Repository navigation
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
Hey Status: This PR is marked as a work-in-progress and references important security work to address 65+ Critical vulnerabilities in the Serena MCP server image (issue #52858). The diff correctly updates workflow lock files and regenerates container pin metadata. Before merge, complete these remaining items:
The changes look focused and well-scoped — all modifications relate to the single security remediation goal. Once the remaining tasks complete, this should be ready for maintainer review. If you'd like to continue this task, you can assign this prompt to your coding agent:
|
:latest with digest pinning for security refreshes
|
@copilot resolve the merge conflicts on this branch. |
There was a problem hiding this comment.
Pull request overview
Routes Serena MCP workflows through :latest while retaining deterministic digest pinning for refreshable security updates.
Changes:
- Updates the shared Serena image reference and pin catalogs.
- Regenerates affected workflow lockfiles with
latest@sha256:…. - Adds a patch changeset documenting the security-refresh behavior.
Show a summary per file
| File | Description |
|---|---|
.changeset/patch-serena-mcp-server-latest-tag.md |
Documents the patch. |
.github/aw/actions-lock.json |
Updates the Serena pin key. |
.github/workflows/shared/mcp/serena.md |
Uses the latest tag. |
.github/workflows/archie.lock.yml |
Propagates the pinned image. |
.github/workflows/daily-compiler-quality.lock.yml |
Propagates the pinned image. |
.github/workflows/daily-file-diet.lock.yml |
Propagates the pinned image. |
.github/workflows/daily-mcp-concurrency-analysis.lock.yml |
Propagates the pinned image. |
.github/workflows/daily-testify-uber-super-expert.lock.yml |
Propagates the pinned image. |
.github/workflows/glossary-maintainer.lock.yml |
Propagates the pinned image. |
.github/workflows/go-fan.lock.yml |
Propagates the pinned image. |
.github/workflows/linter-miner.lock.yml |
Propagates the pinned image. |
.github/workflows/mcp-inspector.lock.yml |
Propagates the pinned image. |
.github/workflows/purelock.lock.yml |
Propagates the pinned image. |
.github/workflows/semantic-function-refactor.lock.yml |
Propagates the pinned image. |
.github/workflows/sergo.lock.yml |
Propagates the pinned image. |
.github/workflows/smoke-copilot-aoai-apikey.lock.yml |
Propagates the pinned image. |
.github/workflows/smoke-copilot-arm.lock.yml |
Propagates the pinned image. |
.github/workflows/smoke-copilot.lock.yml |
Propagates the pinned image. |
.github/workflows/spec-librarian.lock.yml |
Propagates the pinned image. |
.github/workflows/terminal-stylist.lock.yml |
Propagates the pinned image. |
.github/workflows/typist.lock.yml |
Propagates the pinned image. |
pkg/actionpins/data/action_pins.json |
Updates embedded pin data. |
pkg/workflow/data/action_pins.json |
Updates workflow pin data. |
Review details
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
- Files reviewed: 30/30 changed files
- Comments generated: 0
- Review effort level: Balanced
ghcr.io/github/serena-mcp-server:sha-891c160was the highest-risk image in daily scan output, with large critical/high CVE volume and license violations, and required urgent burn-down prioritization. This change shifts Serena image resolution to a refreshable tag while preserving deterministic digest pinning in generated workflow artifacts.Shared Serena import update
ghcr.io/github/serena-mcp-server:latestin:.github/workflows/shared/mcp/serena.mdPin catalog alignment
.github/aw/actions-lock.jsonpkg/actionpins/data/action_pins.jsonpkg/workflow/data/action_pins.jsonGenerated lockfile propagation
latest@sha256:...instead ofsha-891c160@sha256:....Release note
.changeset/patch-serena-mcp-server-latest-tag.md