-
Notifications
You must be signed in to change notification settings - Fork 630
Pull requests: IBM/mcp-context-forge
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
feat: Add E2E test infrastructure for PII filter plugin
#4370
opened Apr 21, 2026 by
prakhar-singh1928
Collaborator
Loading…
3 of 10 tasks
fix(security): sanitize API validation error messages to prevent information disclosure
observability
Observability, logging, monitoring
security
Improves security
SHOULD
P2: Important but not vital; high-value items that are not crucial for the immediate release
#4368
opened Apr 21, 2026 by
bogdanmariusc10
Collaborator
Loading…
5 of 10 tasks
chore: update CI uv action and linted YAML
#4364
opened Apr 21, 2026 by
lucarlig
Collaborator
Loading…
2 of 10 tasks
fix(logging): respect LOG_LEVEL environment variable in plugin logging configuration
observability
Observability, logging, monitoring
plugins
SHOULD
P2: Important but not vital; high-value items that are not crucial for the immediate release
feat(runtime): enhance request validation and size limiting
ica
ICA related issues
MUST
P1: Non-negotiable, critical requirements without which the product is non-functional or unsafe
ready
Validated, ready-to-work-on items
release-fix
Critical bugfix required for the release
#4362
opened Apr 21, 2026 by
MohanLaksh
Collaborator
Loading…
fix(rpc): return -32601 for unknown JSON-RPC methods instead of -32000
bug
Something isn't working
mcp-protocol
Alignment with MCP protocol or specification
#4356
opened Apr 21, 2026 by
shoummu1
Collaborator
Loading…
4 tasks done
[Security][ICACF-16] Strengthen account lockout to prevent brute-force attacks
#4348
opened Apr 20, 2026 by
MohanLaksh
Collaborator
Loading…
8 tasks done
feat: implement dark/light mode theme toggle
#4347
opened Apr 20, 2026 by
vishu-bh
Collaborator
Loading…
fix: Move JWT from the session storage to cookie
#4345
opened Apr 20, 2026 by
gcgoncalves
Collaborator
Loading…
5 of 10 tasks
feat(security): implement UAID cross-gateway auth forwarding and fail-closed allowlist (closes #4236)
#4342
opened Apr 20, 2026 by
rakdutta
Collaborator
Loading…
fix(security): prevent admin bypass from accessing private resources
api
REST API Related item
MUST
P1: Non-negotiable, critical requirements without which the product is non-functional or unsafe
rbac
Role-based Access Control
security
Improves security
#4341
opened Apr 20, 2026 by
bogdanmariusc10
Collaborator
Loading…
5 of 10 tasks
fix(security): add comprehensive input validation to all router query parameters
api
REST API Related item
MUST
P1: Non-negotiable, critical requirements without which the product is non-functional or unsafe
security
Improves security
#4337
opened Apr 20, 2026 by
bogdanmariusc10
Collaborator
Loading…
3 of 10 tasks
fix(security): block URL-encoded injection patterns in SecurityValidator.validate_url()
api
REST API Related item
MUST
P1: Non-negotiable, critical requirements without which the product is non-functional or unsafe
security
Improves security
#4335
opened Apr 20, 2026 by
bogdanmariusc10
Collaborator
Loading…
5 of 10 tasks
[ICACF-15] Restrict gateway test endpoint to approved hosts - SSRF protection
bug
Something isn't working
enhancement
New feature or request
security
Improves security
#4329
opened Apr 20, 2026 by
MohanLaksh
Collaborator
Loading…
9 tasks done
fix(auth): resolve proxy auth database lookup for team/admin context
api
REST API Related item
MUST
P1: Non-negotiable, critical requirements without which the product is non-functional or unsafe
rbac
Role-based Access Control
chore(tests): remove plugin integration tests migrated to cpex-plugins
chore
Linting, formatting, dependency hygiene, or project maintenance chores
plugins
testing
Testing (unit, e2e, manual, automated, etc)
fix: enable MCP session pool and set max sessions per key to resolve stateful MCP server session isolation
#4283
opened Apr 17, 2026 by
Lang-Akshay
Collaborator
•
Draft
fix: rewrite bare /mcp to /mcp/ in MCPPathRewriteMiddleware so stream…
#4282
opened Apr 17, 2026 by
omorros
Contributor
Loading…
4 of 10 tasks
fix(sso): generic OIDC providers can now promote users to platform_admin
#4277
opened Apr 17, 2026 by
marekdano
Collaborator
Loading…
feat: add detailed plugin violation information to OTEL spans
#4272
opened Apr 17, 2026 by
vishu-bh
Collaborator
Loading…
6 tasks done
fix(testing): playwright admin_api fixture to stop duplicating JWT auth, fix linting
#4265
opened Apr 17, 2026 by
marekdano
Collaborator
Loading…
1 of 11 tasks
bugfix/3825-playwright-htmx-dom-detach
#4264
opened Apr 17, 2026 by
Nayana-R-Gowda
Collaborator
Loading…
4 tasks done
fix: clean up server_tool_association before tool deletion
bug
Something isn't working
ica
ICA related issues
release-fix
Critical bugfix required for the release
#4263
opened Apr 17, 2026 by
madhav165
Collaborator
Loading…
3 tasks done
Previous Next
ProTip!
Type g p on any issue or pull request to go back to the pull request listing page.