.
Run: https://github.com/github/gh-aw/actions/runs/31380615330

Generated by 👨‍🍳 PR Sous Chef · gpt54 · 7.58 AIC · ⌖ 8.09 AIC · ⊞ 8.5K · ◷
Comment /souschef to run again

@pelikhan
pelikhan merged commit 558432c into main Aug 10, 2026
1 check failed
@pelikhan
pelikhan deleted the copilot/container-image-scan-fix-issues branch August 10, 2026 11:06
Copilot stopped work on behalf of gh-aw-bot due to an error August 10, 2026 11:06
Copilot AI requested a review from gh-aw-bot August 10, 2026 11:06
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.86.2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[container-image-scan] Container findings for mcp/context7

4 participants