Bump CLI, MCP SDK, and scanner image defaults - #52855
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
PR TriageCategory: chore | Risk: medium | Score: 35/100
Recommended action:
|
PR Triage
Routine CLI/MCP/Docker version bump touching 266 files. No CI runs detected yet. Low urgency; defer until CI signal available. Automated triage — see [PR Triage Report] for full context.
|
|
✅ Test Quality Sentinel completed test quality analysis. No test files were added or modified in this PR. Test Quality Sentinel skipped.
|
|
🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅
|
|
✅ Design Decision Gate 🏗️ completed the design decision gate check. No ADR enforcement needed: PR does not have the implementation label and has only 17 new lines of code in business logic directories (threshold: 100).
|
|
✅ PR Code Quality Reviewer completed the code quality review. Reviewed PR #52855. No actionable blocking issues found in the changed lines; version bumps and regenerated workflow lockfiles appear internally consistent, and no new review comments were necessary.
|
|
✅ Ponytail Reviewer completed successfully! Lean already. Ship. This PR only bumps default CLI/MCP SDK/scanner image versions (changeset entry, compat.json max-agent bump, and regenerated .lock.yml files). No hand-authored logic changed, so there is no over-engineering to flag.
|
There was a problem hiding this comment.
Routine version bump — all version strings updated consistently across lock files and env vars. No logic or security concerns. ✅
🧵 Reviewed using Impeccable skills by Impeccable Skills Reviewer · sonnet46 · 15 AIC · ⌖ 7.01 AIC · ⊞ 5.6K
There was a problem hiding this comment.
Skills-Based Review 🧠
Applied /grill-with-docs — routine version-refresh PR, no logic changes.
📋 Review Summary
What was checked
.github/aw/compat.json:max-agentcorrectly advanced from1.0.79→1.0.80in sync with the Copilot CLI default bump..changeset/patch-cli-docker-version-updates-2026-08-15.md: Well-formed changeset entry, correct bump type (patch), concise description.- Lock files (~260
.lock.yml): mechanically recompiled — no manual review needed.
Positive Highlights
- ✅ Changeset entry matches the scope and intent of the PR.
- ✅
compat.jsonmax-agentkept in sync with the new CLI default — the right place for this change. - ✅ SHA-pinned Docker images refreshed (Syft, Grype, Shellcheck), consistent with supply-chain hardening practices.
- ✅ PR description explicitly lists all version deltas.
No actionable issues found.
🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · sonnet46 · 24.7 AIC · ⌖ 8.33 AIC · ⊞ 7.7K
Comment /matt to run again
There was a problem hiding this comment.
Pull request overview
Refreshes default CLI, MCP SDK, and scanner versions, including generated workflow metadata.
Changes:
- Bumps six CLI/MCP defaults and related installer metadata.
- Updates Syft, Grype, and ShellCheck image pins.
- Recompiles affected workflow metadata and golden output.
Show a summary per file
| File | Description |
|---|---|
pkg/workflow/testdata/TestWasmGolden_AllEngines/gemini.golden |
Updates Gemini golden output. |
pkg/constants/version_constants.go |
Bumps default tool versions. |
pkg/cli/README.md |
Refreshes scanner-image documentation. |
pkg/cli/docker_images.go |
Updates scanner tags and digests. |
actions/setup/sh/install_copilot_cli.sh |
Updates Copilot fallback version. |
actions/setup/js/package.json |
Bumps Copilot SDK dependency. |
.github/workflows/workflow-skill-extractor.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/workflow-normalizer.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/weekly-safe-outputs-spec-review.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/weekly-editors-health-check.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/visual-regression-checker.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/video-analyzer.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/update-astro.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/uk-ai-operational-resilience.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/super-linter.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/static-analysis-report.md |
Updates ShellCheck commands. |
.github/workflows/squad-game-planner.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/smoke-workflow-call.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/smoke-service-ports.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/smoke-multi-pr.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/smoke-create-cross-repo-pr.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/smoke-copilot-small.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/smoke-ci.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/smoke-checkout-pr-dispatch.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/sighthound-security-scan.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/repo-tree-map.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/pr-description-caveman.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/ponytail-reviewer.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/objective-impact-report.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/notion-issue-summary.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/github-remote-mcp-auth-test.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/firewall.lock.yml |
Updates Copilot CLI and SDK metadata. |
.github/workflows/example-permissions-warning.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/example-failure-category-filter.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/designer-drift-audit.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/daily-team-status.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/daily-schema-audit-cursor.lock.yml |
Updates Copilot CLI and SDK metadata. |
.github/workflows/daily-model-inventory.md |
Bumps inventory SDK installation. |
.github/workflows/daily-max-ai-credits-test.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/daily-credit-limit-test.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/daily-byok-ollama-test.lock.yml |
Refreshes Copilot metadata. |
.github/workflows/bot-detection.lock.yml |
Refreshes Copilot metadata. |
.github/aw/compat.json |
Extends Copilot compatibility range. |
.changeset/patch-cli-docker-version-updates-2026-08-15.md |
Records the patch release. |
Review details
- Files reviewed: 125/266 changed files
- Comments generated: 1
- Review effort level: Balanced
| @@ -71,7 +71,7 @@ steps: | |||
|
|
|||
| # Pull shellcheck Docker image | |||
| echo "Pulling shellcheck image..." | |||
| docker pull koalaman/shellcheck:v0.10.0 | |||
| docker pull koalaman/shellcheck:v0.11.0 | |||
There was a problem hiding this comment.
Fixed in 29f2b6d: both shellcheck references in .github/workflows/static-analysis-report.md are now pinned to v0.11.0@sha256:61862eba1fcf09a484ebcc6feea46f1782532571a34ed51fedf90dd25f925a8d, and .github/workflows/static-analysis-report.lock.yml was recompiled accordingly.
|
@copilot resolve the merge conflicts on this branch. |
…cker-versions # Conflicts: # .github/workflows/design-decision-gate.lock.yml Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Resolved and pushed in |
|
@copilot resolve the merge conflicts on this branch. |
|
@copilot Quick triage for maintainer-ready follow-up: This branch still shows merge-conflict state. Please run Run context: https://github.com/github/gh-aw/actions/runs/31886878354
|
…cker-versions # Conflicts: # .github/workflows/pr-code-quality-reviewer.lock.yml Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Resolved and pushed in |
|
@copilot resolve the merge conflicts on this branch. |
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
|
@copilot Quick triage for maintainer-ready follow-up: This branch still shows merge-conflict state. Please run Outstanding review items (newest first):
Run context: https://github.com/github/gh-aw/actions/runs/31888236959
|
Done in |
|
🎉 This pull request is included in a new release. Release: |
Routine version refresh for CLI/MCP tooling and static-analysis Docker images. This updates six CLI/MCP defaults and three scanner image pins, including security-relevant Syft and Grype bumps.
CLI / MCP defaults
2.1.227→2.1.2331.0.79→1.0.801.0.8→1.0.110.39.1→0.55.10.84.1→0.84.2@modelcontextprotocol/sdk:1.24.0→1.30.0Docker scanner images
v1.50.0→v1.51.0v0.116.1→v0.117.0v0.10.0→v0.11.0Generated/runtime metadata