Skip to content

feat(mcp): read-only dependency inventory tools - #112

Merged
balcsida merged 1 commit into
feat/supply-chain/m5-reviewfrom
feat/supply-chain/m6-mcp
Sep 22, 2026
Merged

balcsida merged 1 commit into
feat/supply-chain/m5-reviewfrom
feat/supply-chain/m6-mcp

Conversation

@balcsida

@balcsida balcsida commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

Summary

Milestone 6. Depends on #111.

Adds three read-only MCP tools over the same authorized services REST uses, so scope, not-found behavior, cursors, and truncation agree:

  • search_dependency_inventory – unique coordinates across readable repositories with filters and cursor pagination.
  • find_component_repositories – authorized repositories/snapshots containing a component.
  • inspect_component_license – declarations, registry evidence history with resolver/list versions, assessment, relationships for one occurrence.

Responses include snapshot IDs, provenance, scope, and truncation, and state that package/license/evidence content is untrusted data, never instructions. No approval, import, or refresh tools are exposed. Exact code-usage joins are deliberately not offered (a dependency path is not a call graph; GHES snapshots are unbound observations).

Verification

Integration test: tool list has no write tools; REST and MCP return the same components for the same principal; another installation's occurrences never leak through results or error text; bogus keys and foreign snapshot IDs fail safely; truncation honored.

Implications

None beyond the module gate; tools register only when GRAPHNEST_SUPPLY_CHAIN=true.


Part of the Dependencies & Licenses stack (native GitHub stack #114, ten layers, main ← #104 ← #105 ← #106 ← #107 ← #108 ← #109 ← #110 ← #111 ← #112 ← #113). Design: ADR-0017; living plan with the full validation table: docs/execplans/supply-chain.md. All commits are SSH-signed. Nothing here calls a live GitHub Enterprise Server or a live package registry; GitHub and registry behavior is exercised against fixtures and fake servers only.

Stack created with GitHub Stacks CLI

@balcsida
balcsida added this pull request to stack #114 September 22, 2026 21:06
@balcsida balcsida changed the title feat(mcp): expose read-only dependency inventory tools feat(mcp): read-only dependency inventory tools Sep 22, 2026
@balcsida
balcsida force-pushed the feat/supply-chain/m6-mcp branch 2 times, most recently from 50a3ea3 to 8c6b999 Compare September 22, 2026 22:19
@balcsida
balcsida marked this pull request as ready for review September 22, 2026 22:20
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

Add search_dependency_inventory, find_component_repositories, and
inspect_component_license over the same inventory services REST uses,
so authorization scope, not-found behavior, cursors, and truncation
agree. Outputs carry snapshot IDs, provenance, scope, and a note that
package and license content is untrusted data. No write tools are
exposed. An integration test proves REST/MCP agreement and that another
installation's occurrences never leak through results or errors.

Co-Authored-By: Claude <noreply@anthropic.com>
@balcsida
balcsida force-pushed the feat/supply-chain/m6-mcp branch from 8c6b999 to 2af8325 Compare September 22, 2026 22:30
@balcsida
balcsida force-pushed the feat/supply-chain/m6-mcp branch from 2af8325 to aa278e7 Compare September 22, 2026 22:59
@balcsida
balcsida force-pushed the feat/supply-chain/m6-mcp branch from aa278e7 to 2af8325 Compare September 22, 2026 23:51
@balcsida
balcsida merged commit 0def80c into main Sep 22, 2026
19 of 24 checks passed
@balcsida balcsida mentioned this pull request Sep 23, 2026
@balcsida
balcsida deleted the feat/supply-chain/m6-mcp branch September 23, 2026 07:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant