Skip to content

feat: Add GitHub Packages toolset - #1209

Open
MayorFaj wants to merge 2 commits into
github:mainfrom
MayorFaj:feature/github-packages-support
Open

MayorFaj wants to merge 2 commits into
github:mainfrom
MayorFaj:feature/github-packages-support

Conversation

@MayorFaj

@MayorFaj MayorFaj commented Oct 12, 2025 •

Copy link
Copy Markdown
Contributor

This PR adds an opt-in packages toolset for GitHub Packages, with two consolidated tools.

Closes #1208

Tools

packages_read (read-only, requires read:packages)

Method Owner
list_org_packages, get_org_package, list_org_package_versions, get_org_package_version org
list_user_packages, get_user_package, list_user_package_versions, get_user_package_version username, or the authenticated user when omitted

The list methods support the package_type and visibility filters (packages), the state filter (versions), and page/perPage.

packages_write (destructiveHint: true, requires read:packages + delete:packages)

delete_org_package, delete_org_package_version, delete_user_package, delete_user_package_version

Notes for review

  • Opt-in: packages is not added to the default toolset.
  • New scope: this adds a delete:packages scope to pkg/scopes. It is not requested by default (same treatment as delete_repo), so it is only requested through a per-tool scope challenge.
  • No elicitation on delete: deletes don't use the delete_repository elicitation flow. Deleted packages and versions can be restored for 30 days, and the other delete operations here (issues, discussion comments) rely on destructiveHint. Happy to add confirmation if you'd prefer.
  • Other-user version listing: go-github's Users.ListUserPackageVersions doesn't accept list options, so listing another user's package versions builds the request directly to pass state/page/per_page. I verified that the endpoint honors them.
  • No IFC labels: there's no existing package label in pkg/ifc. I can add one as a follow-up if wanted.
  • No download stats: download counts are not exposed by the REST API, so they aren't returned.

Testing

  • go test ./... and script/lint pass. Toolsnaps and docs are regenerated with UPDATE_TOOLSNAPS=true / script/generate-docs.
  • Live-tested a local build over stdio:
    • org methods against kgateway-dev, including pagination, filters, and slash-containing names like charts/kgateway
    • user methods against public user packages, plus the authenticated user
    • delete paths against non-existent packages, which return a 404
    • --read-only, which hides packages_write

Note: Download statistics are not available through the GitHub REST API and are not included in responses, though they are visible on the GitHub web interface.

Closes: #1208
Screenshot 2025-10-12 at 20 06 47

Copilot AI review requested due to automatic review settings October 12, 2025 19:09
@MayorFaj
MayorFaj requested a review from a team as a code owner October 12, 2025 19:09

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR introduces a comprehensive GitHub Packages toolset to the GitHub MCP Server, enabling management and retrieval of package information for both organizations and users. The addition provides nine package-related operations including listing, retrieving details, and deletion capabilities for packages and their versions.

  • Adds a new "packages" toolset with read/write operations for managing GitHub packages
  • Implements comprehensive test coverage for all package operations with proper error handling scenarios
  • Updates documentation to include the new packages toolset with detailed tool descriptions

Reviewed Changes

Copilot reviewed 14 out of 14 changed files in this pull request and generated no comments.

Show a summary per file
File Description
pkg/github/tools.go Adds packages toolset metadata and integrates it into the default toolset group
pkg/github/packages.go Implements all package-related operations with proper error handling and API interactions
pkg/github/packages_test.go Comprehensive test suite covering all package operations with success and error scenarios
pkg/github/toolsnaps/*.snap Generated tool snapshots for all package operations with proper schema definitions
docs/remote-server.md Documents the new packages toolset with installation links
README.md Updates toolset list and adds detailed package tool documentation

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

@MayorFaj

Copy link
Copy Markdown
Contributor Author
Screenshot 2025-10-12 at 20 14 25

Comment thread pkg/github/__toolsnaps__/delete_org_package.snap Outdated
@github-actions github-actions Bot added the stale label Sep 7, 2026
Add the delete:packages scope to the supported OAuth scope catalog
without requesting it by default, so it is only requested through a
per-tool scope challenge when package deletion is used.
Add an opt-in "packages" toolset with two consolidated tools:

- packages_read: list/get packages and package versions for
  organizations and users (the authenticated user when username is
  omitted), with package_type/visibility/state filters and pagination.
- packages_write: delete packages or individual package versions for
  organizations and users. Marked destructive and requires
  read:packages and delete:packages.

Closes github#1208
@MayorFaj
MayorFaj force-pushed the feature/github-packages-support branch from 32e6b97 to c8a0139 Compare October 4, 2026 17:44
@MayorFaj

MayorFaj commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

@SamMorrowDrums PTAL

@github-actions github-actions Bot removed the stale label Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add GitHub Packages Support to MCP Server

4 participants