• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

stacklok / toolhive / 33268421157
70%

Build:
DEFAULT BRANCH: main
Ran 29 Aug 2026 06:38PM UTC
Jobs 1
Files 903
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

29 Aug 2026 06:29PM UTC coverage: 69.655% (-0.05%) from 69.703%
33268421157

push

github

web-flow
Guard OIDC discovery against private IPs (#6455)

Remote MCP authentication can derive an OIDC issuer from an untrusted realm. The OAuth configuration fallback previously performed discovery without the private-IP dial guard, allowing requests to loopback and private hosts.

Thread the caller-selected blockPrivateIPs policy through OIDC config creation, enforce the remote flow's !AllowPrivateIPs setting, preserve private issuer access for operator-configured token sources, and add listener-based regression tests.

Security-advisory: GHSA-cvhc-p56v-qm9r

Reported-by: Yanhaoxi (https://github.com/Yanhaoxi)

6 of 6 new or added lines in 3 files covered. (100.0%)

60 existing lines in 4 files now uncovered.

76307 of 109550 relevant lines covered (69.65%)

91.65 hits per line

Coverage Regressions

Lines Coverage ∆ File
47
59.42
-4.89% pkg/workloads/manager.go
6
72.34
-6.38% pkg/secrets/keyring/keyctl_linux.go
4
85.61
-2.88% pkg/transport/proxy/transparent/sse_response_processor.go
3
0.0
-100.0% pkg/workloads/sysproc_unix.go
Jobs
ID Job ID Ran Files Coverage
1 33268421157.1 29 Aug 2026 06:38PM UTC 903
69.65
GitHub Action Run
Source Files on build 33268421157
  • Tree
  • List 903
  • Changed 10
  • Source Changed 3
  • Coverage Changed 10
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #33268421157
  • 0fb54d43 on github
  • Prev Build on main (#33208280784)
  • Next Build on main (#33373399293)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc