Skip to content

Report Grype findings on pull requests - #1092

Open
danbarr wants to merge 1 commit into
mainfrom
report-grype-findings
Open

danbarr wants to merge 1 commit into
mainfrom
report-grype-findings

Conversation

@danbarr

@danbarr danbarr commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Publish detailed Grype JSON artifacts before the vulnerability gate fails.
  • Report fixable High and Critical package findings in the failed build job.
  • Maintain a sticky PR comment with affected packages and available fixed versions.

Validation

  • git diff --check
  • Embedded GitHub Script syntax check
  • actionlint: existing findings remain for concurrency.queue and pre-existing shellcheck warnings.

Signed-off-by: Dan Barr <6922515+danbarr@users.noreply.github.com>
@toolhive-release-app

Copy link
Copy Markdown
Contributor

🔒 MCP Security Scan Results

✅ adb-mysql-mcp-server

  • Status: Passed
  • Tools scanned: 3
  • Result: No security issues detected

✅ agentql-mcp

  • Status: Passed
  • Tools scanned: 1
  • Result: No security issues detected

Summary: Scanned 2 MCP server(s), all passed security checks. ✅

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant