Disable vulnerable arXiv MCP container - #51758
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
@copilot resolve the merge conflicts on this branch. |
There was a problem hiding this comment.
Pull request overview
Disables the vulnerable arXiv MCP integration and removes its pinned container artifacts.
Changes:
- Removes arXiv MCP imports from Scout and MCP Inspector.
- Replaces the server definition with a security notice.
- Removes the image digest from manifests and regenerated locks.
Show a summary per file
| File | Description |
|---|---|
.github/aw/actions-lock.json |
Removes the vulnerable image pin. |
.github/workflows/mcp-inspector.lock.yml |
Regenerates Inspector without arXiv. |
.github/workflows/mcp-inspector.md |
Excludes the arXiv integration. |
.github/workflows/scout.lock.yml |
Regenerates Scout without arXiv. |
.github/workflows/scout.md |
Excludes the arXiv integration. |
.github/workflows/shared/mcp/arxiv.md |
Disables the server definition. |
pkg/actionpins/data/action_pins.json |
Removes the embedded image pin. |
pkg/workflow/data/action_pins.json |
Removes the workflow image pin. |
Review details
Tip
Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
- Files reviewed: 8/8 changed files
- Comments generated: 0
- Review effort level: Balanced
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Resolved. I merged |
|
@copilot PR sous-chef triage: this branch is conflicting. Please run No failed checks were listed in the compact candidate snapshot.
|
Ran |
Triage: Disable vulnerable arXiv MCP container
|
|
@copilot PR sous-chef triage: please refresh the current maintainer-facing state on the latest head and run the No failed checks were listed in the compact candidate snapshot.
|
Refreshed on latest head
Actions taken: maintainer-facing triage refresh only; no file changes were needed (head remains |
|
🎉 This pull request is included in a new release. Release: |
The pinned
mcp/arxiv-mcp-serverimage contains 131 Critical/High vulnerabilities and extensive license-policy violations.Disable the integration
Remove vulnerable artifacts