Skip to content

Releases: Blacksp1d3r/runner-mcp

Runner MCP v0.1.2

Runner MCP v0.1.2 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 27 Sep 04:34
83175f4

What's Changed

Full Changelog: v0.1.0...v0.1.2

Runner MCP v0.1.0 — First Alpha

Pre-release

Choose a tag to compare

@Blacksp1d3r Blacksp1d3r released this 24 Sep 18:16

Runner MCP v0.1.0 — First Alpha

The first public alpha release of Runner MCP.

Runner MCP is a security-first, self-hosted MCP server for controlled development and staging operations without exposing a general-purpose remote shell.

Highlights

  • deny-by-default operation model
  • bounded and auditable development operations
  • controlled testing and staging deployment workflows
  • backup, migration and rollback boundaries
  • secret and private-path redaction
  • bounded command and output handling
  • project-scoped configuration and policy
  • release artifact and clean-install validation
  • MIT licensed

Security model

Runner MCP intentionally does not provide arbitrary remote shell access.

Mutating and higher-risk operations are bounded by explicit capabilities, policy checks and approval boundaries. Secrets and private infrastructure details must remain outside repositories, logs and agent-visible output.

Validation

This release is based on normalized commit:

0d6dd66ab1c1db8298940763dc102d4f94ab4af8

On 2026-09-24, Git history metadata was normalized to remove AI-vendor commit attribution. The release source tree remained unchanged (69a1d2c49b45df1a1e1e638ee4db1bd5cda08295). The exact normalized release commit passed Runner MCP validation in workflow run #517, including:

  • Python compilation
  • Ruff
  • pytest
  • whitespace validation
  • release artifact build
  • clean five-minute demo

Alpha limitations

This is an alpha release and should not yet be treated as a fully production-hardened remote operations platform.

In particular:

  • full private-host live self-update/recovery fault-injection proof is not yet completed;
  • automatic connectivity provisioning remains operator-managed;
  • automatic retention pruning is not yet implemented;
  • restore/PITR capabilities remain deliberately bounded;
  • notification integrations may require separately managed private credentials;
  • untrusted public-fork workloads must not run on privileged self-hosted runners.

Please review the documentation and security model before using Runner MCP on important systems.

License

Runner MCP is released under the MIT License.