Add support for creating and updating repository security advisories
还没有人认领这个 Issue。
评估
调研方向
首先定位现有的 security_advisories 工具集及其只读工具,然后将它们的模式与链接的三个 GitHub REST API 操作进行比较。工具集支持创建草稿、更新和发布 advisories,以及通过文档化的端点请求 CVE IDs,即表示完成。
由索引模型根据 Issue 内容生成。
描述
Describe the feature or problem you'd like to solve
The current security_advisories toolset only supports reading advisories (list_repository_security_advisories, list_org_repository_security_advisories, get_global_security_advisory). There is no support for creating, updating, publishing, or requesting CVE IDs for advisories via MCP, forcing security teams to context-switch to the GitHub web UI or REST API for these operations.
Proposed solution
Add three new tools to the security_advisories toolset:
create_repository_security_advisory— create a new draft advisory (POST /repos/{owner}/{repo}/security-advisories)update_repository_security_advisory— update an existing advisory, including transitioning state topublished(PATCH /repos/{owner}/{repo}/security-advisories/{ghsa_id})request_cve_for_repository_security_advisory— request a CVE ID from GitHub for a draft advisory (POST /repos/{owner}/{repo}/security-advisories/{ghsa_id}/cve)
This would allow security teams to manage the full advisory lifecycle — from draft creation through CVE assignment and publication — entirely within the MCP toolset, without leaving their workflow.
Example prompts or workflows (for tools/toolsets only)
- Create a draft advisory: "Create a draft security advisory for a stored XSS vulnerability in our Core product affecting versions below 2.1.0, patched in 2.1.0."
- Update an existing draft: "Update advisory GHSA-xxxx-xxxx-xxxx to add the CVSS vector string and change the severity to high."
- Request a CVE ID: "Request a CVE ID from GitHub for advisory GHSA-xxxx-xxxx-xxxx."
- Publish an advisory: "Publish advisory GHSA-xxxx-xxxx-xxxx."
- End-to-end workflow: "Create a draft advisory for an OS command injection vulnerability in our product, request a CVE ID, and publish it once the CVE has been assigned."
Additional context
Relevant REST API documentation:
- [Create a repository security advisory](https://docs.github.com/en/rest/security-advisories/repository-advisories#create-a-repository-security-advisory)
- [Update a repository security advisory](https://docs.github.com/en/rest/security-advisories/repository-advisories#update-a-repository-security-advisory)
- [Request a CVE for a repository security advisory](https://docs.github.com/en/rest/security-advisories/repository-advisories#request-a-cve-for-a-repository-security-advisory)
- 主要语言
- Go
- 星标
- 33.1k
- 派生
- 5k
- 平均合并
- 2 天 3 小时
- 30 天内合并 PR
- 18
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
github/github-mcp-server 的其他 Issue
-
bug
难度 2/5 1-3 小时 新手友好度 84/100
github/github-mcp-server#3235 ·
-
enhancement
难度 1/5 1 小时以内 新手友好度 88/100
github/github-mcp-server#3042 · 2 条评论 ·
-
bug
难度 2/5 1-3 小时 新手友好度 72/100
github/github-mcp-server#3032 · 1 个 reaction ·
-
难度 2/5 1-3 小时 新手友好度 74/100
github/github-mcp-server#2803 · 1 条评论 ·
-
难度 2/5 1-3 小时 新手友好度 76/100
github/github-mcp-server#2740 ·
查看 github/github-mcp-server 的全部 Issue
相似的 Issue
-
难度 1/5 1 小时以内 新手友好度 90/100
-
enhancement
难度 2/5 1-3 小时 新手友好度 65/100
-
bug
难度 2/5 1-3 小时 新手友好度 75/100
-
难度 2/5 1-3 小时 新手友好度 75/100
-
难度 2/5 1-3 小时 新手友好度 75/100
santhosh-tekuri/jsonschema#276 ·