Skip to content

feat(security): add typed security alert outputs - #3387

Open
SamMorrowDrums wants to merge 2 commits into
sammorrowdrums-typed-search-projected-outputsfrom
sammorrowdrums-typed-security-outputs
Open

SamMorrowDrums wants to merge 2 commits into
sammorrowdrums-typed-search-projected-outputsfrom
sammorrowdrums-typed-security-outputs

Conversation

@SamMorrowDrums

Copy link
Copy Markdown
Collaborator

Summary

Adds typed, protocol-gated structured outputs for security-domain read tools. Modern clients receive compact typed results while existing text responses remain unchanged for legacy and unknown-version clients.

Why

Completes the security-domain tools covered by the structured-output migration.
Fixes #3360

What changed

  • Migrates get_code_quality_finding; code scanning get/list; secret scanning get/list; Dependabot get/list; and global, repository, and organization security advisory get/list tools to typed input/output DTOs.
  • Adds modern/legacy wire and schema-conformance tests; preserves existing text payloads, input schemas, coercion, pagination, scopes, IFC labels, and error behavior.

MCP impact

  • No tool or API changes
  • Tool schema or behavior changed
    Modern clients now receive output schemas and structured results for these tools. Existing text results and tool input schemas are unchanged.
  • New tool added

Prompts tested (tool changes only)

  • No live GitHub prompts run; mocked MCP calls cover schema conformance, typed results, and legacy text-only behavior.

Security / limits

  • No security or limits impact
  • Auth / permissions considered
    Existing scopes and permission checks are unchanged.
  • Data exposure, filtering, or token/size limits considered
    Structured DTOs retain the scoped security details needed by callers; existing full text responses and IFC labels remain unchanged.

Tool renaming

  • I am renaming tools as part of this PR (e.g. in consolidation effort)
    • I have added the new tool aliases in deprecated_tool_aliases.go
  • I am not renaming tools as part of this PR

Note: if you're renaming tools, you must add the tool aliases. For more information on how to do so, please refer to the official docs.

Lint & tests

  • Linted locally with ./script/lint — passed with 0 issues.
  • Tested locally with ./script/test — passed (go test -race ./...).

Docs

  • Not needed — script/generate-docs ran and produced no documentation diff.
  • Updated (README / docs / examples)

@SamMorrowDrums
SamMorrowDrums added this pull request to stack #3385 October 2, 2026 11:20
@SamMorrowDrums
SamMorrowDrums force-pushed the sammorrowdrums-typed-security-outputs branch from 7ef5714 to 836f8a1 Compare October 2, 2026 20:50
@SamMorrowDrums
SamMorrowDrums requested a balanced review from Copilot October 3, 2026 04:26

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Typed input handling introduces compatibility regressions in omitted-state Dependabot calls and null CWE filters.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Extends the structured-output migration to security read tools, providing typed results for modern clients while retaining legacy text responses.

Changes:

  • Adds security input/output types and response projections.
  • Adds protocol-gating and schema-conformance tests.
  • Consolidates architecture-specific license listings.
File Description
third-party-licenses.windows.md Combines Windows architecture listings.
third-party-licenses.linux.md Combines Linux architecture listings.
pkg/​github/​typed_security_outputs_test.go Tests modern structured and legacy text responses.
pkg/​github/​security_outputs.go Defines security types, projections, and normalization helpers.
pkg/​github/​security_advisories.go Migrates advisory reads to typed outputs.
pkg/​github/​secret_scanning.go Migrates secret-scanning reads to typed outputs.
pkg/​github/​dependabot.go Adds typed Dependabot results and pagination.
pkg/​github/​code_scanning.go Migrates code-scanning reads to typed outputs.
pkg/​github/​code_quality.go Adds typed code-quality findings alongside raw text.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread pkg/github/dependabot.go Outdated
WithCursorPagination(schema)

return NewTool(
return NewTool[ListDependabotAlertsInput, DependabotAlertsOutput](
result = attachStaticIFCLabel(ctx, deps, result, ifc.LabelGlobalSecurityAdvisory())
return result, nil, nil
return result, mapSecurityOutputs(advisories, globalSecurityAdvisoryOutput), nil
},
SamMorrowDrums and others added 2 commits October 3, 2026 15:14
Add typed protocol-gated outputs for code quality, code and secret scanning, Dependabot, and security advisories while preserving existing text responses.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep advertised input defaults while disabling runtime default injection for security filters. Normalize null CWE filters, compact findings, and verify modern wire outputs alongside exact legacy formatting.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@SamMorrowDrums
SamMorrowDrums force-pushed the sammorrowdrums-typed-security-outputs branch from 836f8a1 to 8d8c285 Compare October 3, 2026 13:19
@SamMorrowDrums
SamMorrowDrums marked this pull request as ready for review October 3, 2026 13:41
@SamMorrowDrums
SamMorrowDrums requested a review from a team as a code owner October 3, 2026 13:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants