Skip to content

deploy: update prod to v1.7.7#1251

Merged
rdimitrov merged 1 commit intomainfrom
deploy/prod-v1.7.7
May 4, 2026
Merged

deploy: update prod to v1.7.7#1251
rdimitrov merged 1 commit intomainfrom
deploy/prod-v1.7.7

Conversation

@rdimitrov
Copy link
Copy Markdown
Member

Summary

  • Bump mcp-registry:imageTag from 1.7.61.7.7 in deploy/Pulumi.gcpProd.yaml
  • v1.7.7 is a security patch covering three findings (validator hardening, attribute-context UI escaping, IPv6 SSRF blocklist extension); see the v1.7.7 release notes
  • Staging is on f5f40bd (the v1.7.7 commit) and verified end-to-end:
    • /v0.1/version reports the new commit
    • /v0.1/validate rejects a poisoned websiteUrl with website-url-invalid-characters
    • / HTML serves the escapeAttr helper

Test plan

  • Confirm release workflow's ko-push job has finished publishing ghcr.io/modelcontextprotocol/registry:1.7.7 before merging
  • Watch deploy-production workflow rolls the registry pods to 1.7.7
  • Hit https://registry.modelcontextprotocol.io/v0.1/version and confirm git_commit matches f5f40bd...
  • Spot-check the catalogue UI loads cleanly

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@rdimitrov rdimitrov merged commit 1b9f69e into main May 4, 2026
5 checks passed
@rdimitrov rdimitrov deleted the deploy/prod-v1.7.7 branch May 4, 2026 14:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant