Jenkins MCP Server v2.9.9
Released 2026-08-13.
Highlights
- Job discovery, job details, and build details now expose only their documented
response contracts instead of forwarding arbitrary Jenkins/plugin objects. - Build parameter values identified as passwords, tokens, secrets, or
credentials are redacted before they cross the MCP boundary.
New Features
- None.
Improvements
get_jobandget_build_infonow use narrow Jenkinstreequeries, reducing
controller serialization work and MCP response size.- Shared projection helpers keep scalar fields, nested build references, health
reports, and parameter handling consistent across the structured read tools. - Tool descriptions, the compatibility contract, security guidance,
troubleshooting, and the Jenkins-through-Minibridge smoke now describe and
verify the projected response boundary.
Bug Fixes
list_jobspreserved unexpected top-level response fields even though its
public contract contains only the filteredjobscollection.- Individual
list_jobsentries were returned verbatim, allowing action/plugin
objects not requested by the documented contract to cross the boundary. - Folder listings that had only a child
namewere policy-checked against a
reconstructed path but returned nofullName; the response now includes the
same canonical path that was authorized. get_jobreturned depth-two action/property objects and upstream/downstream
job references, which could disclose metadata outside the allowed job's
documented state and build-reference contract.get_build_inforeturned unrelated action, cause, artifact, change-set, and
plugin payloads rather than its documented result/timing/parameter contract.- Password/token/credential parameter classes and secret-like parameter names
could return their values; those values are now replaced with[redacted],
while non-scalar plugin values receive an explicit unsupported marker. - Malformed nested job/build response structures could produce raw iteration or
attribute errors instead of stableJenkinsErrordiagnostics. - Boolean, float, or string console offsets could reach Jenkins despite the
public non-negative integer contract. - Invalid
X-More-Data, a missing cursor while more data remained, or a
regressive cursor on a completed page could silently stop or corrupt console
pagination.
Breaking Changes
- None. Documented identity/state/health/build/timing fields and the existing
Jenkinsactions[].parameters[]shape remain available. Undocumented raw
plugin, relation, cause, artifact, and change-set passthrough is intentionally
removed.
Known Issues
- Jenkins string parameters can contain sensitive data under an innocuous name.
Use Jenkins password/credential parameter types and secret-like names so the
server can identify them; do not place secrets in ordinary string parameters.
Security
- Structured job and build reads now fail closed on malformed nested objects and
project only explicitly documented fields. - Allowed-job detail responses no longer carry upstream/downstream job objects,
closing an indirect metadata path aroundMCP_ALLOWED_JOBS. - Sensitive build parameters are redacted by parameter name and Jenkins class;
arbitrary nested parameter values are never forwarded.
Upgrade Notes
- No configuration changes are required. Reconnect MCP sessions after rollout
so clients refresh the strengthened tool descriptions and response contract.