feat: implement cursor pagination for dependabot alerts - #2651
Conversation
…lated documentation
There was a problem hiding this comment.
Pull request overview
Note
Copilot was unable to run its full agentic suite in this review.
This PR updates the list_dependabot_alerts tool to use cursor-based pagination and to surface pagination metadata (next cursor) in the tool response.
Changes:
- Switched
list_dependabot_alertsfrom page-based pagination (page) to cursor pagination (after). - Updated the tool response format to wrap alerts with
pageInfo(includingnextCursor/hasNextPage). - Updated tests, tool snapshots, and README to reflect the new pagination input and output shape.
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
| pkg/github/dependabot.go | Implements cursor pagination for Dependabot alerts and returns alerts plus pageInfo envelope. |
| pkg/github/dependabot_test.go | Updates tests to use after and validates pageInfo.nextCursor/hasNextPage behavior. |
| pkg/github/toolsnaps/list_dependabot_alerts.snap | Updates the tool input schema snapshot to remove page and add after. |
| README.md | Updates documented inputs for list_dependabot_alerts to replace page with after. |
|
Hey @MayorFaj thanks for your contribution - your fix looks great. Hope you don't mind, but I've pushed a small follow-up commit to your branch to tidy up a couple of things. I made the shared cursor pagination description generic so it works for both REST and GraphQL cursor-based tools, and moved the shared pageInfo helper out of the projects-specific code. |
Thanks @RossTarrant |
github-mcp-server 1.3.0 Created-by: HarmonybrewBot Commit-by: HarmonybrewBot Merged-by: HarmonybrewBot Description: Created by `brew bump` --- Created with `brew bump-formula-pr`.<details> <summary>release notes</summary> <pre>## What's Changed **Highlights** - `get_commits` added as a method to the pull request write tool - `get_file_blame` added to `insiders` mode - Surfacing rate limit error messages to agents properly ### Changes * Send update_issue_suggestions feature flag for set_issue_fields mutation by @boazreicher in github/github-mcp-server#2638 * Fix GraphQL call using the wrong case for method derivation by @moritzheiber in github/github-mcp-server#2660 * Update title annotations for `issue_write` and `add_issue_comment` tools to reflect that they also work with pull requesta by @timrogers in github/github-mcp-server#2664 * feat: implement cursor pagination for dependabot alerts by @MayorFaj in github/github-mcp-server#2651 * Annotate read tools with ifc labels by @JoannaaKL in github/github-mcp-server#2671 * build(deps): bump hono from 4.12.19 to 4.12.23 in /ui in the npm_and_yarn group across 1 directory by @dependabot[bot] in github/github-mcp-server#2606 * build(deps): bump golang from 1.25.10-alpine to 1.25.11-alpine by @dependabot[bot] in github/github-mcp-server#2597 * errors: improve rate limit error messages for AI agents by @danmoseley in github/github-mcp-server#2386 * feat: Add get_commits method to pull_request_read by @RossTarrant in github/github-mcp-server#2608 * build(deps): bump node from `7c6af15` to `144769e` by @dependabot[bot] in github/github-mcp-server#2598 * fix: hide write UI resources in read-only mode by @he-yufeng in github/github-mcp-server#2612 * feat: add get_file_blame tool for retrieving git blame information by @MayorFaj in github/github-mcp-server#1538 * Add Visual Studio one-click install badges by @prasethu in github/github-mcp-server#2085 ## New Contributors * @moritzheiber made their first contribution in github/github-mcp-server#2660 * @danmoseley made their first contribution in github/github-mcp-server#2386 * @prasethu made their first contribution in github/github-mcp-server#2085 **Full Changelog**: https://github.com/github/github-mcp-server/compare/v1.2.0...v1.3.0</pre> <p>View the full release notes at <a href="https://github.com/github/github-mcp-server/releases/tag/v1.3.0">https://github.com/github/github-mcp-server/releases/tag/v1.3.0</a>.</p> </details> <hr> See merge request: Harmonybrew/homebrew-core!11296
Summary
Why
Fixes #2649 #2648
What changed
Fixes
list_dependabot_alertspagination by switching it from page-based pagination to cursor-based pagination.pageparameter fromlist_dependabot_alerts.afterandperPage.pageInfo, so callers can usepageInfo.nextCursorfor the next page.MCP impact
Prompts tested (tool changes only)
Security / limits
Tool renaming
deprecated_tool_aliases.goNote: if you're renaming tools, you must add the tool aliases. For more information on how to do so, please refer to the official docs.
Lint & tests
./script/lint./script/testDocs