feat(security): add typed security alert outputs - #3387
Open
SamMorrowDrums wants to merge 2 commits into
Open
SamMorrowDrums wants to merge 2 commits into
SamMorrowDrums wants to merge 2 commits into
Conversation
SamMorrowDrums
added this pull request to stack #3385
October 2, 2026 11:20
7 of 13 tasks
SamMorrowDrums
force-pushed
the
sammorrowdrums-typed-security-outputs
branch
from
October 2, 2026 20:50
7ef5714 to
836f8a1
Compare
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Typed input handling introduces compatibility regressions in omitted-state Dependabot calls and null CWE filters.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Extends the structured-output migration to security read tools, providing typed results for modern clients while retaining legacy text responses.
Changes:
- Adds security input/output types and response projections.
- Adds protocol-gating and schema-conformance tests.
- Consolidates architecture-specific license listings.
| File | Description |
|---|---|
| third-party-licenses.windows.md | Combines Windows architecture listings. |
| third-party-licenses.linux.md | Combines Linux architecture listings. |
| pkg/github/typed_security_outputs_test.go | Tests modern structured and legacy text responses. |
| pkg/github/security_outputs.go | Defines security types, projections, and normalization helpers. |
| pkg/github/security_advisories.go | Migrates advisory reads to typed outputs. |
| pkg/github/secret_scanning.go | Migrates secret-scanning reads to typed outputs. |
| pkg/github/dependabot.go | Adds typed Dependabot results and pagination. |
| pkg/github/code_scanning.go | Migrates code-scanning reads to typed outputs. |
| pkg/github/code_quality.go | Adds typed code-quality findings alongside raw text. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| WithCursorPagination(schema) | ||
|
|
||
| return NewTool( | ||
| return NewTool[ListDependabotAlertsInput, DependabotAlertsOutput]( |
| result = attachStaticIFCLabel(ctx, deps, result, ifc.LabelGlobalSecurityAdvisory()) | ||
| return result, nil, nil | ||
| return result, mapSecurityOutputs(advisories, globalSecurityAdvisoryOutput), nil | ||
| }, |
Add typed protocol-gated outputs for code quality, code and secret scanning, Dependabot, and security advisories while preserving existing text responses. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep advertised input defaults while disabling runtime default injection for security filters. Normalize null CWE filters, compact findings, and verify modern wire outputs alongside exact legacy formatting. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
SamMorrowDrums
force-pushed
the
sammorrowdrums-typed-security-outputs
branch
from
October 3, 2026 13:19
836f8a1 to
8d8c285
Compare
SamMorrowDrums
marked this pull request as ready for review
October 3, 2026 13:41
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
Adds typed, protocol-gated structured outputs for security-domain read tools. Modern clients receive compact typed results while existing text responses remain unchanged for legacy and unknown-version clients.
Why
Completes the security-domain tools covered by the structured-output migration.
Fixes #3360
What changed
get_code_quality_finding; code scanning get/list; secret scanning get/list; Dependabot get/list; and global, repository, and organization security advisory get/list tools to typed input/output DTOs.MCP impact
Modern clients now receive output schemas and structured results for these tools. Existing text results and tool input schemas are unchanged.
Prompts tested (tool changes only)
Security / limits
Existing scopes and permission checks are unchanged.
Structured DTOs retain the scoped security details needed by callers; existing full text responses and IFC labels remain unchanged.
Tool renaming
deprecated_tool_aliases.goNote: if you're renaming tools, you must add the tool aliases. For more information on how to do so, please refer to the official docs.
Lint & tests
./script/lint— passed with 0 issues../script/test— passed (go test -race ./...).Docs
script/generate-docsran and produced no documentation diff.