This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+2 more
Summary
AI summaryUpdates CI, GEO, and Dependabot across a mixed release.
Full changelog
Release Notes: v2.3.0 → v2.4.0
Features
- #211 — Adopted client-go v2.45.0: added security scan profile GraphQL tools and the user
auditorfield - #201 — Adopted client-go v2.44.0: mirrored
RenewApplicationSecretasgitlab_renew_application_secret - #200 — Added
claude mcp addone-command install, with install-first README, docs, site and assets - #210 — Improved the site for AI search (GEO): structured schema, visible authorship, sitemap
lastmod
Improvements
- #213 — Optimized production hot paths:
gitlab_find_actionsearch 7.5× faster on long queries (4.85s → 0.65s CPU) and per-token MCP server registration 3.7× faster (1.25s → 0.34s) via precomputed search word forms and a compiled-schema cache; unit-test suite CPU cut 51% (690s → 337s) with shared pure fixtures; coverage ofinternal/raised to 99.74% (wizard and prompts at 100%) - #212 — Reduced SonarCloud duplicated lines by extracting shared canonical shapes and helpers into
toolutil(member/board/user/PAT shapes, discussion guidance, GraphQL note mutations, upload file sources), with documented CPD exclusions for the genuinely irreducible cases; restored and guarded the 1:1 struct-audit pair coverage (TestBuildReport_AuditedPairFloors) - #199 — Consolidated developer command-line utilities (26 → 20) with hardening
Documentation
- #203 — Reorganized
docs/audience-first with the Diátaxis framework and overhauled the Astro site (quality, SEO, GEO) - #209 — Polished GEO details: TechArticle entity link, Person image, security lead-with-answer
- #206 — Added a headless AI-assistant install recipe to
llms.txt(+ README pointer) - #204 — Fixed the
llms.txt404, added per-page schema and a homepage FAQ
CI
- #205 / #207 / #208 — Submitted deployed URLs to IndexNow, made it non-fatal on GitHub Pages project sites, and pointed
keyLocationat the domain root (fixed 403) - #195 / #196 / #197 — Added the auto-assign workflow and skipped self-assignment and Dependabot PRs
Dependencies
- #214 — Patch updates: Go TUI stack (
bubbles2.1.1,bubbletea2.0.8,lipgloss2.0.5) andgopsutil4.26.6; siteastro7.0.6,@astrojs/starlight0.41.3,sharp0.35.3,html-validate11.5.5; all GitHub Actions audited as already current - #202 — Updated Go and pnpm dependencies
- #198 — Bumped the npm minor/patch group in
/site(Dependabot)
Full diff: https://github.com/jmrplens/gitlab-mcp-server/compare/v2.3.0...v2.4.0
Contributors: @jmrplens, @dependabot
Commits: 21 | Pull Requests: 19 | Files Changed: 457 (+19,156 / −6,704)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About jmrplens/gitlab-mcp-server
Complete GitLab REST API v4 coverage with 1006 MCP tools across 162 domains, 42 meta-tools, 24 resources, and 38 prompts. Cross-platform Go binary with stdio and HTTP transports, OAuth support, auto-update, read-only and safe modes.
Beta — feedback welcome: [email protected]