Repository navigation
Releases: SanthoshSiddegowda/bugzilla-mcp
Release list
v0.6.0
Install it on your machine
Bugzilla MCP now runs locally, so your Bugzilla API key never leaves your computer. It still starts read-only.
| Where | How |
|---|---|
| Claude Desktop | Download bugzilla-mcp.mcpb below and double-click it. Fill in your Bugzilla URL and API key (stored as a secret). Untick Read-only to allow changes. No Python needed. |
| Claude Code | claude mcp add bugzilla --scope user -e BUGZILLA_URL=https://bugzilla.example.com -e BUGZILLA_API_KEY=your-key -- uvx bugzilla-mcp |
| Cursor, VS Code, others | "command": "uvx", "args": ["bugzilla-mcp"] with BUGZILLA_URL and BUGZILLA_API_KEY in env |
| pip | pip install bugzilla-mcp, then run bugzilla-mcp |
Add --allow-writes (or BUGZILLA_READ_ONLY=false) to enable tools that change Bugzilla. bugzilla-mcp --transport http runs it as a multi-user HTTP server.
The hosted server (https://bugzilla.fastmcp.app/mcp) is still there for trying it out, but your key passes through it, so install locally for real use.
✨ New
bugzilla-mcpcommand on PyPI: stdio by default,--transport http,--allow-writes,--version. The API key is only read from the environment or.env, never from a flag.- One-click Claude Desktop extension (
.mcpb), attached to every release. - Python 3.14 supported and tested.
⬆️ fastmcp 4
- Now requires
fastmcp>=4.0.11,<5(built on MCP Python SDK v2). The server speaks both the session-based protocol (Claude Desktop,mcp-remote) and the new sessionless one. - No tool changes: names, parameters and read-only behaviour are the same as v0.5.0.
🔧 Under the hood
- Builds with
uv_build.LICENSEships in the package. - Releases publish to PyPI through Trusted Publishing (no stored tokens). The workflow refuses to publish if the tag,
pyproject.tomlandmanifest.jsonversions disagree.
Full changelog: v0.5.0...v0.6.0
v0.5.0
⚠️ Breaking change: read-only by default
The server now starts in read-only mode. Tools that change Bugzilla (update_bug, create_bug, add_comment, upload_attachment, tag_comment) are hidden and refused until you turn writes on:
| Server | Enable write tools |
|---|---|
Hosted (https://bugzilla.fastmcp.app/mcp) |
Send the header read_only: false |
| Claude Code | add --header "read_only: false" to claude mcp add |
Claude Desktop (mcp-remote) |
add "--header", "read_only:false" to args |
Local stdio (server_local.py) |
BUGZILLA_READ_ONLY=false |
Reading tools work exactly as before. If an assistant tries a write tool in read-only mode, the error says how to enable it.
✨ New Features
- Read-only mode (#15), plus
BUGZILLA_DISABLED_TOOLS=update_bug,create_bugto remove individual tools. update_bug(dry_run=True)returns the planned changes and each bug's current values without changing anything. Use it before bulk updates.bug_info(include_fields=[...])fetches only the fields you need.- Flexible parameters: search filters and bug ids accept one value or a list (
status: "NEW"or["NEW", "ASSIGNED"]), and parameters now have descriptions with examples.status: "CONFIRMED"no longer fails schema validation.
🔒 Security
- The hosted server no longer registers
download_attachment(s)at all. Saving to disk is only offered by the local server.
🧹 Maintenance
- Removed duplicated client and tool plumbing, with no tool changes (#13).
📚 Docs
- Restored doc fixes from #9 that never reached
main: corrected hosted-server security claims, install steps, API key guidance and the Deprecations section (#14). The v0.4.0 notes listed these. - All 28 tools documented, including the local stdio server setup (#14).
- Read-only mode, dry run, triage rules for
classify_bugs_heuristics, license and GitHub link (#15).
Full changelog: v0.4.0...v0.5.0
v0.4.0
🔒 Security
- Per-request credentials: concurrent users on the hosted server could use each other's API key and Bugzilla URL. Each request now gets its own client (#10).
- API key out of URLs: sent as the
X-BUGZILLA-API-KEYheader where Bugzilla supports it (BMO, Bugzilla master). Stock 5.0/5.2 fall back to?api_key=(deprecated, nothing breaks) (#10). - No server file access on hosted:
upload_attachment(file_path)anddownload_attachment(s)only work in the local server (server_local.py) (#11, #12).
✨ New Features
- 21 new tools (thanks @Darshitpipariya, #8):
update_bug,create_bug,bug_history,bugs_info,bugs_advanced_search, users, products, comment tags, and more. bug_attachments/get_attachment: screenshots come back as images, logs/patches as text.upload_attachmenttakestextordata_base64.- Compact
bug_infoby default (drops empty fields andupdate_token);full=Truefor everything. - Tool hints (
readOnlyHint/destructiveHint) so clients ask beforeupdate_bug. - Local stdio server (
server_local.py) reading credentials from env vars.
🐛 Bug Fixes
create_bugtreated Bugzilla's 201 as failure, causing duplicate bugs on retry.upload_attachmentalways returnedattachment_id: None.- Trailing slash in
bugzilla_urlbroke requests. bugs_commentshid failures as empty comment lists.
📚 Docs
- Claude Code setup; fixed Claude Desktop config (needs
mcp-remote) (#9). - Corrected security claims, install steps, and API key guidance.
- Deprecations section.
Full changelog: v0.3.0...v0.4.0
v0.3.0
✨ New Features
- GitHub Actions CI/CD: Automated testing workflow for continuous integration
- Runs tests on Python 3.12 and 3.13
- Automated test coverage reporting
- Tests run on every push and pull request
🧪 Testing Improvements
- Comprehensive Unit Test Coverage: Achieved 100% test coverage
- Full test coverage for all Bugzilla tools
- Complete middleware test suite
- Comprehensive utility function tests
- Fixed async mock warnings in test suite
- Improved test reliability and maintainability
🔧 Code Quality
- Code Review Fixes: Improved code organization
- Fixed import ordering per code review feedback
- Enhanced code consistency
📊 Project Badges
- Added test status badge to README
- Added license badge
- Added Python version badge
- Added code style badge
🐛 Bug Fixes
- Fixed async coroutine warnings in test suite
- Improved async mock handling in middleware tests
- Enhanced test fixture reliability
📚 Documentation
- Updated README with project badges
- Improved project visibility with status indicators
Migration Notes
No breaking changes in this release. This is a maintenance and quality improvement release.
Upgrading from v0.2.0:
- No action required
- All existing configurations remain compatible
- Improved test coverage ensures better reliability
Full Changelog: v0.2.0...v0.3.0
What's Changed
- Acknowledge cursor.store listing notification by @Copilot in #4
- Add comprehensive unit test coverage for Bugzilla MCP components by @Copilot in #5
New Contributors
- @Copilot made their first contribution in #4
v0.2.0
🎉 New Features
-
Documentation Site: Added comprehensive documentation site built with Nuxt.js
- Getting started guide
- Installation instructions
- Configuration details
- Usage examples
- Security best practices
- Deployed and accessible via Vercel
-
Enhanced Error Handling: Improved error messages across all Bugzilla tools
- Better validation for uninitialized Bugzilla client
- More descriptive error messages for debugging
- Consistent error handling pattern across all tools
🐛 Bug Fixes
-
Fixed MCP Error Handling: Resolved issue where MCP server was throwing "object none" errors
- Added proper null checks for Bugzilla client initialization
- Improved error messages to guide users on proper configuration
- All tools now properly validate client state before execution
-
Vercel Route Configuration: Fixed routing configuration for production deployment
- Corrected route handling for Vercel deployment
- Ensured proper API endpoint accessibility
📚 Documentation Improvements
- Updated README with clearer configuration examples
- Added comprehensive documentation site with detailed guides
- Improved setup instructions for different MCP clients (Claude Desktop, Cursor IDE, VS Code)
- Added security best practices section
🔧 Technical Improvements
- Enhanced error handling in
bugzilla_mcp/tools/bugzilla.py - Improved code consistency across all tool functions
- Better exception handling with descriptive error messages
📦 Dependencies
- No breaking changes to dependencies
- Compatible with existing MCP client configurations
Migration Notes
No breaking changes in this release. Existing configurations will continue to work without modification.
If you're upgrading from 0.1.0:
- No action required
- All existing API keys and configurations remain valid
- New error messages may provide better feedback if configuration issues exist
Contributors
Thank you to all contributors who helped improve this release!
v0.1.0
Release v0.1.0 - Initial Release
🎉 First Stable Release
This is the initial stable release of the Bugzilla MCP Server, a Model Context Protocol server that enables secure interaction with Bugzilla instances.
✨ Features
- Query Bug Information: Retrieve complete details about any bug by ID
- Search Bugs: Use Bugzilla's powerful quicksearch syntax to find bugs
- Manage Comments: Add public or private comments to bugs
- Secure Access: API key-based authentication through HTTP headers
- Comprehensive Error Handling: Robust error handling for reliable operation
- Full Documentation: Complete documentation site with usage examples
🛠️ Available Tools
bug_info- Get complete information about a bugbug_comments- Retrieve comments for a bug (with optional private comments)add_comment- Add comments to bugs (public or private)bugs_quicksearch- Search bugs using Bugzilla's quicksearch syntaxlearn_quicksearch_syntax- Access Bugzilla's quicksearch documentationserver_url- Get your Bugzilla instance base URLbug_url- Generate direct links to specific bugs
🚀 Quick Start
Hosted Server: Use the production server at https://bugzilla.fastmcp.app/mcp - no local setup required!
Just add it to your MCP client configuration with your Bugzilla API key and instance URL.
📦 Installation
# Using uv (recommended)
uv sync
uv run python server.py
# Or with standard Python
pip install fastmcp httpx python-dotenv
python server.py📚 Documentation
Full documentation is available at: Documentation Site
🔒 Security
- API key-based authentication
- Minimal permission requirements
- Secure header-based configuration
- Follows security best practices
🙏 Acknowledgments
This project was inspired by Sai Karthik's mcp-bugzilla project.
📄 License
Apache 2.0 License - see LICENSE file for details.