Use GitHub-signed commits for repository file write tools

未关闭
#2,771 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
68/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
冷清
技术栈
go, graphql
领域
api, backend

调研方向

从 create_or_update_file 和 push_files 的实现开始,然后将它们与现有的 delete_file 路径及其对 GitHub APIs 的使用进行比较。调查 GraphQL createCommitOnBranch,并保留现有的工具输入和响应结构。完成的标准是:在支持的情况下,写入操作会生成经 GitHub 验证的提交,并且 pull requests 满足签名提交要求。

由索引模型根据 Issue 内容生成。

描述

Summary

Repository write tools such as create_or_update_file and push_files can create unsigned commits. In repositories that require verified commit signatures, the MCP-created pull request is then blocked with:

Commits must have verified signatures.

Reproduction

  1. Use the MCP server against a repository with a ruleset/branch protection rule requiring signed commits.
  2. Create a branch.
  3. Use create_or_update_file or push_files to write a commit.
  4. Open a pull request.

Actual behavior

The commit can be reported by GitHub as verification.verified=false with verification.reason=unsigned, and the pull request cannot be merged while the signed-commit rule is active.

Expected behavior

Repository write tools should use a GitHub API path that can produce GitHub-verified commits when supported by the authenticated actor, so MCP-generated pull requests can satisfy signed-commit requirements without clients managing GPG or SSH signing keys.

Notes

I verified in an internal test repository that switching the file write to GraphQL createCommitOnBranch produced a commit with:

  • verification.verified=true
  • verification.reason=valid

The existing delete_file implementation already avoids the simpler REST contents deletion path because of commit signing behavior. The same issue can affect create/update and multi-file writes.

Proposed fix

Use GraphQL createCommitOnBranch for create_or_update_file and push_files, keeping the existing tool inputs and response shape as much as possible.

主要语言
Go
星标
33.1k
派生
5k
平均合并
2 天 15 小时
30 天内合并 PR
27

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

github/github-mcp-server 的其他 Issue

查看 github/github-mcp-server 的全部 Issue

相似的 Issue

更多 Go Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。