You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Two Docker-image dependency updates detected and applied on 2026-06-28. Both are clean single-version bumps published on 2026-06-27 with no intermediate releases.
Tool
Old
New
Published
Risk
GitHub MCP Server
v1.4.0
v1.5.0
2026-06-27
Low
MCP Gateway (gh-aw-mcpg)
v0.3.30
v0.3.31
2026-06-27
Low
All other monitored tools are already at latest: Claude Code 2.1.195, Copilot CLI 1.0.65, Copilot SDK 1.0.4, Codex 0.142.3, Pi 0.80.2, Playwright MCP 0.0.76, Playwright CLI 0.1.14, Playwright Browser v1.61.1.
Impact on gh-aw: The GitHub MCP server in gh-aw runs in lockdown/read-only mode and is consumed as a pinned Docker image. New reaction and issue-dependency tools expand capability without breaking existing read paths. The legacy issue-write deprecation is the only item to monitor, but gh-aw uses safe-outputs (not the MCP write tools) for GitHub writes, so impact is minimal.
Full v1.5.0 changelog
Highlights: STDIO OAuth (no PAT), react to issue/PR comments, parent issues via issue_read, MCP App shows labels/milestones.
Schema URL pinned to gh-aw versions v0.81.3 and v0.81.5
Impact on gh-aw: MCP Gateway is the default sandbox.agent container. The DIFC GHEC data-residency host-derivation fix and issue-dependency guard fixes improve correctness for enterprise/data-residency setups. The jsonschema v5→v6 migration is internal; no config-surface changes observed. Low risk.
Overview
Two Docker-image dependency updates detected and applied on 2026-06-28. Both are clean single-version bumps published on 2026-06-27 with no intermediate releases.
All other monitored tools are already at latest: Claude Code 2.1.195, Copilot CLI 1.0.65, Copilot SDK 1.0.4, Codex 0.142.3, Pi 0.80.2, Playwright MCP 0.0.76, Playwright CLI 0.1.14, Playwright Browser v1.61.1.
GitHub MCP Server v1.4.0 → v1.5.0
Features
issue_readtool / newget_parentmethod (Add get_parent method to issue_read github-mcp-server#2726)Breaking / Deprecations
Fixes
ui_getpagination to cap latency (fix(ui_get): bound pagination to cap latency github-mcp-server#2766)add_comment_to_pending_review(fix(pull_requests): validate required params in add_comment_to_pending_review github-mcp-server#2770)show_ui(fix(mcp-apps): reconcile the show/defer contract — render results, remove show_ui github-mcp-server#2774)delete:trueon issue fields viadeleteIssueFieldValuemutation (Fix delete:true on issue fields by calling deleteIssueFieldValue mutation github-mcp-server#2755)Impact on gh-aw: The GitHub MCP server in gh-aw runs in lockdown/read-only mode and is consumed as a pinned Docker image. New reaction and issue-dependency tools expand capability without breaking existing read paths. The legacy issue-write deprecation is the only item to monitor, but gh-aw uses safe-outputs (not the MCP write tools) for GitHub writes, so impact is minimal.
Full v1.5.0 changelog
Highlights: STDIO OAuth (no PAT), react to issue/PR comments, parent issues via issue_read, MCP App shows labels/milestones.
What's Changed:
8d95af5to523c3efgithub-mcp-server#27533ad34catoa2dc166github-mcp-server#2752Full changelog: github/github-mcp-server@v1.4.0...v1.5.0
MCP Gateway (gh-aw-mcpg) v0.3.30 → v0.3.31
~33 merged PRs, predominantly tests and refactoring (mostly authored by lpcox with Copilot).
Fixes
Refactoring / Maintenance
fixSchemaBytes()workarounddifc.IsSingularReadTool)Impact on gh-aw: MCP Gateway is the default
sandbox.agentcontainer. The DIFC GHEC data-residency host-derivation fix and issue-dependency guard fixes improve correctness for enterprise/data-residency setups. The jsonschema v5→v6 migration is internal; no config-surface changes observed. Low risk.Full changelog reference
Full changelog: github/gh-aw-mcpg@v0.3.30...v0.3.31
Verification
pkg/constants/version_constants.goupdated:DefaultGitHubMCPServerVersionv1.4.0→v1.5.0,DefaultMCPGatewayVersionv0.3.30→v0.3.31make build && make recompile && make recompile(double recompile for MCPG SHA pin refresh) — 257/257 workflows compiled, 0 errors, 202 warnings (all pre-existing).lock.yml+ constants). No stale v1.4.0 / v0.3.30 references remain. v1.5.0 present in 252 lock files, v0.3.31 in 257. Nopkg/workflow/js/*.jsfiles modified.References:
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
awmgmcpgSee Network Configuration for more information.