From 62bf2b29105b93b6a3e3ef27ab15d96e74da3bb1 Mon Sep 17 00:00:00 2001 From: ritms42 Date: Thu, 24 Sep 2026 21:48:57 +0200 Subject: [PATCH] fix(mcp): pin chrome-devtools-mcp to 1.10.1 instead of @latest The default chrome-devtools connector is launched with `npx -y` and `@latest`, so every session start can silently install whatever version was most recently published to npm. Pinning makes the default connector reproducible and removes the unpinned-npx finding that /security-scan (AgentShield) reports against ECC's own .mcp.json. The same spec is pinned in the Codex merge script so both harnesses stay in sync, and the Codex merge test is updated to match. Co-Authored-By: Claude Opus 5.5 --- .mcp.json | 2 +- scripts/codex/merge-mcp-config.js | 2 +- tests/scripts/codex-hooks.test.js | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.mcp.json b/.mcp.json index 045baea18..9860a4dbe 100644 --- a/.mcp.json +++ b/.mcp.json @@ -2,7 +2,7 @@ "mcpServers": { "chrome-devtools": { "command": "npx", - "args": ["-y", "chrome-devtools-mcp@latest"] + "args": ["-y", "chrome-devtools-mcp@1.10.1"] } } } diff --git a/scripts/codex/merge-mcp-config.js b/scripts/codex/merge-mcp-config.js index 721e3c29f..64f42d333 100644 --- a/scripts/codex/merge-mcp-config.js +++ b/scripts/codex/merge-mcp-config.js @@ -94,7 +94,7 @@ const DEFAULT_MCP_STARTUP_TIMEOUT_TOML = `startup_timeout_sec = ${DEFAULT_MCP_ST // mcp-configs/mcp-servers.json. Existing user-managed entries are never // touched by the merge (add-only), except the known-invalid repair below. const ECC_SERVERS = { - 'chrome-devtools': dlxServer('chrome-devtools', 'chrome-devtools-mcp@latest', { startup_timeout_sec: DEFAULT_MCP_STARTUP_TIMEOUT_SEC }, DEFAULT_MCP_STARTUP_TIMEOUT_TOML) + 'chrome-devtools': dlxServer('chrome-devtools', 'chrome-devtools-mcp@1.10.1', { startup_timeout_sec: DEFAULT_MCP_STARTUP_TIMEOUT_SEC }, DEFAULT_MCP_STARTUP_TIMEOUT_TOML) }; // ECC <= 2.0.0 emitted [mcp_servers.exa] with a `url` key. Codex rejects diff --git a/tests/scripts/codex-hooks.test.js b/tests/scripts/codex-hooks.test.js index c47f6d986..ef4934e6b 100644 --- a/tests/scripts/codex-hooks.test.js +++ b/tests/scripts/codex-hooks.test.js @@ -916,7 +916,7 @@ if ( const merged = fs.readFileSync(configPath, 'utf8'); const parsed = TOML.parse(merged); assert.strictEqual(parsed.mcp_servers['chrome-devtools'].command, 'npx'); - assert.deepStrictEqual(parsed.mcp_servers['chrome-devtools'].args, ['chrome-devtools-mcp@latest']); + assert.deepStrictEqual(parsed.mcp_servers['chrome-devtools'].args, ['chrome-devtools-mcp@1.10.1']); assert.strictEqual(parsed.mcp_servers['chrome-devtools'].startup_timeout_sec, 30); // No retired server may be (re-)emitted — exa's url form broke Codex (#2224). assert.strictEqual(parsed.mcp_servers.exa, undefined);