Added
- Breaking: Before a merge, an approval,
play_job,create_release,create_tag, arun_pipelineon the default branch or a protected ref, anupdate_issuethat makes a confidential issue public, and every delete, the server asks you through the MCP client (form elicitation) when the client supports it; only an accept writes, so a client that declares elicitation and answers with nobody there can no longer make these writes. GITLAB_MCP_REQUIRE_PROMPT(--require-prompt) refuses those writes as[blocked]when the client cannot ask you.update_commentedits one of your own comments on an issue or a merge request in place, keeping its thread, replies and diff position.add_commentreturns the new comment'supdated_at, whichupdate_commenttakes as its witness.
Changed
- Breaking: the Go module path is now
github.com/mmedum/gitlab-mcp/v2, as Go requires from v2 on; install withgo install github.com/mmedum/gitlab-mcp/v2/cmd/gitlab-mcp@latest.
Fixed
- A server no longer refreshes the sign-in before it serves when a login recorded its scopes, so a host that kills it during startup no longer signs the profile out.
- A server that is stopped waits for a sign-in refresh in progress to be stored before it exits.
- A refresh no longer spends the refresh token when the stored sign-in cannot be read again under the lock.
Built by GoReleaser from the tag. Each archive carries the binary,
LICENSE, NOTICE and README, with an SBOM beside it.
Verify a download before you run it:
sha256sum -c checksums.txt --ignore-missing
cosign verify-blob checksums.txt --bundle checksums.txt.bundle \
--certificate-identity 'https://github.com/mmedum/gitlab-mcp/.github/workflows/release.yml@refs/tags/v2.0.0' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
gh attestation verify gitlab-mcp_2.0.0_linux_amd64.tar.gz --repo mmedum/gitlab-mcp
gh attestation verify gitlab-mcp_2.0.0.mcpb --repo mmedum/gitlab-mcpgitlab-mcp_2.0.0.mcpb is the Claude Desktop bundle. Its
SHA-256 is in the same signed checksums.txt. It does not log
you in: install the binary as well and run
gitlab-mcp login --client-id <application id> once from a terminal.