github / github/github-mcp-server

Add read-only regression coverage for dynamic toolsets and deprecated aliases

Open
#2,192 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
33k
Forks
5k
Avg merge
2d 1h
Merged PRs (30d)
52

Description

Read-only guarantees currently depend on implicit inventory behavior that is not regression-tested across dynamic toolset enablement and deprecated alias resolution.

Current behavior is insufficient because the server's read-only contract spans multiple capability surfaces (`DynamicTools`, inventory filtering, and deprecated alias lookup), but there is no focused test that proves mutating canonical tools and deprecated aliases stay unavailable when read-only mode is active.

Why now: `--read-only` is a core governance boundary for this server, so the contract should be locked in with explicit regression coverage before toolset and alias work drifts further.

Claim-to-codepath map:
- Dynamic toolset registration in `pkg/github/dynamic_tools.go`
- Deprecated alias mapping in `pkg/github/deprecated_tool_aliases.go`
- Server inventory assembly in `internal/ghmcp/server.go`
- Request-level filtering tests in `pkg/http/handler_test.go`

Requested behavior:
- Read-only mode should continue to exclude mutating tools when a toolset is enabled dynamically.
- Deprecated aliases for mutating tools should not re-expose write capability under read-only filtering.
- The invariant should be covered by targeted tests.

## Evidence Packet
- Commit under test: `1da41fa6947f`
- Runtime environment:
- OS: Darwin 25.3.0 arm64
- Go: go1.25.7
- golangci-lint: 2.8.0
- Minimal repro:
1. Build inventory/server state with read-only mode enabled.
2. Exercise dynamic toolset enablement and deprecated alias lookup.
3. Verify whether any mutating capability becomes available.
- Expected behavior: no mutating canonical tool or deprecated alias becomes callable in read-only mode.
- Actual behavior: the code path is not covered by a focused regression test today.

## Acceptance Criteria
- Add targeted tests proving read-only behavior holds for dynamic toolsets and deprecated aliases.
- Keep the change scoped to regression coverage unless a concrete behavior bug is found.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.