This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+2 more
Affected surfaces
ReleasePort's take
Light signalReleasePort Layerβ―1 v2.0.5 adds project serviceβaccount exposure and several e2e test improvements.
Why it matters: Exposes project service accounts for tighter analysis; bugfixes stabilize Docker runner bootstrap, enable root OAuth readiness waiting, and allow passwordβless root token bootstrapping in tests. Plan to adopt the new authentication flow before next sprint.
Summary
AI summaryUpdates @jmrplens, π Bug Fixes, and e2e across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Exposes project service accounts and tightens analysis. Exposes project service accounts and tightens analysis. Source: llm_adapter@2026-05-22 Confidence: high |
β |
| Bugfix | Medium |
Bootstrap root token without password grant for e2e tests. Bootstrap root token without password grant for e2e tests. Source: llm_adapter@2026-05-22 Confidence: high |
β |
| Bugfix | Medium |
Stabilizes Docker runner bootstrap in e2e tests. Stabilizes Docker runner bootstrap in e2e tests. Source: llm_adapter@2026-05-22 Confidence: high |
β |
| Bugfix | Medium |
Waits for root OAuth readiness in e2e tests. Waits for root OAuth readiness in e2e tests. Source: llm_adapter@2026-05-22 Confidence: high |
β |
| Other | Medium |
Aligns AI customizations with current architecture documentation. Aligns AI customizations with current architecture documentation. Source: llm_adapter@2026-05-22 Confidence: low |
β |
| Other | Medium |
Completes global documentation audit. Completes global documentation audit. Source: llm_adapter@2026-05-22 Confidence: low |
β |
| Other | Medium |
Updates manifests for v2.0.3 release. Updates manifests for v2.0.3 release. Source: llm_adapter@2026-05-22 Confidence: low |
β |
| Other | Medium |
Updates client-go to v2.30.0 and expands Orbit tools. Updates client-go to v2.30.0 and expands Orbit tools. Source: llm_adapter@2026-05-22 Confidence: low |
β |
Full changelog
Changelog
β¨ Features
- 0f2a16c6c881b63f3d547530db1f73fbdd7445e7: feat: expose project service accounts and tighten analysis (@jmrplens)
π Bug Fixes
- 5ebe87ec4327ed5ba7a4f51aa6aeb67cb408ff75: fix(e2e): bootstrap root token without password grant (@jmrplens)
- 410a0a57a2abc21c272ef2f96731e050ffa8b1ad: fix(e2e): stabilize Docker runner bootstrap (@jmrplens)
- f2b6552ecc2afc4f4836b965f9442513854e7c02: fix(e2e): wait for root OAuth readiness (@jmrplens)
π Documentation
- 8ff955f8922041a6d54c4a1f8705c14df6fb998d: docs: align AI customizations with current architecture (@jmrplens)
- 210d5acf25e9deb326bb7d865c43d554aa6e6d01: docs: complete global documentation audit (@jmrplens)
π§ Maintenance
- 493a7f6d236fcd9e6c17910e45d1dce27aacc8b6: Update client-go to v2.30.0 and expand Orbit tools (@jmrplens)
- cc8f136ea5c8a7d30b222d555f21bbc75d8f2e2c: chore: update manifests for v2.0.3 (@jmrplens)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About jmrplens/gitlab-mcp-server
Complete GitLab REST API v4 coverage with 1006 MCP tools across 162 domains, 42 meta-tools, 24 resources, and 38 prompts. Cross-platform Go binary with stdio and HTTP transports, OAuth support, auto-update, read-only and safe modes.
Related context
Beta — feedback welcome: [email protected]