feat(mcp): Add semantic Docker query tools - #534
Merged
Merged
Conversation
SafeDep Report SummaryNo dependency changes detected. Nothing to scan. This report is generated by SafeDep Github App |
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #534 +/- ##
==========================================
+ Coverage 82.75% 82.87% +0.11%
==========================================
Files 133 133
Lines 15666 16102 +436
==========================================
+ Hits 12965 13345 +380
- Misses 2221 2267 +46
- Partials 480 490 +10 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
Extend MCP's find_symbol tool to recognize Docker node types, enabling basic Docker file queries through the existing MCP infrastructure. Changes: - Add dockerfile_instruction and compose_service to validTypes map - Add LSP Symbol Kind mapping for Docker types (Constant=14, Module=2) - Include Docker statistics in get_index_info response - Add comprehensive unit tests with 95.4% coverage - Create test fixtures for integration testing This enables: - Querying Dockerfile instructions via find_symbol(type="dockerfile_instruction") - Querying docker-compose services via find_symbol(type="compose_service") - Docker statistics in index info (docker_instructions, compose_services) Foundation for PR-02 (semantic Docker queries) and PR-03 (dependency graph). Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Implements three new MCP tools for advanced Docker configuration analysis: 1. find_dockerfile_instructions - Semantic Dockerfile queries - Instruction-specific filtering (FROM, USER, EXPOSE, etc.) - Security analysis (unpinned images, root users) - Parsed details (base_image, tag, digest, user, port, etc.) 2. find_compose_services - Docker Compose service queries - Configuration filtering (privileged, port, volume) - Security risk analysis (CRITICAL/HIGH/MEDIUM/LOW) - Detects: Docker socket exposure, host network, dangerous caps 3. get_dockerfile_details - Complete Dockerfile breakdown - Multi-stage build analysis - Security summary with risk assessment - All instructions with parsed details Implementation: - Added 10 parsing helper functions (parseFromInstruction, etc.) - Added 3 tool implementations (~500 lines) - Added 3 tool definitions with comprehensive docs - Wired up tool dispatch in executeTool() Testing: - Created tools_docker_semantic_test.go with 11 test functions - 100% test pass rate - 94.5% code coverage - Tests cover: basic queries, filters, security analysis, parsing Security Features: - CWE-1188 detection (unpinned images) - Root user detection (HIGH risk) - Privileged container detection (CRITICAL risk) - Docker socket exposure detection (CRITICAL risk) - Host network mode detection (HIGH risk) - Dangerous capability detection (HIGH risk) Related: PR-01 (basic Docker MCP support) Next: PR-03 (dependency graph analysis) Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Remove automatic security analysis features that were not requested: - Removed security_issue and risk_level from Dockerfile instructions - Removed security_issues and risk_level from compose services - Renamed security_summary to summary in get_dockerfile_details - Removed issues and risk_level calculations Changes: - buildDockerInstructionMatch: Returns parsed details only - buildComposeServiceMatch: Returns configuration only - get_dockerfile_details: Returns summary stats without risk scoring - Updated tool descriptions to remove security analysis mentions - Updated all tests to remove security assertions - Fixed linter issues (godot, gocritic) The tools now provide semantic filtering and parsed details without opinionated security scoring, allowing users to apply their own security policies and risk thresholds. Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
shivasurya
force-pushed
the
pr-02-semantic-docker-queries
branch
from
February 16, 2026 03:11
fc1e033 to
b51d043
Compare
shivasurya
force-pushed
the
pr-01-docker-mcp-basic-support
branch
from
February 16, 2026 03:11
ed049da to
1014ea8
Compare
Owner
Author
This stack of pull requests is managed by Graphite. Learn more about stacking. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.




Adds three semantic Docker MCP tools for advanced configuration filtering.
Stacked on: #531 (PR-01)
Tools Added
find_dockerfile_instructions- Semantic Dockerfile queries with instruction-specific filtersfind_compose_services- Docker Compose service filteringget_dockerfile_details- Complete Dockerfile breakdown with multi-stage analysisFeatures
Semantic Filtering:
Parsed Details:
Examples
Find unpinned base images:
{"tool": "find_dockerfile_instructions", "arguments": {"instruction_type": "FROM", "has_digest": false}}Find privileged containers:
{"tool": "find_compose_services", "arguments": {"has_privileged": true}}Get complete Dockerfile breakdown:
{"tool": "get_dockerfile_details", "arguments": {"file_path": "/app/Dockerfile"}}Testing
🤖 Generated with Claude Code