Skip to content

Route Serena MCP workflows through :latest with digest pinning for security refreshes - #52935

Closed
pelikhan with Copilot wants to merge 2 commits into
mainfrom
copilot/container-image-scan
Closed

pelikhan with Copilot wants to merge 2 commits into
mainfrom
copilot/container-image-scan

Conversation

Copilot AI commented Aug 15, 2026 •

Copy link
Copy Markdown
Contributor

ghcr.io/github/serena-mcp-server:sha-891c160 was the highest-risk image in daily scan output, with large critical/high CVE volume and license violations, and required urgent burn-down prioritization. This change shifts Serena image resolution to a refreshable tag while preserving deterministic digest pinning in generated workflow artifacts.

  • Shared Serena import update

    • Switched the shared MCP component from a commit-style tag to ghcr.io/github/serena-mcp-server:latest in:
      • .github/workflows/shared/mcp/serena.md
  • Pin catalog alignment

    • Updated Serena container key/reference in action pin data so compiled workflows still emit pinned digest form:
      • .github/aw/actions-lock.json
      • pkg/actionpins/data/action_pins.json
      • pkg/workflow/data/action_pins.json
  • Generated lockfile propagation

    • Recompiled affected workflow lockfiles so all Serena consumers now reference latest@sha256:... instead of sha-891c160@sha256:....
  • Release note

    • Added a patch changeset describing the security-remediation intent and daily pin-refresh behavior:
      • .changeset/patch-serena-mcp-server-latest-tag.md
# before
container: "ghcr.io/github/serena-mcp-server:sha-891c160"

# after
container: "ghcr.io/github/serena-mcp-server:latest"
# compiled lockfiles still resolve to:
# ghcr.io/github/serena-mcp-server:latest@sha256:...

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

Hey @github/Copilot 👋 — thanks for working on this critical container image security remediation! Here's what I see:

Status: This PR is marked as a work-in-progress and references important security work to address 65+ Critical vulnerabilities in the Serena MCP server image (issue #52858). The diff correctly updates workflow lock files and regenerates container pin metadata.

Before merge, complete these remaining items:

  • Finish the checklist — the PR body shows several unchecked tasks:
    • Update Serena MCP shared workflow container reference (currently showing as incomplete)
    • Run targeted validation for workflow compilation and impacted tests
    • Run final required checks, secret scan, code review, and CodeQL
  • Add test coverage — this remediation affects multiple workflows (18+ .lock.yml files). Ensure the targeted validation tests pass before marking ready for review.
  • Mark as ready — once all checklist items are complete, remove the [WIP] prefix and unmark as draft.

The changes look focused and well-scoped — all modifications relate to the single security remediation goal. Once the remaining tasks complete, this should be ready for maintainer review.

If you'd like to continue this task, you can assign this prompt to your coding agent:

Complete the container image security remediation PR #52935:
1. Verify all tasks in the PR checklist are complete
2. Run workflow compilation validation for the updated lock files
3. Run any impacted tests to ensure no regressions
4. Perform final secret scan and CodeQL checks
5. Remove [WIP] from title and unmark as draft once all checks pass

Generated by ✅ Contribution Check · auto · 48.9 AIC · ⌖ 3.27 AIC · ⊞ 9.1K · ◷

Copilot AI changed the title [WIP] Fix critical vulnerabilities in container image Route Serena MCP workflows through :latest with digest pinning for security refreshes Aug 15, 2026
Copilot AI requested a review from pelikhan August 15, 2026 17:05
@pelikhan
pelikhan marked this pull request as ready for review August 15, 2026 17:51
Copilot AI balanced review requested due to automatic review settings August 15, 2026 17:51
@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot resolve the merge conflicts on this branch.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Routes Serena MCP workflows through :latest while retaining deterministic digest pinning for refreshable security updates.

Changes:

  • Updates the shared Serena image reference and pin catalogs.
  • Regenerates affected workflow lockfiles with latest@sha256:….
  • Adds a patch changeset documenting the security-refresh behavior.
Show a summary per file
File Description
.changeset/patch-serena-mcp-server-latest-tag.md Documents the patch.
.github/aw/actions-lock.json Updates the Serena pin key.
.github/workflows/shared/mcp/serena.md Uses the latest tag.
.github/workflows/archie.lock.yml Propagates the pinned image.
.github/workflows/daily-compiler-quality.lock.yml Propagates the pinned image.
.github/workflows/daily-file-diet.lock.yml Propagates the pinned image.
.github/workflows/daily-mcp-concurrency-analysis.lock.yml Propagates the pinned image.
.github/workflows/daily-testify-uber-super-expert.lock.yml Propagates the pinned image.
.github/workflows/glossary-maintainer.lock.yml Propagates the pinned image.
.github/workflows/go-fan.lock.yml Propagates the pinned image.
.github/workflows/linter-miner.lock.yml Propagates the pinned image.
.github/workflows/mcp-inspector.lock.yml Propagates the pinned image.
.github/workflows/purelock.lock.yml Propagates the pinned image.
.github/workflows/semantic-function-refactor.lock.yml Propagates the pinned image.
.github/workflows/sergo.lock.yml Propagates the pinned image.
.github/workflows/smoke-copilot-aoai-apikey.lock.yml Propagates the pinned image.
.github/workflows/smoke-copilot-arm.lock.yml Propagates the pinned image.
.github/workflows/smoke-copilot.lock.yml Propagates the pinned image.
.github/workflows/spec-librarian.lock.yml Propagates the pinned image.
.github/workflows/terminal-stylist.lock.yml Propagates the pinned image.
.github/workflows/typist.lock.yml Propagates the pinned image.
pkg/actionpins/data/action_pins.json Updates embedded pin data.
pkg/workflow/data/action_pins.json Updates workflow pin data.

Review details

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

  • Files reviewed: 30/30 changed files
  • Comments generated: 0
  • Review effort level: Balanced

@github-actions
github-actions Bot deleted the copilot/container-image-scan branch August 23, 2026 02:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[container-image-scan] Container findings for ghcr.io/github/serena-mcp-server

3 participants