Repository navigation
OpenSpec setup, unofficial/Rapid7 disclaimers, and CI/release hardening - #17
Merged
Merged
Conversation
Initialize OpenSpec (spec-driven schema) with the /opsx:* command and skill integration, and add two managed changes: - official-parity-and-mcp-modernization: reach feature parity with the official Rapid7 MCP (DB intel tools, module check, async results, safety gate) and adopt current MCP-spec features (annotations, structured output, elicitation, resources, FastMCP 3.x evaluation). Planning only — not yet implemented. - release-and-ci-hardening: CI quality gates + SBOM release integration. Implemented in the following commits. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…dloot owner - Prefix the PyPI description and README with "unofficial" and add a clear "not affiliated with / supported by Rapid7" notice (README + NOTICE). - Credit GH05TCREW as the original author; frame this fork's contribution as additional features plus the PyPI release. - Update owner/repository references from cbdmaul to setuidloot (repo renamed) across pyproject, README, server.json, and the MCP registry namespace; set author/maintainer to setuidloot <michael@mccord.ai>. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Close the release-pipeline gaps identified against the release-and-ci-hardening OpenSpec change: - generate_sbom.py: add a `--check` mode (fails if sbom.json has drifted from poetry.lock) and make status messages robust to an out-of-tree output path. - CI (ci.yml): new jobs alongside the test matrix — packaging build + twine check, `black --check` (blocking) with advisory `mypy`, and SBOM freshness. - Release (release.yml): verify SBOM freshness (fail-fast), upload it as a separate `sbom` artifact (kept out of dist/ so PyPI publish is unaffected), and attach sbom.json to the GitHub Release. - Add `make sbom-check`; document the gates in RELEASING.md and CONTRIBUTING.md. - Add tests for the SBOM generator and its --check mode. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
pymetasploit3 <=1.0.6 (GHSA-qpc3-8vqg-8g6w, no upstream fix) is vulnerable to console command injection: newline characters in module options such as RHOSTS terminate the intended `set <key> <value>` command and execute attacker-supplied console commands. Our console execution path (`_execute_module_console`) built `set` commands the same way and shared the exposure. Add `_reject_unsafe_option_chars()` and apply it in both `_set_module_options` (RPC path) and `_execute_module_console` (console path, incl. payload options), rejecting newline / carriage-return / NUL in option names and values before any value is interpolated into a console command. Add unit + async tests. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Raises the mcp floor from >=1.6.0 to >=1.28.1 (resolves to 1.29.0), clearing three high-severity Dependabot alerts: - GHSA-vj7q-gjh5-988w (WebSocket transport Host/Origin validation) - GHSA-jpw9-pfvf-9f58 (HTTP transports serve requests without verifying principal) - GHSA-hvrp-rf83-w775 (task handlers accessible across clients) Re-locks dependencies, regenerates sbom.json, and records the security fixes and release-prep changes under an Unreleased CHANGELOG section. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Groundwork for the first public PyPI release of this fork (
metasploit-mcp), managed via a newly-initialized OpenSpec workflow, plus remediation of all open Dependabot alerts.1. OpenSpec initialization + change proposals (
chore(openspec))/opsx:*command + skill integration under.claude/.openspec/changes/:official-parity-and-mcp-modernization— plan to reach parity with the official Rapid7 MCP and adopt current MCP-spec features. Planning only — not implemented here.release-and-ci-hardening— implemented in this PR (see Add HTTP health check endpoints for Docker and monitoring systems #3).2. Unofficial status + Rapid7 disclaimers + owner rename (
docs)cbdmaul→setuidloot(repo renamed) acrosspyproject.toml,README.md,server.json, MCP registry namespace; author set tosetuidloot <michael@mccord.ai>.3. CI quality gates + SBOM release integration (
ci)generate_sbom.py --check(drift detection); CI jobs for packaging build +twine check,black --check(blocking) with advisorymypy, and SBOM freshness; release verifies + attachessbom.json. Docs + tests.4. Security — Dependabot remediation (
fix(security),fix(deps))pymetasploit3, no upstream fix): console command injection via newline characters in module options (e.g.RHOSTS). Mitigated in code:_reject_unsafe_option_chars()rejects newline / carriage-return / NUL in option names and values on both the RPC (_set_module_options) and console (_execute_module_console) paths, before any value is interpolated into asetcommand. Added unit + async tests.mcp): bumpedmcp>=1.6.0→>=1.28.1(resolves to 1.29.0), clearing GHSA-vj7q-gjh5-988w, GHSA-jpw9-pfvf-9f58, GHSA-hvrp-rf83-w775.Verification
black --check src tests,poetry build,twine check,generate_sbom.py --checkall pass locally.Notes / follow-ups
mypyis intentionally advisory for now (pre-existing backlog); flipping to blocking is tracked in the change's tasks.setuidloot/MetasploitMCP(workflowrelease.yml, envpypi) before first publish.mcpalerts will auto-close once this merges tomain. The criticalpymetasploit3alert has no upstream fix, so it will remain "open" in Dependabot despite the code mitigation — it should be dismissed as "risk mitigated in code / no fix available" after merge.🤖 Generated with Claude Code