Skip to content

v2.0.0

Latest

Choose a tag to compare

@github-actions github-actions released this 29 Sep 20:22
· 44 commits to main since this release
f8fa564

Added

  • Breaking: Before a merge, an approval, play_job, create_release, create_tag, a run_pipeline on the default branch or a protected ref, an update_issue that makes a confidential issue public, and every delete, the server asks you through the MCP client (form elicitation) when the client supports it; only an accept writes, so a client that declares elicitation and answers with nobody there can no longer make these writes.
  • GITLAB_MCP_REQUIRE_PROMPT (--require-prompt) refuses those writes as [blocked] when the client cannot ask you.
  • update_comment edits one of your own comments on an issue or a merge request in place, keeping its thread, replies and diff position.
  • add_comment returns the new comment's updated_at, which update_comment takes as its witness.

Changed

  • Breaking: the Go module path is now github.com/mmedum/gitlab-mcp/v2, as Go requires from v2 on; install with go install github.com/mmedum/gitlab-mcp/v2/cmd/gitlab-mcp@latest.

Fixed

  • A server no longer refreshes the sign-in before it serves when a login recorded its scopes, so a host that kills it during startup no longer signs the profile out.
  • A server that is stopped waits for a sign-in refresh in progress to be stored before it exits.
  • A refresh no longer spends the refresh token when the stored sign-in cannot be read again under the lock.

Built by GoReleaser from the tag. Each archive carries the binary,
LICENSE, NOTICE and README, with an SBOM beside it.

Verify a download before you run it:

sha256sum -c checksums.txt --ignore-missing
cosign verify-blob checksums.txt --bundle checksums.txt.bundle \
  --certificate-identity 'https://github.com/mmedum/gitlab-mcp/.github/workflows/release.yml@refs/tags/v2.0.0' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com
gh attestation verify gitlab-mcp_2.0.0_linux_amd64.tar.gz --repo mmedum/gitlab-mcp
gh attestation verify gitlab-mcp_2.0.0.mcpb --repo mmedum/gitlab-mcp

gitlab-mcp_2.0.0.mcpb is the Claude Desktop bundle. Its
SHA-256 is in the same signed checksums.txt. It does not log
you in: install the binary as well and run
gitlab-mcp login --client-id <application id> once from a terminal.