dependabot-alerts.mjs's openAlerts() has no error handling for a rate-limited or partially-failed GitHub API response
维护者通常 1 天内回复
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 74/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- github, javascript
调研方向
从 scripts/dependabot-alerts.mjs 中的 openAlerts() 开始,将其 gh api 调用与 isPermissionDenied() 以及现有处理方式进行比较。运行 scripts/dependabot-alerts.test.mjs,然后为受到速率限制的分页响应和部分失败的分页响应添加覆盖。完成的标准是:有意处理失败情况,不产生未处理的异常,并且负向路径测试通过。
由索引模型根据 Issue 内容生成。
描述
Which version line?
v2 — current (@modelcontextprotocol/inspector@latest)
Which client?
All / shared core
Inspector version
2.7.0 (git tag) — static code-review finding, not run locally
Node version
N/A — static code review, no live run performed
Operating system (and browser, for the web client)
N/A — static code review
Transport
Not applicable / never connected
MCP server under inspection
N/A — this is a static code-review finding against the 2.7.0 tag's scripts/dependabot-alerts.mjs, not a live reproduction against a running MCP server.
Steps to reproduce
Found via static review of the 2.7.0 tag source, not a live run.
- scripts/dependabot-alerts.mjs's isPermissionDenied() (~line 737) explicitly detects and handles rate-limiting for the "is Dependabot security-fixes enabled" check, and main() has a test covering "continues, reporting UNVERIFIED, when the token cannot read the setting."
- The actual alert-listing function, openAlerts() (~lines 797-805), calls
gh api --paginate --slurp repos/${repo}/dependabot/alerts?state=open&per_page=100with no try/catch or equivalent handling around that call, unlike the permission-check path. - A repo-wide read of the co-located scripts/dependabot-alerts.test.mjs finds tests for the permission-check rate-limit path but no negative-path test exercising openAlerts() itself against a rate-limited (403/429) or partially-failed (paginated request cut off mid-stream) GitHub API response.
No live run against the GitHub API was performed; this is based on reading the script and its test file against the 2.7.0 tag.
Expected behavior
openAlerts() handles a rate-limited (403/429) or partially-failed paginated response from the GitHub API the same deliberate way isPermissionDenied() already handles rate-limiting for the security-fixes-setting check — either surfacing a clear, non-crashing error/UNVERIFIED result, or retrying — rather than letting an unhandled exception propagate out of gh api.
Actual behavior
openAlerts() calls gh api --paginate --slurp repos/${repo}/dependabot/alerts?state=open&per_page=100 with no try/catch and no test covering what happens when that call is rate-limited or fails partway through a paginated response — in contrast to the permission-check path a few functions away, which explicitly detects and handles rate-limiting (isPermissionDenied(), covered by tests at lines 234-253 of the test file).
Suggested fix: wrap openAlerts()'s gh api call in the same kind of error handling as the permission-check path (detect rate-limit/partial-failure, surface a clear error or retry), and add a negative-path test for it alongside the existing rate-limit test for isPermissionDenied().
Logs, errors, or screenshots
No response
Already prototyped a fix?
No response
Before you submit
- I searched existing issues and this is not a duplicate.
- This is not a security vulnerability report (those go through the private advisory process).
- 主要语言
- TypeScript
- 星标
- 11k
- 派生
- 1.5k
- 平均合并
- 4 小时 40 分钟
- 30 天内合并 PR
- 139
环境准备
- 提供 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
modelcontextprotocol/inspector 的其他 Issue
-
bug v2
难度 2/5 1-3 小时 新手友好度 88/100
modelcontextprotocol/inspector#2656 ·
维护者通常 1 天内回复
-
bug v2
难度 2/5 1-3 小时 新手友好度 68/100
modelcontextprotocol/inspector#2647 ·
维护者通常 1 天内回复
-
bug v2
难度 2/5 1-3 小时 新手友好度 76/100
modelcontextprotocol/inspector#2646 ·
维护者通常 1 天内回复
-
bug v2
难度 2/5 1-3 小时 新手友好度 72/100
modelcontextprotocol/inspector#2645 ·
维护者通常 1 天内回复
-
chore v2
难度 2/5 1-3 小时 新手友好度 72/100
modelcontextprotocol/inspector#2644 ·
维护者通常 1 天内回复
查看 modelcontextprotocol/inspector 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 78/100
JoviDeCroock/pracht#432 ·
维护者通常 1 天内回复
-
approved check:passed streams:add
难度 1/5 1 小时以内 新手友好度 75/100
维护者通常 1 天内回复
-
Hardware attribute name "app Connection Support" has inconsistent casing可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭
难度 1/5 1 小时以内 新手友好度 88/100
walletbeat/walletbeat#1628 ·
维护者通常 1 天内回复
-
bug go
难度 2/5 1-3 小时 新手友好度 82/100
genkit-ai/genkit#6761 · 1 条评论 ·
维护者通常 2 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
NousResearch/hermes-agent#136483 ·
维护者通常 1 天内回复