Skip to content

GHAS plugin enhancements#37

Merged
aashah merged 3 commits intomainfrom
gregbty/security-tool-enhancements
May 5, 2026
Merged

GHAS plugin enhancements#37
aashah merged 3 commits intomainfrom
gregbty/security-tool-enhancements

Conversation

@gregbty
Copy link
Copy Markdown
Contributor

@gregbty gregbty commented May 5, 2026

This change adds a new custom MCP server configuration to improve the out-of-the-box experience.

Copilot AI review requested due to automatic review settings May 5, 2026 17:13
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR improves the Advanced Security plugin’s out-of-the-box MCP setup by adding a default GitHub MCP server configuration and updating skill/docs to reference it.

Changes:

  • Add a default plugins/advanced-security/.mcp.json GitHub MCP server configuration and wire it into the plugin marketplace entry.
  • Update the secret-scanning and dependency-scanning skills to reference the default MCP configuration/toolsets.
  • Expand the Advanced Security plugin README to document the dependency-scanning skill.
Show a summary per file
File Description
plugins/advanced-security/skills/secret-scanning/SKILL.md Updates prerequisites/toolset wording and links to the default MCP config.
plugins/advanced-security/skills/dependency-scanning/SKILL.md Updates prerequisites wording and links to the default MCP config.
plugins/advanced-security/README.md Documents the dependency-scanning skill in the plugin README.
plugins/advanced-security/.mcp.json Adds a default GitHub MCP server configuration for GHAS-related toolsets/tools.
.github/plugin/marketplace.json Registers the plugin’s default MCP server config path in marketplace metadata.

Copilot's findings

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

  • Files reviewed: 5/5 changed files
  • Comments generated: 4

Comment thread plugins/advanced-security/skills/secret-scanning/SKILL.md
Comment thread plugins/advanced-security/skills/dependency-scanning/SKILL.md
Comment thread plugins/advanced-security/.mcp.json
Comment thread plugins/advanced-security/.mcp.json
@aashah aashah added this pull request to the merge queue May 5, 2026
Merged via the queue into main with commit 164d6e6 May 5, 2026
4 checks passed
@aashah aashah deleted the gregbty/security-tool-enhancements branch May 5, 2026 22:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants