Skip to content

pilot(mcp): enable GitHub MCP secret-scanning for .github-private reviews (#681) - #757

Merged
don-petry merged 13 commits into
mainfrom
claude/mcp-pilot-github-secret-scanning
Jun 17, 2026
Merged

don-petry merged 13 commits into
mainfrom
claude/mcp-pilot-github-secret-scanning

Conversation

@don-petry

@don-petry don-petry commented Jun 15, 2026 •

Copy link
Copy Markdown
Collaborator

What

Activates the opt-in MCP review knob (epic #676) on this repo as the #681 pilot, using GitHub MCP secret-scanning (the security-first starter from the #650 weekly update). Adds .github/review-mcp.json — the conventional path engine.sh auto-discovers (#679) — pointing at GitHub's hosted MCP server, read-only secret_protection toolset.

{ "mcpServers": { "github": { "type": "http",
  "url": "https://api.githubcopilot.com/mcp/x/secret_protection/readonly",
  "headers": { "Authorization": "Bearer ${GH_TOKEN}" } } } }
  • No secret committed — ${GH_TOKEN} is expanded at review time from the review job's existing token (the DON_PETRY_BOT_GH_PAT_CLASSIC PAT set at pr-review.yml job level — not the Actions GITHUB_TOKEN).
  • Read-only toolset — secret_protection/readonly; reads secret-scanning signal, never writes.
  • Safe by design ([Phase 1] Graceful degradation: warn (never fake) when an MCP server is unavailable #678): if the server fails to launch or the token scope is short, the engine emits a ::warning::[mcp] … and the review continues normally — it cannot break the pipeline.
  • Also fixes the test_engine_mcp.bats "MCP off by default" assertion (which expected this file to be absent) and wires the config path into the dev-lead test triggers.

⚠️ Activation checklist — MANUAL steps (this PR alone does NOT turn MCP on)

All three must be in place; order doesn't matter.

  1. ✅ Set the tools knob (repo variable) so the model may invoke the server's tools:

    gh variable set REVIEW_MCP_ALLOWED_TOOLS --body 'mcp__github__*' --repo petry-projects/.github-private
  2. ❌ Promote the review channel — REQUIRED, MANUAL. Reviews run pr-review.yml@pr-review/stable (pinned via agent_ref: pr-review/stable), so pr-review/stable must point at a commit that has the MCP engine ([Phase 1] Thread an optional MCP config into the Claude agentic review tiers (engine.sh) #677–[Phase 2] Document recommended MCP servers per tech stack #680).

    ⚠️ PREREQUISITE — fetch latest main first. cut-release.sh defaults to --ref origin/main; if your local origin/main is stale it will tag an old commit and stable lands on a pre-MCP engine (this is exactly what happened on the first attempt — v1.6.0/stable got pinned to 6feb0fe, which predates MCP).

    git fetch origin main
    bash scripts/cut-release.sh pr-review <next-free-version> --ref origin/main --channel stable --push
    • Use the next unused version — v1.6.0 is already burned on the wrong commit, so use 1.6.1 (or higher). Immutable vX.Y.Z tags are never overwritten.
    • Requires tag-push permission on the protected pr-review/* namespace; CI/automation cannot push it.
    • Verify after: git show pr-review/stable:scripts/engine.sh | grep -q REVIEW_MCP_CONFIG && echo OK should print OK.
  3. ⏳ Merge this PR (CODEOWNER approval / admin).

  4. Token scope — only if needed. The bot PAT already carries repo (validated by pr-review.yml), so secret-scanning read should work. If the first MCP review emits ::warning::[mcp] …, grant donpetry-bot repo-Admin / org security-manager access + confirm the PAT's repo scope, then re-promote.

Measurement (the #681 deliverable)

  • MCP-OFF baseline (captured): review-workflow reliability green (daily-pr-review-health.yml); latency ~20–30s/PR; reviews currently use training-data + repo-local tools only.
  • After activation: pr_review_health.sh (wider LOOKBACK_DAYS) for the latency/reliability delta + watch reviews for MCP-sourced secret findings → pilot note + go/no-go.

Scope / safety

Pilot only — broader rollout is a separate, explicit human decision (#681). Target is .github-private itself (ring-0 self-host); graceful degradation bounds the blast radius.

Refs: epic #676, story #681, docs/initiatives/mcp-powered-review.md.


Generated by Claude Code

…iews (#681)

Activates the opt-in MCP review knob (epic #676) on this repo as the #681
pilot: commits .github/review-mcp.json — the conventional path engine.sh
auto-discovers — configuring GitHub's hosted MCP server (read-only
secret_protection toolset). Auth uses the review job's existing GH_TOKEN
via env expansion; no token is committed.

Graceful degradation (#678) means a launch/auth failure is a ::warning:: +
normal review, never a broken pipeline. Inert until REVIEW_MCP_ALLOWED_TOOLS
is set and this lands on the running pr-review channel — see PR body.

https://claude.ai/code/session_015VRMMWmqW9nW81jygmea3e
@don-petry
don-petry requested a review from a team as a code owner June 15, 2026 11:29
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Jun 15, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

A new .github/review-mcp.json file is added, defining an MCP server configuration named github that uses HTTP transport pointed at the GitHub Copilot MCP endpoint with an Authorization header referencing GH_TOKEN.

Changes

MCP Server Configuration

Layer / File(s) Summary
GitHub MCP server config
.github/review-mcp.json
New JSON config defining mcpServers.github with HTTP transport, the Copilot MCP endpoint URL, and a Bearer ${GH_TOKEN} authorization header.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related issues

Possibly related PRs

  • petry-projects/.github-private#713: That PR modifies scripts/engine.sh to conditionally read REVIEW_MCP_CONFIG and pass MCP flags to Claude review tiers, which directly consumes the config file introduced here.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and specifically describes the main change: enabling a GitHub MCP pilot for secret-scanning in .github-private reviews with the configuration file addition.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/mcp-pilot-github-secret-scanning

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a new configuration file .github/review-mcp.json to set up an MCP server for GitHub with bearer token authorization. There are no review comments provided, and I have no feedback to offer on these changes.

@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — waiting on PR blockers (intent: review-changes)

PR: #757
No changes were committed, but the PR still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews). The retry cron will re-attempt automatically. Next attempt after: 2026-06-15T12:07:39Z

@don-petry

Copy link
Copy Markdown
Collaborator Author

Note

@don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically.
Next attempt after: 2026-06-15T12:07:39Z

@don-petry
don-petry enabled auto-merge (squash) June 15, 2026 11:37
@don-petry
don-petry disabled auto-merge June 15, 2026 11:46
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — review-changes (no-changes)

No changes were needed for this PR.

@don-petry
don-petry enabled auto-merge (squash) June 15, 2026 11:47
@don-petry
don-petry disabled auto-merge June 15, 2026 12:04
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
Issues addressed: 0
- Quality Gate Passed: No actionable issues found (0 new issues, 0 hotspots)
Files changed: None required
Skipped (informational): 0
```
No changes are required. The PR is clean per the quality gate, all CI checks are either passing or still in progress, and no reviewers have requested changes.

@don-petry
don-petry enabled auto-merge (squash) June 15, 2026 12:04
@don-petry
don-petry disabled auto-merge June 15, 2026 12:25
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — review-changes (no-changes)

No changes were needed for this PR.

@don-petry
don-petry enabled auto-merge (squash) June 15, 2026 12:28
@don-petry
don-petry disabled auto-merge June 15, 2026 12:45
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — review-changes (no-changes)

No changes were needed for this PR.

@don-petry
don-petry enabled auto-merge (squash) June 15, 2026 12:46
@don-petry
don-petry disabled auto-merge June 15, 2026 12:59
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
Issues addressed: 0
- Quality gate: PASSED (0 new issues, 0 security hotspots)
Files changed: .github/review-mcp.json (config only, no security issues detected)
Tier 1 blockers: None
Next steps: Await completion of in-progress CI checks (Lint, ShellCheck, Secret scan)
```
**No changes required.** The PR is in good standing — the SonarCloud quality gate has passed with no issues, there are no security hotspots in the configuration file, and no blockers from CI or code reviewers. The remaining in-progress checks will validate the changes automatically.

@don-petry
don-petry enabled auto-merge (squash) June 16, 2026 21:21
@don-petry
don-petry disabled auto-merge June 16, 2026 21:28
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — waiting on PR blockers (intent: review-changes)

PR: #757
No changes were committed, but the PR still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews). The retry cron will re-attempt automatically. Next attempt after: 2026-06-16T22:01:03Z

@don-petry

Copy link
Copy Markdown
Collaborator Author

Note

@don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically.
Next attempt after: 2026-06-16T22:01:03Z

@don-petry
don-petry enabled auto-merge (squash) June 16, 2026 21:31
@don-petry
don-petry disabled auto-merge June 16, 2026 23:47
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — review-changes (applied)

Changes committed and pushed.

@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — waiting on PR blockers (intent: review-changes)

PR: #757
No changes were committed, but the PR still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews). The retry cron will re-attempt automatically. Next attempt after: 2026-06-17T00:24:19Z

@don-petry

Copy link
Copy Markdown
Collaborator Author

Note

@don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically.
Next attempt after: 2026-06-17T00:24:19Z

@don-petry
don-petry enabled auto-merge (squash) June 16, 2026 23:54
@sonarqubecloud

Copy link
Copy Markdown

@don-petry
don-petry disabled auto-merge June 17, 2026 00:00
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — review-changes (no-changes)

No changes were needed for this PR.

@don-petry
don-petry enabled auto-merge (squash) June 17, 2026 00:01
@don-petry

Copy link
Copy Markdown
Collaborator Author

Manual step performed (variable set). Human approves.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-human-review Flagged by automated PR review agent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants