fix: keep GitHub MCP credentials out of argv - #209
Conversation
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (1)
Disabled knowledge base sources:
📝 WalkthroughSummary by CodeRabbit
WalkthroughThe GitHub MCP server configuration now uses native HTTP transport with the GitHub Copilot MCP endpoint. The shell subprocess, ChangesGitHub MCP transport
Estimated code review effort: 1 (Trivial) | ~2 minutes Poem
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
Before / after
gh auth tokenwas interpolated into anmcp-remoteprocess argument.Breaking and irreversible changes
Deliberate boundaries
Verification
bun run formatbun run lintbun run checkgit diff --checkjq empty .ruler/mcp.jsonSummary by cubic
Replaces the shell-based GitHub MCP launcher with Ruler's native HTTP transport so the GitHub OAuth token no longer gets interpolated into a child-process argv. The GitHub MCP endpoint is now configured directly as an HTTP server, so clients use native HTTP authentication instead of the
sh -clauncher withmcp-remote. Reverting this change restores the previous configuration; no compile-time or state changes are involved, and OAuth credential rotation and contaminated-process termination were handled operationally.Written for commit 9f81ea4. Summary will update on new commits.