Skip to content

🤖 fix: restore the security baseline and CI compatibility - #92

Open
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/go_modules/github.com/modelcontextprotocol/go-sdk-1.4.1
Open

dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/go_modules/github.com/modelcontextprotocol/go-sdk-1.4.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 19, 2026

Copy link
Copy Markdown

Summary — scope explicitly reopened

The issue #100 scope decision expands this existing PR into a combined security-baseline and CI-compatibility repair. Integration is in progress; this PR is not review-ready or merge-ready. The current published head remains fc52a605 while integration is validated locally.

Keep the original MCP SDK 1.4.1 upgrade, focused transport/parser regressions, and missing-authentication limitations. Add the tested Go 1.26.8 / Coder 2.35.8 Security Support dependency graph, explicit Trivy 0.74.0 inputs at all five existing SHA-pinned action invocations, and a narrowly tested Codex-comment metadata/clean-security-verdict fix. No real finding may be ignored, and summary metadata is not approval.

Why this is one delivery unit

Merge-group runs force the full gates. Toolchain-only, scanner-only, or dependency-only prerequisites would remain red and cannot land independently. The work will use distinct logical commits inside PR #92, not a replacement PR or a red prerequisite stack. Part of #100; that issue must remain open until verification after an authorized landing.

Dependency size and rationale

The frozen graph changes 374 modules: 152 additions, 14 removals, and 208 version changes relative to fc52a605. It changes 2,320 files, with 305,522 additions and 210,083 deletions. Only go.mod and go.sum change outside vendor/ in that graph. This is substantial generated dependency churn, not a small upgrade. The full module inventory is retained for integration and review.

Coder 2.35.8 is the selected Security Support (N−2) channel, not an opportunistic latest-version bump. Explicit corrections include gRPC 1.83.2, x/crypto 0.55.0 and x/mod 0.40.0 plus required minimal-version-selection changes. No application compatibility fixes were needed in the experiment.

Evidence and remaining gates

The private graph-2 experiment passed requested local/native gates on tree e1a059e4988c6f00db898f6457abe04dd7a15871. Against frozen databases, main→graph-2 gated findings were govulncheck 55→0, Trivy filesystem 41→0, and image 60→0. Those Trivy runs used 0.65.0, not the newly selected 0.74.0. Six non-called govulncheck advisories remain outside its failing symbol-level gate. Scanner results are not deployment-exploitation or production-readiness claims.

The integrated candidate still needs complete local tests/build/vendor/lint/docs/actionlint, focused race and helper negative controls, verified native 0.74.0 installation, filesystem/image/Terraform-config scans, actual cluster E2E, hosted CI, and separately correlated normal/security/final reviews within the existing six-assessment lifetime budget. The PR E2E skip is not cluster proof. No review requests will be sent before known blockers are cleared and the candidate is stable.

Earlier MCP screenshots and terminal recording cover fc52a605 only; new integrated evidence will be labeled by exact head.

Boundaries

No authentication redesign, scan suppressions, weakened gates, branch-rule changes, publisher repair, GoReleaser command/tag/changelog changes, releases/images pushed, merge, enqueue, or auto-merge. Main-image publishing is not restored by this PR alone. PR #99 and the existing dependency PRs stay untouched and open. The human retains the merge step.


📋 Implementation Plan

PR 92: integrated security baseline and CI compatibility

Scope and delivery unit

Preserve the existing MCP SDK 1.4.1 changes, regression tests, and deployment-limit documentation. Adopt the tested issue #100 graph 2 plus the two demonstrated CI-compatibility fixes in the same existing PR. Full merge-group gates prevent independently landable red prerequisite slices. Use separate logical commits: dependency graph/toolchain documentation; Trivy installation pins; fail-closed Codex-comments recognition/tests. Keep issue #100 and dependency PRs #91/#93/#94/#95/#96 open. No publisher repair, GoReleaser command/tag/changelog changes, authentication redesign, releases/images pushed, merge/enqueue/auto-merge, or unrelated cleanup.

The graph changes 374 modules (152 additions, 14 removals, 208 version changes), 2,320 files, 305,522 additions and 210,083 deletions. This is substantial generated dependency churn, not a small source patch. Preserve the complete inventory and supported-channel rationale. Six non-called govulncheck advisories remain outside the symbol-level failing gate; do not describe them as fixed or deployment exploitation.

Acceptance and phase gates

  1. Verify active mandate, current PR head/reviews, clean checkout, scope-decision receipt and frozen experiment manifest/patch hashes. Update public scope before publishing code. Gate: full live API audit, no overwritten co-driven work or review-counter reset.
  2. Apply only the hash-verified graph 2 patch onto fc52a60 using a dry run and base guard. Gate: staged tree exactly e1a059e4988c6f00db898f6457abe04dd7a15871, only go.mod/go.sum outside vendor, before any authored follow-up. Preserve patch/module inventories; update only toolchain statements directly made stale by Go 1.26.8.
  3. Keep the current Trivy action SHA and explicitly pin 0.74.0 at all five invocations. Gate: independently verified official release asset/checksum and successful native nested-installer execution in an owned clean environment; all existing severities, ignores, scan settings and failing exit thresholds unchanged. Prove 0.74 filesystem/image/Terraform-config scans on the integrated candidate; 0.65 experiment results are not a substitute.
  4. Reproduce the helper failure offline, then recognize only fully anchored actual summary metadata shape and the exact clean security verdict. Gate: whole-script tests cover running/completed metadata, normal/security clean replies, real findings, quoted/unanchored/ malformed/lookalike markers, marker followed by finding, unresolved/resolved threads, frozen PR 🤖 ci: repair main-channel GoReleaser preparation #99 payload and API failures. Metadata remains absence-of-findings only, never review approval. Wire the suite into canonical local and hosted gates without weakening existing filters.
  5. Validate the complete integrated source with make test/build/verify-vendor/lint/docs-check, actionlint, focused race and helper negative controls. Gate: exact source/tool/command/native-exit receipts, explicit frozen-db govulncheck plus current CI scanner semantics, owned 0.74 fs/image/config scans and unchanged generated API output. Commit cohesive logical changes only after their local gates; revalidate final commit.
  6. Dogfood and run full deployment checks on an owned Kind environment, including CNPG/template behavior, plus Terraform fmt/init-with-backend-disabled/validate/tflint/config scan. Gate: actual cluster steps, not the PR E2E skip; screenshots and video, native exits, image/source identities and cleanup. Publish the stable head and require real hosted installs/scans/required checks. Actual merge-group execution remains contingent on the human queue step; never synthesize or bypass that authority.
  7. Coordinate exact stabilized tree/scanner pins with issue 🤖 ci: diagnose and restore verified main image publishing #98 owner for private non-publishing Go 1.26.8 packaging. Reconcile automatic assessments before any explicit review. Gate: separately correlated normal/security Codex verdicts and a fresh independent final assessment, at most six lifetime assessments including pending reservations, required current-head checks, and resolved findings. Bound failed review requests to one retry per type/candidate. Report substantial new blockers to the desk before adding mechanism.

Hands-on dogfood

Use private terminal and Kind resources with explicit ownership receipts. Exercise MCP hostile-input/legitimate-client tests and real cluster CNPG/template operations from the exact candidate. Record actual commands with screenshots and video; label any accelerated terminal playback. Inspect semantic frames, upload with compatible gh --attach, and checksum-verify published assets. Retain exact source/scanner/database/native exits. Do not expose credentials or use production/shared clusters, mutable shared tags, or broad cleanup.

Evidence and cancellation

Write only under delivery/pr92/integration for new evidence. Previously finalized PR #92/issue #100 packets are read-only inputs. Read status.json before each resume/wake/external mutation and stop if inactive. Keep the existing review ledger without resetting counts. Preserve co-driven commits with fresh ref/body guards and normal pushes; do not rewrite publisher PR #99. Keep the workspace for human-landing verification. Completion means ready with evidence or a specific blocker, not merely an updated PR.


Generated with xum • Model: coder:openai/gpt-6-astra • Thinking: xhigh

Bumps [github.com/modelcontextprotocol/go-sdk](https://github.com/modelcontextprotocol/go-sdk) from 1.3.0 to 1.4.1.
- [Release notes](https://github.com/modelcontextprotocol/go-sdk/releases)
- [Commits](modelcontextprotocol/go-sdk@v1.3.0...v1.4.1)

---
updated-dependencies:
- dependency-name: github.com/modelcontextprotocol/go-sdk
  dependency-version: 1.4.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Mar 19, 2026
Exercise the production transport defaults with fake Kubernetes clients and loopback-only HTTP. Cover hostile Host/origin/content-type inputs, parser key aliases, legitimate SDK calls, and service-host limitations. Document that transport checks are not authentication.

PR #92 remains scoped to SDK 1.4.1.

Signed-off-by: Thomas Kosiewski <tk@coder.com>

---
_Generated with [`xum`](https://github.com/coder/xum) • Model: `coder:openai/gpt-6-astra` • Thinking: `xhigh`_

Change-Id: I03f9419542b9813951e9d7fe06ee2501ca8b0d75
@ThomasK33 ThomasK33 changed the title chore(deps): bump github.com/modelcontextprotocol/go-sdk from 1.3.0 to 1.4.1 🤖 fix: harden MCP HTTP transport with SDK 1.4.1 Sep 18, 2026
@ThomasK33

ThomasK33 commented Sep 18, 2026

Copy link
Copy Markdown
Member

🤖 Exact-head MCP security dogfood

Source: fc52a605d202286b59794449e34c9dc8738186d9. Go 1.25.7; agent-tty 0.5.0 / Node 24.21.0. All four recorded commands returned native test exit 0.

These are actual test-binary executions with fake Kubernetes clients and loopback-only HTTP. The Pod-side local address is modeled. No live cluster, actual port-forward, or browser exploit was exercised. Every rejected/ignored payload must produce zero workspace-tool reads and no state change; a valid follow-up must still work. The service-address examples explicitly show that transport protections are not authentication.

The video is an accelerated render of the recorded terminal session, with idle gaps compressed (6.6 seconds). It is not a fresh run during playback. Source, binary hash, command, native-exit and raw terminal receipts are retained privately. Screenshots provide readable views of each step.

1. Loopback Host rejection and legitimate local clients

Loopback Host rejection and legitimate local clients

2. Cross-site and content-type rejections without tool effects

Cross-site and content-type rejections without tool effects

3. Case/null-key isolation and a working SDK client

Case/null-key isolation and a working SDK client

4. Service-host model and the remaining unauthenticated access

Service-host model and the remaining unauthenticated access

Accelerated terminal recording:

dogfood.webm

Readiness remains blocked by vulnerability gates. No code/security review was requested.


Generated with xum • Model: coder:openai/gpt-6-astra • Thinking: xhigh

@ThomasK33 ThomasK33 changed the title 🤖 fix: harden MCP HTTP transport with SDK 1.4.1 🤖 fix: restore the security baseline and CI compatibility Sep 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant