# Reported issues for MCP Health Monitor by oaslananka

Pod holds 22 of 44 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to [MCP Health Monitor by oaslananka](/mcp/mcp-health-monitor-by-oaslananka).

## Most discussed

### [PACKAGING] Complete public release and npm distribution verification

## Problem
The repository declares `mcp-health-monitor@1.0.3`, but `npm view mcp-health-monitor` reports the package was unpublished on 2026-05-17, GitHub has no releases, and no `npm-production` environment exists. Impact: README install commands and public artifact verification do not work end-to-end.

## Required changes
Complete the release path: create/merge the release-please release PR or otherwise establish the intended release state, configure the `npm-production` environment required b

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/6) · 2026-05-26 · closed · 7 comments

### [SECURITY] Add SBOM, license compliance, Scorecard, and artifact verification gates

## Problem
The repo has CodeQL, Dependabot, secret scanning, Gitleaks, and release asset provenance, but no SBOM generation, REUSE/SPDX compliance check, license scanning, OpenSSF Scorecard target, or checksum verification policy beyond release assets. Impact: supply-chain evidence is incomplete for a public security/monitoring package.

## Required changes
Add SBOM generation, license/SPDX compliance scanning, OpenSSF Scorecard tracking, and artifact/checksum verification gates appropriate for 

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/11) · 2026-05-26 · closed · 6 comments

### [GOVERNANCE] Add templates, triage policy, support SLA, and label docs

## Problem
The repository has no issue templates, PR template, stale/triage policy, support policy, maintainer response SLA, or in-repo label taxonomy documentation. Discussions are disabled. Labels and a governance project were created during the audit, but the governance model is not yet documented or enforced in the repository. Impact: external contributors do not have a clear path for bugs, PRs, questions, or maintenance expectations.

## Required changes
Add GitHub issue forms/templates, a 

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/10) · 2026-05-26 · closed · 3 comments

### [DOCS] Add ADRs and generated API documentation workflow

## Problem
Major technical decisions are not captured as ADRs, and API documentation is configured (`typedoc.json`) but not generated or enforced in CI. The repository also lacks direct TypeDoc dependencies for that configuration. Impact: future maintainers cannot trace decisions around MCP transport policy, PAT encryption, SQLite schema, release workflow, or generated API surface.

## Required changes
Add ADRs for the main architectural/security/release decisions and wire generated API docs int

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/8) · 2026-05-26 · closed · 3 comments

### [P1] Harden Renovate, pre-commit security gates, and repository analysis integrations

## Context

The 2026-07-20 repository audit confirmed that Renovate, Snyk, and SonarQube Cloud are connected, but the repository-local controls are incomplete:

- `renovate.json` validates, yet it references labels that do not exist in the repository taxonomy and the Dependency Dashboard has not refreshed since 2026-07-07.
- `.pre-commit-config.yaml` currently runs only formatting, lint, and type checking.
- `SEMGREP_APP_TOKEN` exists, but no Semgrep GitHub Actions workflow is committed.
- The S

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/81) · 2026-07-20 · closed · 2 comments

### [P0] Restore v1.1.0 release integrity across source, npm, GitHub, GHCR, and MCP Registry

## Context

The current `main` branch contains substantial post-1.0.0 work, including stateful HTTP sessions, runtime hardening, registry/GHCR workflows, dependency changes, and agent-runtime packaging. However, `package.json`, `mcp.json`, and `server.json` still declare `1.0.0`; npm and the official MCP Registry also expose `1.0.0`.

A remote Release Please branch already contains a `1.1.0` version/changelog commit, but there is no open release pull request. The public release surfaces therefor

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/77) · 2026-07-20 · closed · 2 comments

### [P1] Add generic HTTP, TLS expiry, and response assertion monitoring

## Context

Not every dependency is an MCP server or CI pipeline. A practical monitor should validate HTTP endpoints, TLS expiry, status codes, latency, and response assertions.

## Scope

Add generic HTTP target registration, status/latency checks, TLS expiry checks, optional response assertions, and remote-safe SSRF policy.

## Acceptance criteria

- [ ] HTTP targets can be registered, checked, listed, and removed.
- [ ] TLS expiry threshold can alert before expiration.
- [ ] Response assertio

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/42) · 2026-06-24 · closed · 2 comments

### [P1] Improve Azure DevOps pipeline diagnostics, auth failures, rate limits, and log classification

## Context

Azure support works, but failed builds and API errors need better classification than raw status and short log tails.

## Scope

Classify auth, permission, not-found, throttling, timeout, malformed response, and failed-step cases. Add stable error codes and remediation hints.

## Acceptance criteria

- [ ] `check_pipeline_status` reports structured failure categories.
- [ ] `get_pipeline_logs` includes failed step metadata and bounded excerpts.
- [ ] Tests cover 401, 403, 404, 429, 5

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/39) · 2026-06-24 · closed · 2 comments

## Most recent

### [P0] Enforce MCP Registry description length before release publication

## Problem

The `health-monitor-mcp-v1.2.0` release successfully published npm, GHCR, release assets, SBOMs, and provenance, but the official MCP Registry rejected `server.json` with HTTP 422 because `description` exceeded the registry's 100-character limit.

Current validation checks namespace, version, and package consistency but does not enforce this official Registry constraint before release publication.

## Required remediation

- shorten the public MCP/server description to at most 100 ch

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/103) · 2026-07-22 · closed · 0 comments

### [P1] Make release verification portable and registry publishing reusable

## Context

The v1.1.0 release completed successfully across npm, GHCR, GitHub Release assets, and the official MCP Registry, but two orchestration defects were exposed during independent verification:

1. The reusable MCP Registry workflow checked `github.event_name == 'workflow_call'`. Reusable workflows preserve the caller event (`release` here), so the called publish job was skipped and required the documented manual recovery dispatch.
2. `scripts/verify-npm-package.mjs` compared registry SR

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/93) · 2026-07-21 · closed · 0 comments

### [P3] Review MCP 2026 transport changes and TypeScript SDK v2 migration readiness

## Context

The current production package correctly uses `@modelcontextprotocol/sdk` v1.x. The official TypeScript SDK keeps v1.x as the recommended production line while v2 remains pre-alpha, with the next MCP specification scheduled for 2026-07-28.

The locked release candidate introduces breaking transport/runtime changes that are directly relevant to this repository, including removal of protocol-level sessions and `Mcp-Session-Id`, deterministic list ordering, standard routing headers, tra

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/79) · 2026-07-20 · open · 0 comments

### [P2] Bound concurrency for interactive batch checks and provider fan-out

## Context

The background scheduler respects `HEALTH_MONITOR_MAX_CONCURRENCY`, but interactive tools such as `check_all`, `check_all_projects`, and pipeline-group checks use broad `Promise.all`/`Promise.allSettled` fan-out. As the server and provider registry grows, one tool call can create an unbounded burst of child processes, network connections, SQLite writes, or provider API requests.

## Scope

- Extract a shared bounded-concurrency helper from the scheduler implementation.
- Apply the sa

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/78) · 2026-07-20 · closed · 1 comment

### [P1] Enforce bounded HTTP request-body consumption and request timeouts

## Context

`readRequestBody()` returns `413` after the configured 1 MiB limit is exceeded, but the request stream is not explicitly stopped or drained and later chunks can continue reaching the listener. A slow or oversized chunked request can therefore consume resources after the logical rejection point.

## Scope

- Reject oversized requests early when a valid `Content-Length` exceeds the limit.
- Stop buffering immediately after the byte limit is crossed.
- Drain or terminate the request saf

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/76) · 2026-07-20 · closed · 0 comments

### [P0] Prevent Azure DevOps PAT forwarding to untrusted log URLs

## Context

`getPipelineLogs()` consumes log URLs returned by the Azure DevOps timeline API and sends the Azure PAT-derived `Authorization` header to those URLs. The current path does not enforce an HTTPS/trusted-origin policy and relies on default fetch redirect behavior.

A malformed, compromised, or unexpectedly redirected log URL must not be able to move Azure credentials outside the intended trust boundary.

## Scope

- Parse and validate every timeline log URL before attaching credentials.

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/75) · 2026-07-20 · closed · 0 comments

### [P0] Preserve MCP stdio protocol integrity by routing runtime logs to stderr

## Context

The stdio MCP transport reserves `stdout` for protocol messages. The current structured logger writes `debug` and `info` events with `console.log`, while `src/mcp.ts` can start the scheduler when `HEALTH_MONITOR_AUTO_CHECK=1`. Scheduler lifecycle and check-completion logs can therefore be interleaved with JSON-RPC traffic and corrupt the client connection.

## Impact

This is a release-blocking protocol-integrity defect for packaged stdio usage. It is most visible when automatic chec

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/74) · 2026-07-20 · closed · 0 comments

### [P2] Verify live branch protection, required checks, and Actions permissions

## Context

The repository documents required branch protection and workflow security settings, but live GitHub repository settings must be periodically verified because they are external to git history.

## Scope

- Verify `main` branch protection and required checks.
- Confirm required checks include Validate, Workflow Security, Docker Build, CodeQL Analysis, and Review Thread Gate as documented.
- Verify GitHub Actions permissions and selected action policy match repository security expectati

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/55) · 2026-06-24 · closed · 0 comments

### [P2] Verify npm trusted publishing, provenance, and external release settings

## Context

The publish workflow already uses OIDC-capable permissions, but npm trusted publisher settings live outside the repository and must be verified on npmjs.com. npm trusted publishing removes long-lived npm publish tokens and depends on the exact GitHub repository, workflow filename, environment, and supported runner model.

## Scope

- Verify npm trusted publisher settings for `health-monitor-mcp`.
- Confirm organization/user, repository, workflow filename, and environment name match `

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/54) · 2026-06-24 · closed · 0 comments

### [P2] Align roadmap, release state, runtime configs, and deployment documentation

## Context

The repository has moved beyond the original 1.0.0 documentation baseline. npm and the official MCP Registry are live, the source tree contains post-1.0 runtime and packaging work, Node 24 is the declared runtime floor, and new GitHub milestones now define the forward roadmap.

Several user-facing surfaces still describe the first release as pending or use inconsistent runtime commands and deployment examples.

## Scope

- Update `ROADMAP.md` to reflect the live milestone structure a

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/53) · 2026-06-24 · closed · 1 comment

### [P2] Triage stale remote branch origin/10-governance-templates before deleting or merging

## Context

Remote branch `origin/10-governance-templates` is not merged into main and its diff removes many currently valuable governance, docs, release, and security files. It should not be blindly merged.

## Scope

Determine whether the branch is obsolete, delete it if superseded, or cherry-pick only safe commits into a clean PR.

## Acceptance criteria

- [ ] Maintainer decision is recorded.
- [ ] Branch is deleted or converted into a clean PR with minimal diff.
- [ ] Governance/security/re

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/52) · 2026-06-24 · closed · 0 comments

### [P2] Improve agent-facing tool descriptions, structured errors, and remediation hints

## Context

Tool names are usable, but agents benefit from sharper prerequisites, deterministic error codes, and remediation hints.

## Scope

Expand tool descriptions, add stable error codes/remediation hints, standardize output schemas across health, pipeline, alert, and provider tools.

## Acceptance criteria

- [ ] Common failures return stable codes.
- [ ] Tool descriptions distinguish HTTP, SSE, and stdio.
- [ ] Usage docs include agent-oriented examples.
- [ ] Tests assert important error

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/51) · 2026-06-24 · closed · 1 comment

### [P2] Define multi-user workspace, RBAC, and audit-log architecture

## Context

The current architecture is local, single-user, and SQLite-backed. Remote or shared deployments need an authenticated principal model, workspace isolation, role-aware tool access, per-user credentials, and durable audit trails.

The existing static bearer token is suitable for private single-operator deployments, but it does not provide standards-based identity, scopes, principal propagation, or tenant isolation for a public/shared MCP HTTP service.

## Scope

- Define workspace, use

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/50) · 2026-06-24 · open · 0 comments

### [P2] Design external secret providers, key rotation, and credential recovery model

## Context

PAT encryption exists, and webhook secrets will need the same or stronger protection. Shared deployments need external secret provider options and rotation.

## Scope

Design a provider abstraction, key rotation/re-encryption flow, missing-key recovery, audit events, and write an ADR before implementation.

## Acceptance criteria

- [ ] ADR documents provider model, threat model, and migration strategy.
- [ ] Rotation can be performed without losing registered providers.
- [ ] Failed

[Read the thread](https://github.com/oaslananka/health-monitor-mcp/issues/49) · 2026-06-24 · open · 0 comments

The remaining reports are on [the project's issue tracker](https://github.com/oaslananka/health-monitor-mcp/issues).
