Releases: mmedum/gitlab-mcp
Release list
v2.0.0
Added
- Breaking: Before a merge, an approval,
play_job,create_release,create_tag, arun_pipelineon the default branch or a protected ref, anupdate_issuethat makes a confidential issue public, and every delete, the server asks you through the MCP client (form elicitation) when the client supports it; only an accept writes, so a client that declares elicitation and answers with nobody there can no longer make these writes. GITLAB_MCP_REQUIRE_PROMPT(--require-prompt) refuses those writes as[blocked]when the client cannot ask you.update_commentedits one of your own comments on an issue or a merge request in place, keeping its thread, replies and diff position.add_commentreturns the new comment'supdated_at, whichupdate_commenttakes as its witness.
Changed
- Breaking: the Go module path is now
github.com/mmedum/gitlab-mcp/v2, as Go requires from v2 on; install withgo install github.com/mmedum/gitlab-mcp/v2/cmd/gitlab-mcp@latest.
Fixed
- A server no longer refreshes the sign-in before it serves when a login recorded its scopes, so a host that kills it during startup no longer signs the profile out.
- A server that is stopped waits for a sign-in refresh in progress to be stored before it exits.
- A refresh no longer spends the refresh token when the stored sign-in cannot be read again under the lock.
Built by GoReleaser from the tag. Each archive carries the binary,
LICENSE, NOTICE and README, with an SBOM beside it.
Verify a download before you run it:
sha256sum -c checksums.txt --ignore-missing
cosign verify-blob checksums.txt --bundle checksums.txt.bundle \
--certificate-identity 'https://github.com/mmedum/gitlab-mcp/.github/workflows/release.yml@refs/tags/v2.0.0' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
gh attestation verify gitlab-mcp_2.0.0_linux_amd64.tar.gz --repo mmedum/gitlab-mcp
gh attestation verify gitlab-mcp_2.0.0.mcpb --repo mmedum/gitlab-mcpgitlab-mcp_2.0.0.mcpb is the Claude Desktop bundle. Its
SHA-256 is in the same signed checksums.txt. It does not log
you in: install the binary as well and run
gitlab-mcp login --client-id <application id> once from a terminal.
v1.1.0
Added
update_labeltakesclear_descriptionandclear_priority, andupdate_milestonetakesclear_description,clear_start_dateandclear_due_date.
Built by GoReleaser from the tag. Each archive carries the binary,
LICENSE, NOTICE and README, with an SBOM beside it.
Verify a download before you run it:
sha256sum -c checksums.txt --ignore-missing
cosign verify-blob checksums.txt --bundle checksums.txt.bundle \
--certificate-identity 'https://github.com/mmedum/gitlab-mcp/.github/workflows/release.yml@refs/tags/v1.1.0' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
gh attestation verify gitlab-mcp_1.1.0_linux_amd64.tar.gz --repo mmedum/gitlab-mcp
gh attestation verify gitlab-mcp_1.1.0.mcpb --repo mmedum/gitlab-mcpgitlab-mcp_1.1.0.mcpb is the Claude Desktop bundle. Its
SHA-256 is in the same signed checksums.txt. It does not log
you in: install the binary as well and run
gitlab-mcp login --client-id <application id> once from a terminal.
v1.0.0
Added
login,logout,statusanddoctor, signing in with your own OAuth application through--client-id.- gitlab.com as the one instance, with profiles kept side by side; a sign-in is only ever sent to the instance that issued it.
- Token refresh under a cross-process lock, so two clients share one login.
- Read tools:
get_me,resolve_url,search_projects,get_project,search_issues,get_issue,list_discussions,search_merge_requests,get_merge_request,get_file,list_tree,list_branches,list_commits,get_commit. - GitLab content rendered inside untrusted-content boundaries, within a reply budget that says what it left out.
get_commitcontinues a long commit message withmessage_offset, as every cut read can be continued.- Review reads:
list_mr_files,get_mr_diff,list_mr_commitsandlist_review_comments, your own unpublished drafts. - History reads:
compare_refsandlist_tags. - CI reads:
list_pipelines,get_pipelinewith its failed jobs,list_jobs,get_job_logandlint_ciat a ref. get_job_logreads a log in byte windows, the tail by default or the failing section, cleaned of colors and section markers, with token and key shapes masked.- Planning and navigation reads:
list_labels,list_milestones,list_members,find_users,list_todosandsearch. - Resources for an issue, a merge request and a job log, carrying the same text as their tools.
resolve_urlnamesget_pipeline,get_job_logandcompare_refsfor pipeline, job and compare links.- Read-only mode (
GITLAB_MCP_READ_ONLY) registers only the read tools and requests onlyread_api. - The quick-action guard every later write goes through.
- Write tools:
create_issue,update_issue,add_comment,resolve_discussion,create_merge_request,update_merge_request,create_branch,create_commitandmark_todos_done. - Reviews in drafts:
add_review_comment,delete_review_commentandsubmit_review, which publishes every draft at once; an approving review needsGITLAB_MCP_ENABLE_SHIP=true. - Inline comments land where asked: the server computes GitLab's diff position from a file, line and side, and reports where the comment landed.
- A line GitLab would run as a quick action refuses the write, or is sent as text with
escape_commands. - Every write takes
dry_run, and names the project's visibility in its result. - Updates to issues and merge requests require the
updated_atyou read, and are refused[stale]if it moved. update_issuemakes a confidential issue public only withGITLAB_MCP_ENABLE_SHIP=true.create_commitrefuses the default branch and every protected branch, andcreate_branchrefuses a name a protected-branch rule covers; code reaches them through a merge request.- A create whose answer is lost is never repeated: the server reads to say whether it happened.
GITLAB_MCP_WRITE_NAMESPACESconfines writes to the groups and projects it names.lint_cichecks configuration you pass, before it is committed; it may not useinclude:, since GitLab fetches what an include names.- Ship tools, registered only with
GITLAB_MCP_ENABLE_SHIP=true:merge_merge_request,approve_merge_requestandunapprove_merge_request, which take the headshayou reviewed, andrun_pipeline,retry_pipeline,retry_job,play_jobandcancel_pipeline. - Pipeline and job variables are sent and never shown: a result names their keys.
- Destructive tools, registered only with
GITLAB_MCP_ENABLE_DESTRUCTIVE=trueand refused withoutconfirm: true:delete_branch, which refuses the default, protected and unmerged branches, anddelete_comment, for your own comments only. - The
wikitoolset:list_wiki_pages,get_wiki_page,save_wiki_pageanddelete_wiki_page; a change carries a hash of the content you read. - The
snippetstoolset:list_snippets,get_snippetandcreate_snippet, which only creates private snippets. - The
releasestoolset:list_releases,get_releaseandcreate_release, which is Ship. - The
deploymentstoolset (list_environments,list_deployments) and theactivitytoolset (list_events). resolve_urlnamesget_wiki_pagefor a wiki page's link, andlist_wiki_pagesfor the wiki's index, when thewikitoolset is on.make evalsscores a model against the tool surface, including four instructions planted in content that it must not follow.get_job_logreads only the window it shows, so a log of any size can be read, and each window no longer downloads the whole log.get_mr_diffreads from the page that holdsfile_offset, so paging through a large merge request reads each page about once.get_projectcontinues a long description withoffset.get_mr_diff,get_commitandcompare_refscontinue one file's diff larger than the budget withdiff_offset.get_pipelinenames its failed trigger jobs and the downstream pipeline each started.add_commentstarts a resolvable thread withthread, andresolve_discussionresolves issue threads withtype: issue.- A lost comment is settled however many threads were started after it.
add_review_commentreports theline_codeGitLab computed for a draft on a line.retry_jobandplay_jobtake values for the inputs a job declares.create_releasetakes asset links, only to the project's own pages and packages.link_issuesandunlink_issuesrelate two issues, in one project or two.move_issuemoves an issue to another project, never to one more people can see; it is Ship.rebase_merge_requestrebases a merge request's source branch from the head you reviewed; it is Ship.cherry_pick_commitandrevert_commitcommit to a branch, never the default or a protected one, and their dry run says whether the change applies.get_blameshows who last changed each line of a file.list_job_artifactsandget_job_artifactread a job's artifacts, one text file at a time, with secrets masked.- The
planningtoolset:create_label,update_label,delete_label,create_milestone,update_milestoneanddelete_milestone; a label carries aversionits writes take. - The
releasestoolset gainscreate_tag, which refuses protected names, anddelete_tag. - Repository gates run by
make checkand CI on Linux, macOS and Windows. - Signed release archives for six platforms with SBOMs, build provenance, a Claude Desktop bundle and an MCP registry entry.
Built by GoReleaser from the tag. Each archive carries the binary,
LICENSE, NOTICE and README, with an SBOM beside it.
Verify a download before you run it:
sha256sum -c checksums.txt --ignore-missing
cosign verify-blob checksums.txt --bundle checksums.txt.bundle \
--certificate-identity 'https://github.com/mmedum/gitlab-mcp/.github/workflows/release.yml@refs/tags/v1.0.0' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
gh attestation verify gitlab-mcp_1.0.0_linux_amd64.tar.gz --repo mmedum/gitlab-mcp
gh attestation verify gitlab-mcp_1.0.0.mcpb --repo mmedum/gitlab-mcpgitlab-mcp_1.0.0.mcpb is the Claude Desktop bundle. Its
SHA-256 is in the same signed checksums.txt. It does not log
you in: install the binary as well and run
gitlab-mcp login --client-id <application id> once from a terminal.