Skip to content

[deep-report] Pin unpinned npm/uvx package versions in agentdb, ruflo, and fabric-rti MCP servers #65971

Description

@github-actions

Description

Three local MCP server configs reference packages without a fixed version: .github/workflows/shared/mcp/agentdb.md:11 (args: ["agentdb@alpha"], a moving pre-release channel, not a pinned version), .github/workflows/shared/mcp/ruflo.md:16 (args: ["-y", "ruflo@latest", ...], explicitly latest), and .github/workflows/shared/mcp/fabric-rti.md:4-6 (command: "uvx", args: ["microsoft-fabric-rti-mcp"] with no version qualifier at all). Each can silently pull a different package build on a future run with no diff in this repo to review. For comparison, ast-grep.md (ast-grep-mcp@0.0.2), sentry.md (@sentry/mcp-server@0.33.0), and graft.md (0.8.0) in the same directory are already pinned correctly.

Expected Impact

Reproducible, auditable MCP server builds; closes a supply-chain drift gap consistent with the sibling container-image pinning issue filed from the same report.

Suggested Agent

New Agent (small, mechanical config change) or any workflow-config-authoring agent.

Estimated Effort

Quick (< 1 hour)

Data Source

DeepReport Intelligence Briefing - 2026-10-05 (cycle 5), sourced from MCP Inspector Report #65925 recommendation 1. Live-verified against .github/workflows/shared/mcp/agentdb.md:11, ruflo.md:16, and fabric-rti.md:4-6.

Generated by 🔬 Deep Report · claude · agent · 277.3 AIC · ⌖ 7.91 AIC · ⊞ 7.1K · ◷

  • expires on Oct 7, 2026, 5:13 PM UTC-08:00

Activity

  1. github-actions commented on Oct 6, 2026

    @github-actions
    ContributorAuthor

    🍪 Issue Monster selected this for Copilot

    I've identified this issue as a good candidate for automated resolution and requested assignment to the Copilot coding agent.

    If assignment succeeds, the Copilot coding agent will analyze the issue and create a pull request with the fix.

    Om nom nom! 🍪

    🍪 Om nom nom by Issue Monster · pi · gpt54 · 13.7 AIC · ⌖ 8.12 AIC · ⊞ 12.8K · ◷

  2. github-actions commented on Oct 6, 2026

    @github-actions
    ContributorAuthor

    Caution

    agentic threat detected
    Threat detection flagged this output in warn mode. Manual review is REQUIRED before any follow-up automation.

    Details

    Potential security threats were detected in the agent output.

    Review the workflow run logs for details.

    🍪 Issue Monster selected this for Copilot

    I've identified this issue as a good candidate for automated resolution and requested assignment to the Copilot coding agent.

    If assignment succeeds, the Copilot coding agent will analyze the issue and create a pull request with the fix.

    Om nom nom! 🍪

    🍪 Om nom nom by Issue Monster · pi · gpt54 · 16.6 AIC · ⌖ 17.9 AIC · ⊞ 12.7K · ◷

  3. github-actions commented on Oct 8, 2026

    @github-actions
    ContributorAuthor

    This issue was automatically closed because it expired on 2026-10-08T01:13:03.771Z.

    Closed by Workflow

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions