Commit Graph

750 Commits

Author SHA1 Message Date
Tommaso Moro b06d570f05 Delete mcp-apps-are-here.md
CodeQL / Analyze (go) (push) Has been cancelled
CodeQL / Analyze (actions) (push) Has been cancelled
Build and Test Go Project / build (macos-latest) (push) Has been cancelled
Build and Test Go Project / build (ubuntu-latest) (push) Has been cancelled
Build and Test Go Project / build (windows-latest) (push) Has been cancelled
2026-02-25 15:58:34 +00:00
Tommaso Moro b6a509dd52 Add mcp-apps-are-here.md 2026-02-25 15:23:48 +00:00
kaitlin-duolingo 91b35e0f77 Get check runs (#1953)
* Add support for get_check_runs

* Run generate-docs

* Address AI code review comment

* make descriptions less ambiguous for model

* lint and docs

* fix lint

---------

Co-authored-by: tommaso-moro <tommaso-moro@github.com>
Co-authored-by: Tommaso Moro <37270480+tommaso-moro@users.noreply.github.com>
2026-02-25 13:42:24 +00:00
Sam Morrow a32a757d70 Fix panic when fetching resources fails due to network error (#1506)
* fix panic due to defer reading body of failed request

---------

Co-authored-by: Adam Holt <omgitsads@github.com>
2026-02-25 12:51:06 +01:00
Matt Holloway 2b55513a9e Update MIME types for UI resources to include profile for MCP Apps (#2078)
* update MIME types for UI resources to include profile for MCP Apps

* make it a const
2026-02-24 16:38:13 +00:00
Matt Holloway a94f95b43f Enhance client support checks for MCP Apps UI rendering (#2051)
* enhance client support checks for MCP Apps UI rendering

* update dependencies and enhance MCP Apps UI support handling

* chore: regenerate license files

Auto-generated by license-check workflow

* retrigger CI

* update test

* introduce constants for client names and remove wrong ide name for mcp apps support

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-02-24 13:41:19 +00:00
Tommaso Moro c0ba3edcee use minimal types (#2066) 2026-02-24 13:07:45 +00:00
Tommaso Moro 3ffc06b71d reduce context for add_issue_comments using minimal types (#2063) 2026-02-24 11:20:19 +00:00
Atharva Patil 48a2a05651 Use configured --gh-host as oauth authorization server (#2046)
When configured with a `--gh-host` argument, construct the OAuth Authorization Server URL from this host, rather than defaulting to `https://github.com/login/oauth`

Co-authored-by: Adam Holt < 4619+omgitsads@users.noreply.github.com>
Co-authored-by: atharva1051 <53966412+atharva1051@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
2026-02-24 10:52:19 +01:00
C. Ross cdf84bcf6c Make Example MCP Name consistent (#2069) 2026-02-23 11:46:43 -05:00
Tommaso Moro ee3ab7b23e reduce context usage for get_pull_request_review_comments (#2062) 2026-02-23 14:32:44 +00:00
Tommaso Moro 713848b0eb add minimal types for get_files (#2059) 2026-02-23 13:49:05 +00:00
Sam Morrow 16ff74a0eb feat: move copilot tools to default copilot toolset (#2039)
* feat: move copilot tools to default copilot toolset

Move AssignCopilotToIssue and RequestCopilotReview from the issues and
pull_requests toolsets respectively into a new default-enabled copilot
toolset. This groups all copilot-related tools together and makes them
available by default.

- Set Default: true on ToolsetMetadataCopilot
- Remove copilot from RemoteOnlyToolsets()
- Update AllTools() grouping and tests
- Regenerate docs

Refs: github/copilot-mcp-core#1180

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* refactor: move copilot tools to dedicated copilot.go

Extract AssignCopilotToIssue, RequestCopilotReview, AssignCodingAgentPrompt,
and all supporting types/helpers from issues.go and pullrequests.go into
copilot.go and copilot_test.go.

This follows the existing convention where each domain (actions, dependabot,
discussions, gists, etc.) has its own file, and keeps the copilot toolset
implementation cohesive in one place.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-02-23 11:38:26 +01:00
dependabot[bot] d982175686 build(deps): bump ajv
Bumps the npm_and_yarn group with 1 update in the /ui directory: [ajv](https://github.com/ajv-validator/ajv).


Updates `ajv` from 8.17.1 to 8.18.0
- [Release notes](https://github.com/ajv-validator/ajv/releases)
- [Commits](https://github.com/ajv-validator/ajv/compare/v8.17.1...v8.18.0)

---
updated-dependencies:
- dependency-name: ajv
  dependency-version: 8.18.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-02-21 08:54:14 +01:00
dependabot[bot] dc41c650a3 build(deps): bump hono
Bumps the npm_and_yarn group with 1 update in the /ui directory: [hono](https://github.com/honojs/hono).


Updates `hono` from 4.11.7 to 4.12.0
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](https://github.com/honojs/hono/compare/v4.11.7...v4.12.0)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.12.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-02-21 07:48:46 +01:00
Matt Holloway dc3ee11f4c fix for -1 in tailLines (#2047)
CodeQL / Analyze (go) (push) Has been cancelled
CodeQL / Analyze (actions) (push) Has been cancelled
Docker / build (push) Has been cancelled
Build and Test Go Project / build (macos-latest) (push) Has been cancelled
Build and Test Go Project / build (ubuntu-latest) (push) Has been cancelled
Build and Test Go Project / build (windows-latest) (push) Has been cancelled
GoReleaser Release / release (push) Has been cancelled
MCP Server Diff / mcp-diff (push) Has been cancelled
Publish to MCP Registry / publish (push) Has been cancelled
v0.31.0
2026-02-19 15:17:52 +00:00
tommaso-moro c38802ac80 rename to --exclude-tools 2026-02-18 17:13:41 +01:00
tommaso-moro 9c8f96f6bf add header support in http entry point 2026-02-18 17:13:41 +01:00
tommaso-moro 0b76ca8fd2 add disallowed-tools flag to enable shuting off tools as part of server configuration 2026-02-18 17:13:41 +01:00
Sam Morrow 5e1c94b25c fix: pin Docker base images to SHA256 digests
Pin all three Dockerfile base images to their SHA256 digests to resolve
code scanning alerts for unpinned Docker images. Dependabot docker
ecosystem is already configured and will keep these digests up to date.

- node:20-alpine (alert #14)
- golang:1.25.7-alpine (alert #15)
- gcr.io/distroless/base-debian12 (proactive)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-02-18 17:06:01 +01:00
Adam Holt 08231a2aeb Add support for custom middleware in the correct order. (#2026)
* Add support for custom middleware in the correct order.

* Switch this up to be more clear on what it's doing
2026-02-18 14:43:59 +01:00
Tommaso Moro 851030c20b Reduce context usage for create_or_update_file tool (#2027)
* optimize context usage

* add assortions and check for nil response

* refactor
2026-02-18 10:26:19 +00:00
JoannaaKL eec84f73b5 Improve AI issue triage prompts to detect unfilled templates (#2030)
- Add explicit detection of unmodified template text and placeholders
- Add detection of meaningless/spam-like titles
- Add 'Invalid' assessment category for spam/test issues
- Add label recommendations (waiting-for-reply, invalid)
- Strengthen 'Missing Details' criteria with specific examples
- Add guidance to be specific about which sections need actual content

This addresses issues like #2029 where template text was not replaced
with actual information but was not flagged as missing details.
2026-02-18 11:20:27 +01:00
e-straight 67b8bf2ed2 Add ProjectV2 status update tools (list, get, create) (#1987)
* Add ProjectV2 status update tools (list, get, create)

Closes https://github.com/github/github-mcp-server/issues/1963

Add three new individual tools and wire them into the consolidated
project tools for managing GitHub ProjectV2 status updates:

- list_project_status_updates / projects_list: List status updates for
  a project with pagination, ordered by creation date descending
- get_project_status_update / projects_get: Fetch a single status
  update by node ID
- create_project_status_update / projects_write: Create a status update
  with optional body, status, start_date, and target_date

New GraphQL types and queries (statusUpdateNode, statusUpdatesUserQuery,
statusUpdatesOrgQuery, statusUpdateNodeQuery) support both user-owned
and org-owned projects. The CreateProjectV2StatusUpdateInput type is
defined locally since the shurcooL/githubv4 library does not include it.

Also includes quality improvements discovered during implementation:

- Extract resolveProjectNodeID helper to deduplicate ~70 lines of
  project ID resolution logic shared between addProjectItem and
  createProjectStatusUpdate
- Add client-side YYYY-MM-DD date format validation for start_date
  and target_date fields before sending to the API
- Fix brittle node type check in getProjectStatusUpdate that relied
  on stringifying a githubv4.ID and comparing to "<nil>"
- Refactor createProjectStatusUpdate to accept typed parameters
  instead of raw args map
- Add deprecated tool aliases for all three new individual tools
- Add ProjectResolveIDFailedError constant for consistent error
  reporting

Test coverage includes 21 subtests covering both user and org paths,
pagination, error handling, input validation, field verification, and
consolidated tool dispatch.

* Fix projects_get required params and harden status update tools

Loosen projects_get schema to only require "method", since
get_project_status_update only needs status_update_id and never uses
owner or project_number. Also use pointer types for optional
statusUpdateNode fields, add owner_type validation for list/create
status updates, clamp negative per_page values, and fix
resolveProjectNodeID to return "" instead of nil on error.

* Resolve conflicts

* Update doc

* Update aliases

* Dont update tool renaming docs

---------

Co-authored-by: e-straight <elijahstr@users.noreply.github.com>
Co-authored-by: JoannaaKL <joannaakl@github.com>
2026-02-18 10:14:40 +01:00
Tommaso Moro 543a1fa019 use minimal types for issue comments to optimize context usage (#2024) 2026-02-17 12:36:28 +00:00
Tommaso Moro dc7e789dc4 Optimize context usage for getting an issue using the issue_read tool (#2022)
* minimize context usage using minimal types for get issue comments

* preserver reactions field

* add back author association
2026-02-17 10:33:15 +00:00
Tommaso Moro f04c137bdd Reduce context usage for getting a Pull Request (#2017)
* introduce minimal pr type

* update to use time.RFC3339

* confine change to single PR
2026-02-17 09:37:59 +00:00
Adam Holt efe9d40b58 Token scopes context (#1997)
CodeQL / Analyze (go) (push) Has been cancelled
CodeQL / Analyze (actions) (push) Has been cancelled
Build and Test Go Project / build (macos-latest) (push) Has been cancelled
Build and Test Go Project / build (ubuntu-latest) (push) Has been cancelled
Build and Test Go Project / build (windows-latest) (push) Has been cancelled
* Move scope storage into its own context key, separately from token info.

This allows us to provide scopes seperately in the remote server, where
we have scopes before we do the auth.

* Skip token extraction if token info already exists in context.

This is to avoid redundant token extraction in remote setup where token info may have already been extracted earlier in the request lifecycle.

* Check for existing scopes in context before fetching from GitHub API in scope challenge middleware

* Return error type for unknown tools in inventory builder and handle it in HTTP handler
2026-02-16 14:10:28 +01:00
dependabot[bot] d44894eb6f build(deps): bump @modelcontextprotocol/sdk (#2007)
Bumps the npm_and_yarn group with 1 update in the /ui directory: [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk).


Updates `@modelcontextprotocol/sdk` from 1.25.3 to 1.26.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/v1.25.3...v1.26.0)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.26.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-12 14:48:42 +01:00
Matt Holloway e83440db58 Add initial PoC for MCP Apps for select tools under Insiders (#1957)
* PoC full flow (hello world example)

* add avatar resource domain

* add postmessage logic and richer UI

* add create issue ui

* update ui for issue creatioon

* fix

* ignore banner

* update docs after rebase

* update toolsnap for get_me

* new UI changes

* update docs

* update workflows that need ui build

* add UI diff

* fix build ui step for windows runners to use git bash

* fix UI diff

* refactor issue creation UI

* add AvatarWithFallback component and update UserCard to use it; enhance CreateIssueApp to manage existing issue data

* fix formatting of button labels

* add create pull request functionality with UI support and insiders

* update docs

* add test for insiders mode handling in ServerTool schema

* remove `show_ui` param for now

* make insiders mode metadata stripping generic

* remove ui diff

* fix CI

* remove redundant mention of old app name

* add node types to fix ide issues for ts code

* remove unused TriangleDownIcon import

* update @primer/behaviors and electron-to-chromium versions in package-lock.json

* add check to ensure base and head are not the same when creating a new PR

* remove old show_ui

* fix gitignore for dist so builds dont break

* add tests for insiders mode handling and metadata stripping in ServerTool

* remove unused state and components from CreatePRApp

* fix ui build

* update docker build to fix npm issue

* remove reference to show_ui

* allow insiders to work for non-ui features

* formalise insiders inventory support

* update docs

* fix overflow issues and replace pull request dropdown with matching UI from dotcom

* fix createpullrequest test

* consolidate fetching tools under `ui_get` tool to remove toolset deps

* fix issue data prefill in issue_write form

* fix link component when updating issue

* fix avatar URL

* fix broken issue update logic

* remove dbg

* fix for new GetFlags

* revert to original required fields for create_pull_request

* fix for UI form submission

* Simplify MCP App UIs for basic branch

Remove advanced features to be kept in mcp-ui-apps-advanced:
- Strip labels, assignees, milestones, issue types, repo picker from issue-write
- Strip repo picker, branch selectors from pr-write
- Delete ui_get tool (ui_tools.go, ui_tools_test.go, ui_get.snap)
- Remove UIGet registration from tools.go

Basic forms retain: title, body, submit with _ui_submitted,
draft/regular split button (PR), MarkdownEditor, and SuccessView.

* Fix header spacing in issue-write and pr-write UIs

Add proper spacing between icon, title text, and repo name in the
header bar for both issue-write and create-pull-request forms.

* fix UI spacing

* Add insiders flag to User-Agent header

When InsidersMode is enabled, append '(insiders)' to the User-Agent
string sent with GitHub API requests, enabling server-side adoption
tracking.

* address ui feedback

* added ui/no-ui support

* improve active state UI for write and preview button. make padding consistent in textarea

* return to prev non ui check

* use hardcoded client name check for ui support

* linter fixes

* merge fix

* linter fix 2

---------

Co-authored-by: tommaso-moro <tommaso-moro@github.com>
2026-02-12 13:03:00 +00:00
Ksenia Bobrova 09d38df96f Use Contents API instead of raw endpoint to fetch file content (#1998)
* Use Contents API instead of raw endpoint to fetch file content

* Address Copilot comment

* Fix linter errors
2026-02-12 13:43:41 +01:00
Oleksandr Redko 1b829dc736 Update .github/workflows/lint.yml
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2026-02-12 12:58:49 +01:00
Oleksandr Redko 505d5dc33a refactor: modernize code with modernize and intrange 2026-02-12 12:58:49 +01:00
JoannaaKL 266bd9311e Gogithub update (#2004)
* Bump google/go-github

* chore: regenerate license files

Auto-generated by license-check workflow

* Fix required block

* Go mod vendor and tidy again

* Remove unused fatih/color dependency to fix CI (#2005)

* Initial plan

* Remove unused github.com/fatih/color dependency

The fatih/color package was listed in go.mod but not actually imported
or used anywhere in the codebase. This caused the CI "go mod tidy -diff"
check to fail. Running go mod tidy removed:
- github.com/fatih/color v1.18.0
- github.com/mattn/go-colorable v0.1.13 (transitive)
- github.com/mattn/go-isatty v0.0.20 (transitive)

Fixes the failing ubuntu-latest workflow build.

Co-authored-by: JoannaaKL <67866556+JoannaaKL@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: JoannaaKL <67866556+JoannaaKL@users.noreply.github.com>

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
2026-02-12 11:04:54 +01:00
copilot-swe-agent[bot] bbc675abe9 Make schema cache an opinionated default for HTTP handlers
Co-authored-by: SamMorrowDrums <4811358+SamMorrowDrums@users.noreply.github.com>
2026-02-11 11:32:07 +01:00
copilot-swe-agent[bot] ed30a1dee8 Co-locate WithSchemaCache with other With functions
Co-authored-by: SamMorrowDrums <4811358+SamMorrowDrums@users.noreply.github.com>
2026-02-11 11:32:07 +01:00
copilot-swe-agent[bot] cd1b5a203a Fix lint CI: use Go 1.25 to match golangci-lint v2.5.0
Co-authored-by: SamMorrowDrums <4811358+SamMorrowDrums@users.noreply.github.com>
2026-02-11 11:32:07 +01:00
Sam Morrow ff00c689b0 Add shared SchemaCache for streamable-http server
Create a shared mcp.SchemaCache in RunHTTPServer and pass it through
to each per-request MCP Server via ServerOptions. This avoids repeated
JSON schema reflection and resolution when a new Server is created for
every request in stateless mode, matching the pattern used by the
remote server.
2026-02-11 11:32:07 +01:00
Matt Holloway bc02fd7354 fix test 2026-02-10 12:55:24 +01:00
Matt Holloway 858966005f fix ff hangover from old code 2026-02-10 12:55:24 +01:00
copilot-swe-agent[bot] 9a6f2ec549 Revert .gitignore changes
Co-authored-by: mattdholloway <918573+mattdholloway@users.noreply.github.com>
2026-02-10 12:55:24 +01:00
copilot-swe-agent[bot] bee1bdefe7 Fix: Remove test binary and update .gitignore to exclude *.test files
Co-authored-by: mattdholloway <918573+mattdholloway@users.noreply.github.com>
2026-02-10 12:55:24 +01:00
copilot-swe-agent[bot] fbbc238cf8 No code changes (final verification complete)
Co-authored-by: mattdholloway <918573+mattdholloway@users.noreply.github.com>
2026-02-10 12:55:24 +01:00
copilot-swe-agent[bot] 3c53687eb3 Remove old non-consolidated actions and Projects toolsets
This commit removes the old individual tool implementations for
Actions and Projects toolsets that have been superseded by consolidated
tools (actions_list, actions_get, actions_run_trigger, get_job_logs,
projects_list, projects_get, projects_write).

Removed old Actions tools:
- ListWorkflows, ListWorkflowRuns, RunWorkflow, GetWorkflowRun
- GetWorkflowRunLogs, ListWorkflowJobs, GetJobLogs
- RerunWorkflowRun, RerunFailedJobs, CancelWorkflowRun
- ListWorkflowRunArtifacts, DownloadWorkflowRunArtifact
- DeleteWorkflowRunLogs, GetWorkflowRunUsage

Removed old Projects tools:
- ListProjects, GetProject, ListProjectFields, GetProjectField
- ListProjectItems, GetProjectItem, AddProjectItem
- UpdateProjectItem, DeleteProjectItem

Also removed:
- Feature flag constants (FeatureFlagHoldbackConsolidatedActions/Projects)
- FeatureFlagDisable from consolidated tools
- Old toolsnaps for removed tools
- Tests for removed tools
- Unused helper function toNewProjectType

Co-authored-by: mattdholloway <918573+mattdholloway@users.noreply.github.com>
2026-02-10 12:55:24 +01:00
Oleksandr Redko ccfec3dcd4 build(deps): bump github.com/josephburnett/jd/v2 to v2.4.0 2026-02-10 11:01:16 +01:00
copilot-swe-agent[bot] ee74b47d91 Fix buildkit-cache-dance action to use cache-map instead of deprecated cache-source
Co-authored-by: SamMorrowDrums <4811358+SamMorrowDrums@users.noreply.github.com>
2026-02-09 22:43:02 +01:00
dependabot[bot] 30765decab build(deps): bump reproducible-containers/buildkit-cache-dance
Bumps [reproducible-containers/buildkit-cache-dance](https://github.com/reproducible-containers/buildkit-cache-dance) from 2.1.4 to 3.3.1.
- [Release notes](https://github.com/reproducible-containers/buildkit-cache-dance/releases)
- [Commits](https://github.com/reproducible-containers/buildkit-cache-dance/compare/4b2444fec0c0fb9dbf175a96c094720a692ef810...6f699a72a59e4252f05a7435430009b77e25fe06)

---
updated-dependencies:
- dependency-name: reproducible-containers/buildkit-cache-dance
  dependency-version: 3.3.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-02-09 22:43:02 +01:00
github-actions[bot] 0db2b51c0b chore: regenerate license files
Auto-generated by license-check workflow
2026-02-09 22:35:39 +01:00
dependabot[bot] 42d9d0755b build(deps): bump github.com/go-chi/chi/v5 from 5.2.3 to 5.2.5
Bumps [github.com/go-chi/chi/v5](https://github.com/go-chi/chi) from 5.2.3 to 5.2.5.
- [Release notes](https://github.com/go-chi/chi/releases)
- [Changelog](https://github.com/go-chi/chi/blob/master/CHANGELOG.md)
- [Commits](https://github.com/go-chi/chi/compare/v5.2.3...v5.2.5)

---
updated-dependencies:
- dependency-name: github.com/go-chi/chi/v5
  dependency-version: 5.2.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-02-09 22:35:39 +01:00
dependabot[bot] 50ad0c80d4 build(deps): bump golang from 1.25.6-alpine to 1.25.7-alpine
Bumps golang from 1.25.6-alpine to 1.25.7-alpine.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.25.7-alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-02-09 22:32:41 +01:00