Clean stale GitHub guard coverage cache entries - #12235
Conversation
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
There was a problem hiding this comment.
🟢 Approval recommended
The normalization mappings match the guard’s canonical CLI operation identifiers, with no unresolved issues found.
Pull request overview
Updates the guard coverage workflow to prevent obsolete GitHub CLI names from recurring as false-positive gaps.
Changes:
- Removes ten stale CLI spellings while preserving canonical identifiers for real gaps.
- Regenerates the compiled workflow artifact.
File summaries
| File | Description |
|---|---|
.github/workflows/github-mcp-guard-coverage-checker.md |
Adds cache normalization instructions. |
.github/workflows/github-mcp-guard-coverage-checker.lock.yml |
Regenerates the workflow with updated tooling. |
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 0
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
🔒 mcpg Read-Only Stress — docker-sbxSurface coverage: MCP tool calls + proxied CLI (REST) + GraphQL mutations
Overall: INCONCLUSIVE
Prerequisites needed to run this variant end-to-end: valid
|
🔒 mcpg Read-Only Stress — defaultSurface coverage: MCP tool calls + proxied CLI (REST) + GraphQL mutations
Overall: INCONCLUSIVE
No writes succeeded. Zero FAILs. References: §33409341415
|
The guard already models the reported CLI write operations under canonical synthetic identifiers, but persisted coverage state retained obsolete
gh …command spellings. This caused recurring false-positive coverage findings.known_gapsandlast_all_gaps.github-mcp-guard-coverage-checker.lock.ymlfor the updated prompt.