Skip to content

mcpc: link only mcpc, drop libsecret, fix strict audit - #59

Merged
jancurn merged 1 commit into
mainfrom
claude/stoic-dirac-5q2frq
Oct 3, 2026
Merged

jancurn merged 1 commit into
mainfrom
claude/stoic-dirac-5q2frq

Conversation

@jancurn

@jancurn jancurn commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

Refs apify/mcpc#435

  • Use formula_opt_bin("node") to fix brew audit --strict.
  • Link only mcpc into bin. mcpc starts its bridge with node dist/bridge/index.js, never as mcpc-bridge. The shebang rewrite still covers every file in the package's bin/, so it works once mcpc-bridge is removed.
  • Drop libsecret on Linux. The prebuilt keyring addon talks to D-Bus directly and doesn't link libsecret.

The update workflow only rewrites url/sha256, so it won't undo these changes.

Checks run on Linux: brew style, brew install --build-from-source, brew test and brew audit --strict all passed, and mcpc-bridge isn't in $(brew --prefix)/bin. Not run on macOS.

🤖 Generated with Claude Code

https://claude.ai/code/session_017YGopmusCEniC5NmoxTyAA

- Use formula_opt_bin("node") instead of Formula["node"].opt_bin
  (brew audit --strict).
- Symlink only bin/mcpc into the prefix. mcpc starts its bridge as
  `node dist/bridge/index.js` and never runs mcpc-bridge by name, and the
  executable is being removed upstream (apify/mcpc#435). The shebang
  rewrite still globs the package's bin/ so it keeps working once
  mcpc-bridge is gone.
- Drop the Linux libsecret dependency: the prebuilt @napi-rs/keyring addon
  talks to D-Bus directly and does not link libsecret.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017YGopmusCEniC5NmoxTyAA
@jancurn
jancurn requested a balanced review from Copilot October 3, 2026 20:19
@jancurn
jancurn merged commit c2db958 into main Oct 3, 2026
3 checks passed
@jancurn
jancurn deleted the claude/stoic-dirac-5q2frq branch October 3, 2026 20:20

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The absence of mcpc-bridge should be protected by an automated formula-test assertion.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Updates the mcpc formula to match upstream bridge packaging and satisfy strict Homebrew audits.

Changes:

  • Exposes only the mcpc executable.
  • Removes the unnecessary Linux libsecret dependency.
  • Uses Homebrew’s audited Node path helper.
File Description
Formula/​mcpc.rb Updates dependencies, executable linking, and Node test invocation.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread Formula/mcpc.rb
bin.install_symlink libexec.glob("bin/*")
# Only mcpc goes on PATH: it starts its bridge as `node dist/bridge/index.js`
# and never runs mcpc-bridge by name.
bin.install_symlink libexec/"bin/mcpc"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants