Skip to content

fix(mcp): link the public repository from the registry manifest - #14

Merged
feng-shiplight merged 1 commit into
mainfrom
feng/workspace
Sep 29, 2026
Merged

feng-shiplight merged 1 commit into
mainfrom
feng/workspace

Conversation

@feng-shiplight

Copy link
Copy Markdown
Contributor

Summary

apps/mcp-server/server.json omitted the optional repository field, so the MCP registry entry gives readers no way to reach this server's source.

That omission was correct when it was made. 0.2.0 shipped a repository pointing at a repo that returned 404 to everyone outside the org, so every reader of the registry entry got a broken link, and the field was dropped rather than publish one. ShiplightAI/shiplight-cli is public now and holds this server's source, so the premise is gone.

"repository": {
  "url": "https://github.com/ShiplightAI/shiplight-cli",
  "source": "github",
  "subfolder": "apps/mcp-server"
}

The url and the subfolder both come from the instructions the existing tests left behind for this exact moment (scripts/__tests__/server-json-registry-manifest.test.ts).

This reaches the registry with the next release, 0.2.4. The published 0.2.3 entry keeps the manifest it was published with.

Test plan

  • The url returns HTTP 200 to an anonymous, redirect-following request — the same check the publish preflight performs.
  • mcp-publisher validate accepts the manifest with subfolder included (run via the preflight: ✅ server.json is valid).
  • The preflight's repository step now reports publicly reachable (HTTP 200) instead of omitted, so the reachable path is exercised rather than the empty one.
  • Two tests pinned the field absent, each documenting how to invert it; both now assert the link and both fail against the pre-change manifest (verified by stashing server.json — 1 failure in each suite):
    • scripts/__tests__/server-json-registry-manifest.test.ts
    • apps/mcp-server/scripts/repositoryLink.test.ts
  • The well-formedness guard in server-json-registry-manifest.test.ts was deliberately written to be vacuous while the field was missing, so it activates on its own and needed no change.
  • Full scripts guard suite 144/144; mcp-server unit suite 35/35.

Why this can't regress quietly

publish-mcp-registry.ts already fetches repository.url anonymously and blocks the release on a 4xx that means "you cannot see this" (repositoryLink.ts deliberately does not block on 5xx, 408, 425 or 429, which are runner- or GitHub-side noise). So a change back to a private or wrong repo fails the release rather than shipping another broken link.

Stale comments in repositoryLink.ts and publish-mcp-registry.ts asserting the field is "deliberately absent" are corrected; the reasoning they carried still governs the verdict rules, so it is kept rather than deleted.

🤖 Generated with Claude Code

server.json omitted `repository` because the server's source was private.
0.2.0 shipped one pointing at a repo that 404'd for everyone outside the
org, and the field was dropped rather than publish a link nobody could
open. ShiplightAI/shiplight-cli is public now and holds this source, so the
premise is gone and registry readers have no way to reach the code.

Both the url and `subfolder: apps/mcp-server` come from the instructions the
existing tests left for this moment; the url returns HTTP 200 to an
anonymous request, and `mcp-publisher validate` accepts the manifest with
subfolder included.

Two tests pinned the field absent and each documented how to invert it.
Both now assert the link, and both fail against the pre-change manifest.
The well-formedness guard in server-json-registry-manifest.test.ts was
written to be vacuous while the field was missing, so it activates on its
own.

The publish preflight already fetches the url anonymously and blocks on a
4xx, so a regression to a private or wrong repo fails the release rather
than shipping another broken link.

This reaches the registry with 0.2.4; the published 0.2.3 entry keeps the
manifest it was published with.

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review: fix(mcp): link the public repository from the registry manifest

Verdict: Approve — no blocking issues found.

Overview

Adds the repository field to apps/mcp-server/server.json now that ShiplightAI/shiplight-cli is public. Two tests that previously asserted the field was absent are inverted to assert the correct value. Two TypeScript files receive comment-only updates correcting now-stale history. No logic changes.

Findings

# Severity Location Finding
1 LOW apps/mcp-server/scripts/repositoryLink.test.ts:107 The new assertion checks only manifest.repository?.url, not the full object (source, subfolder). The structural completeness check lives in server-json-registry-manifest.test.ts:122 via deepEqual, so nothing is unguarded — the asymmetry is intentional and matches the PR description. Not a defect.

No CRITICAL, HIGH, or MEDIUM issues found.

Additional notes

  • server.json keeps version: "0.2.3" — correct; the bump to 0.2.4 belongs to the publish workflow, not this PR.
  • The previously vacuous well-formed guard at scripts/__tests__/server-json-registry-manifest.test.ts:129 (if (!manifest.repository) return) now actively runs its assert.match / assert.ok checks, giving free coverage uplift.
  • The publish preflight independently fetches repository.url anonymously and blocks on 4xx (repositoryLink.ts), providing a runtime safety net against future regression.
  • All files follow the project's ESM conventions; no any introduced.

@feng-shiplight
feng-shiplight merged commit 52955a5 into main Sep 29, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant