This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+2 more
Affected surfaces
Summary
AI summaryUpdates @jmrplens, 🚧 Maintenance, and deps across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Adds 10 enterprise+dynamic surface cases (MS-ENT-DYN-1..10) Adds 10 enterprise+dynamic surface cases (MS-ENT-DYN-1..10) Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Dependency | Low |
Updates @astrojs/starlight and astro dependencies (2026-06) Updates @astrojs/starlight and astro dependencies (2026-06) Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Dependency | Low |
Updates Go runtime via bubbletea chain and pnpm (#159) Updates Go runtime via bubbletea chain and pnpm (#159) Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Dependency | Low |
Updates Go and pnpm dependencies (2026-06) Updates Go and pnpm dependencies (2026-06) Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Medium |
Bumps Go to 1.26.4 to clear GO-2026-5037 vulnerability Bumps Go to 1.26.4 to clear GO-2026-5037 vulnerability Source: llm_adapter@2026-06-06 Confidence: low |
— |
Full changelog
Changelog
✨ Features
- 1acf878c838dd00aab96e2f9f17391b5f5f5ec8b: feat(eval): add 10 enterprise+dynamic surface cases (MS-ENT-DYN-1..10) (#158) (@jmrplens)
🐛 Bug Fixes
- 8f9399e8b6da95a04529bbd5ab53beb8924e2f30: fix(ci): bump Go to 1.26.4 to clear GO-2026-5037 (#152) (@jmrplens)
🚧 Maintenance
- 9cfc21aa9e30b28e358893674346ceb79eb94c9b: chore(deps): bump @astrojs/starlight and astro (2026-06) (#155) (@jmrplens)
- 4497df234a50f0cd8c609925b040850f5b7ddc05: chore(deps): update Go (golang.org/x/exp via bubbletea chain) and pnpm (#159) (@jmrplens)
- fb340c04ff46b4298f9cbaa5d8ef4b905a30495a: chore(deps): update Go and pnpm dependencies (2026-06) (#153) (@jmrplens)
- 4487cc28383bdb6eb8c5fb6ebdc7c87509b3a802: chore(release): 2.1.3 + CE dynamic surface baseline (#160) (@jmrplens)
- a004ed6343fb231adb567903b1e2b807ba586944: chore: regenerate README and testing docs after EE coverage expansion (#157) (@jmrplens)
- dee0c1dd471cb23d4267af5b8d52cdd3b3469926: chore: update manifests for v2.1.2 (@jmrplens)
- da07670cf6cfd486e4a1922d65a2c22bc6b02fe1: test(e2e): add EE tool coverage and LDAP test infrastructure (#156) (@jmrplens)
- c6707fe405d61f6803366751182f67b33304c46b: test(e2e): phase 1-3 P1 coverage gaps + EE iterations feature flag fix (#148) (@jmrplens)
Security Fixes
- Bumps Go to 1.26.4 to clear CVE GO-2026-5037
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About jmrplens/gitlab-mcp-server
Complete GitLab REST API v4 coverage with 1006 MCP tools across 162 domains, 42 meta-tools, 24 resources, and 38 prompts. Cross-platform Go binary with stdio and HTTP transports, OAuth support, auto-update, read-only and safe modes.
Beta — feedback welcome: [email protected]