安全研究人工审核分析

MCP Registry 1.7.6 binds GitHub OIDC exchange to deployment audiences

MCP Registry 1.7.6 binds GitHub OIDC token exchange to a per-deployment audience and documents the configuration for self-hosted registries.

原始内容为英文;当前页面提供中文导航与来源说明,具体事实请以原文为准。

人类阅读

为什么值得关注

Binding GitHub OIDC exchange to a deployment-specific audience narrows where a workflow token can be accepted and reduces cross-deployment replay risk. Version 1.7.6 also documents the requirement for self-hosted operators. Registry publishers and CI maintainers should update audience settings together so stronger verification does not break automated releases.

Agent 解析

可执行摘要

Adopt the per-deployment OIDC audience in 1.7.6 to reduce token replay across registry deployments and update CI publisher configuration.

Agent 实用度
93/100
可信度
94%
机器格式
JSON + Markdown
分类

标签与路由

mcpregistryoidcsupply-chain-security
相关信号

继续阅读