mirror of
https://github.com/affaan-m/ECC.git
synced 2026-09-29 13:05:18 +02:00
fix(mcp): pin chrome-devtools-mcp to 1.10.1 instead of @latest
The default chrome-devtools connector is launched with `npx -y` and `@latest`, so every session start can silently install whatever version was most recently published to npm. Pinning makes the default connector reproducible and removes the unpinned-npx finding that /security-scan (AgentShield) reports against ECC's own .mcp.json. The same spec is pinned in the Codex merge script so both harnesses stay in sync, and the Codex merge test is updated to match. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
e482e57941
commit
62bf2b2910
@@ -2,7 +2,7 @@
|
||||
"mcpServers": {
|
||||
"chrome-devtools": {
|
||||
"command": "npx",
|
||||
"args": ["-y", "chrome-devtools-mcp@latest"]
|
||||
"args": ["-y", "chrome-devtools-mcp@1.10.1"]
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -94,7 +94,7 @@ const DEFAULT_MCP_STARTUP_TIMEOUT_TOML = `startup_timeout_sec = ${DEFAULT_MCP_ST
|
||||
// mcp-configs/mcp-servers.json. Existing user-managed entries are never
|
||||
// touched by the merge (add-only), except the known-invalid repair below.
|
||||
const ECC_SERVERS = {
|
||||
'chrome-devtools': dlxServer('chrome-devtools', 'chrome-devtools-mcp@latest', { startup_timeout_sec: DEFAULT_MCP_STARTUP_TIMEOUT_SEC }, DEFAULT_MCP_STARTUP_TIMEOUT_TOML)
|
||||
'chrome-devtools': dlxServer('chrome-devtools', 'chrome-devtools-mcp@1.10.1', { startup_timeout_sec: DEFAULT_MCP_STARTUP_TIMEOUT_SEC }, DEFAULT_MCP_STARTUP_TIMEOUT_TOML)
|
||||
};
|
||||
|
||||
// ECC <= 2.0.0 emitted [mcp_servers.exa] with a `url` key. Codex rejects
|
||||
|
||||
@@ -916,7 +916,7 @@ if (
|
||||
const merged = fs.readFileSync(configPath, 'utf8');
|
||||
const parsed = TOML.parse(merged);
|
||||
assert.strictEqual(parsed.mcp_servers['chrome-devtools'].command, 'npx');
|
||||
assert.deepStrictEqual(parsed.mcp_servers['chrome-devtools'].args, ['chrome-devtools-mcp@latest']);
|
||||
assert.deepStrictEqual(parsed.mcp_servers['chrome-devtools'].args, ['chrome-devtools-mcp@1.10.1']);
|
||||
assert.strictEqual(parsed.mcp_servers['chrome-devtools'].startup_timeout_sec, 30);
|
||||
// No retired server may be (re-)emitted — exa's url form broke Codex (#2224).
|
||||
assert.strictEqual(parsed.mcp_servers.exa, undefined);
|
||||
|
||||
Reference in New Issue
Block a user