Repository navigation
Releases: github/github-mcp-server
Release list
GitHub MCP Server 2.0.2
Bugfix release
- fix(inventory): restore typed tool HTTP header validation by @SamMorrowDrums in #3454
Full Changelog: v2.0.1...v2.0.2
GitHub MCP Server 2.0.1
GitHub MCP Server 2.0.0
Highlights β¨
More and more agents are supporting Code Mode or Programmatic Tool Calling so we have added support for structured outputs and output schemas to help do this effectively.
These schemas are only advertised to clients advertising MCP 2026-07-28 spec support (or later). Our compound tools required some updates to allowed output schemas, so they are not valid for older clients and we don't return them.
What's Changed
- perf: cache encoded tools/list schemas by @SamMorrowDrums in #3407
- Pin GitHub Actions to commit SHAs by @github-security-bot in #3259
- feat(inventory): add typed MCP tool registration foundation by @SamMorrowDrums in #3371
- feat(context): add typed tool schemas and outputs by @SamMorrowDrums in #3377
- feat(comments): add typed visibility tool inputs and outputs by @SamMorrowDrums in #3384
- feat(search): add typed projected result outputs by @SamMorrowDrums in #3386
- feat(security): add typed security alert outputs by @SamMorrowDrums in #3387
- feat: type discussion and notification tool outputs by @SamMorrowDrums in #3388
- feat(repos): add typed commit tool outputs by @SamMorrowDrums in #3389
- feat(issues): add typed metadata, comment, and dependency outputs by @SamMorrowDrums in #3391
- feat(repos): complete typed repository tool outputs by @SamMorrowDrums in #3392
- feat(issues): add protocol-gated typed consolidated issue tools by @SamMorrowDrums in #3393
- Type granular issue MCP inputs and protocol-gated outputs by @SamMorrowDrums in #3394
- refactor(search): type repository, user, org and commit search tools by @SamMorrowDrums in #3395
- refactor(pull-requests): migrate consolidated PR tools to typed inputs and outputs by @SamMorrowDrums in #3396
- refactor(pull-requests): type granular MCP tools by @SamMorrowDrums in #3397
- refactor(actions): type consolidated MCP tools by @SamMorrowDrums in #3398
- Address typed output compatibility gaps by @kerobbi in #3433
New Contributors
- @github-security-bot made their first contribution in #3259
Full Changelog: v1.14.0...v2.0.0
GitHub MCP Server 1.14.0
What's Changed
- fix(pull_request_reviews): Update pending pull request review lookup to work when the authenticated actor is a Copilot bot by @Copilot in #3355
- build(deps): remediate npm alerts and refresh safe dependencies by @SamMorrowDrums in #3370
- build: upgrade golangci-lint to v2.14.0 by @SamMorrowDrums in #3380
- build(deps): upgrade go-github to v92.0.0 by @SamMorrowDrums in #3381
- build(ui): upgrade to TypeScript 7 and align the Node 26 toolchain by @SamMorrowDrums in #3379
- feat(ui): migrate MCP Apps SDK to v2 by @SamMorrowDrums in #3378
- ci: migrate cosign to v3 and dual-publish image signatures by @SamMorrowDrums in #3382
- build(ui): migrate to React 19 and Primer React 38 by @SamMorrowDrums in #3383
Full Changelog: v1.13.0...v1.14.0
GitHub MCP Server 1.13.0
Changelog
- 85b0399 Add granular tools to hide and unhide issue comments, PR review comments and PR reviews (#3350)
What's Changed
- Preserve versioned STDIO API user agents across MCP protocols by @jidicula in #3323
- Always enable MCP Apps UI; remove remote_mcp_ui_apps flag gate by @SamMorrowDrums in #3348
- Use source revisions for non-release Docker builds by @jidicula in #3357
- Add granular tools to hide and unhide issue comments, PR review comments and PR reviews by @timrogers in #3350
New Contributors
Full Changelog: v1.12.2...v1.13.0
GitHub MCP Server 1.12.2
What's Changed
- feat: add update_issue_comment tool by @timrogers in #3284
- feat: add
remove_issue_reaction,remove_issue_comment_reactionandremove_pull_request_review_comment_reactiontools to the granular issues and pull requests toolsets by @timrogers in #3285
Full Changelog: v1.12.1...v1.12.2
GitHub MCP Server 1.12.1
Bugfix release
Oauth protected resource metadata became too permissive in the supported scopes advertised, which has been addressed in this release.
What's Changed
- Return a clear error for missing owner/repo/issue_number in the copilot assignment tools by @thejdubb02 in #3221
- build(deps): bump golang from 1.27.0-alpine to 1.27.1-alpine by @dependabot[bot] in #3239
- fix(oauth): advertise only default scopes in protected resource metadata by @SamMorrowDrums in #3251
New Contributors
- @thejdubb02 made their first contribution in #3221
Full Changelog: v1.12.0...v1.12.1
GitHub MCP Server 1.12.0
Highlights
- New governance tools for agents. Read and manage repository rulesets and custom properties across repository, organization, and enterprise levels.
- Faster, safer feature flags. Functional availability rules evaluate lazily after static filtering, deduplicate checks per request, and preserve precise availability errors.
- Safer write operations. Pin merge HEADs, recover file SHAs, use least-privilege public-repository access, and detect silently dropped labels.
- Richer review and discovery support. Adds review range coordinates, thread resolution reasons, projected-header preflights, Server Card support, and Agent Plugins.
- Better content fidelity. Markdown bodies, titles, release notes, comments, and commit messages preserve visible content while filtering unsafe invisible characters.
What's Changed
- Remove documentation for unavailable tool-search command by @tommaso-moro in #3162
- Expose Copilot review thread resolution reasons by @cagesellchen in #3123
- fix(repos): give create_or_update_file callers a SHA they can actually get by @dylanpulver in #3131
- fix: allow public_repo for public contribution tools by @paulcakeface in #3140
- Enable feature flags via URL query parameter (?features=) for headerless hosted connections by @CAOShurong in #3146
- Add expectedHeadSha pinning to merge_pull_request by @jcosta1970 in #3182
- Fix e2e harness compilation against go-github v89 and go-sdk v1.7 by @ppoffice in #3187
- Return range coordinates for review comments by @yiheng-kkk in #3193
- Fix issue_write silently dropped label errors by @SamMorrowDrums in #3195
- fix(http): allow projected MCP headers in preflights by @SamMorrowDrums in #3167
- Spell perPage the same way in every paginated tool by @karpovantonme in #3142
- Add MCP Server Card (SEP-2127) types + handler by @SamMorrowDrums in #2768
- Refactor feature flags to use functional availability rules by @SamMorrowDrums in #3166
- feat(governance): add repository ruleset tools with multi-level scope challenge by @SamMorrowDrums in #2991
- feat(governance): add custom properties tools by @SamMorrowDrums in #2992
- Fix HTML entities in sanitized titles by @SamMorrowDrums in #3216
- build(deps): bump fast-uri from 3.1.5 to 3.1.7 in /ui in the npm_and_yarn group across 1 directory by @dependabot[bot] in #3208
- build(deps): bump the npm_and_yarn group across 1 directory with 2 updates by @dependabot[bot] in #3217
- build(deps): bump github/codeql-action from 4.37.4 to 4.37.9 by @dependabot[bot] in #3192
- feat: add Agent Plugins 1.0 package by @777genius in #3169
- fix(sanitize): preserve Markdown body fidelity on read surfaces by @SamMorrowDrums in #3177
- build(deps): bump actions/stale from 10 to 11 by @dependabot[bot] in #3003
- Fix main CI sanitizer integration by @SamMorrowDrums in #3219
New Contributors
- @cagesellchen made their first contribution in #3123
- @paulcakeface made their first contribution in #3140
- @CAOShurong made their first contribution in #3146
- @jcosta1970 made their first contribution in #3182
- @ppoffice made their first contribution in #3187
- @yiheng-kkk made their first contribution in #3193
- @karpovantonme made their first contribution in #3142
- @777genius made their first contribution in #3169
Full Changelog: v1.11.0...v1.12.0
GitHub MCP Server 1.11.0
Highlights
- Smarter OAuth challenges: per-call scope checks request only the permissions each tool invocation needs with runtime checks where required.
- Improved browser OAuth support: CORS now works across OAuth discovery routes, with configurable authorization-server URLs.
- Improved sub-issue workflow: create parent and sub-issues atomically.
- Better HTTP caching for STDIO: REST responses support ETag conditional requests.
- Runtime refresh: upgraded to Go 1.27authorizationauthorization plus routine security and dependency updates.
What's Changed
- feat(http): add --authorization-server flag to override OAuth AS URL by @Anika-Sol in #2900
- Name the root command after the installed binary by @plusky in #2998
- fix(http): preserve CORS across OAuth routes by @SamMorrowDrums in #3147
- Add atomic parent issue creation by @zwick in #3134
- Add ETag conditional requests to the REST transport by @joshfree in #3026
- build(deps): bump github/codeql-action from 4 to 4.37.4 by @dependabot[bot] in #3004
- Add per-call OAuth scope checks by @SamMorrowDrums in #3128
- build(deps): bump docker/setup-buildx-action from 4.2.0 to 4.3.0 by @dependabot[bot] in #3157
- build(deps): bump github.com/go-chi/chi/v5 from 5.3.1 to 5.3.2 by @dependabot[bot] in #3156
- build(deps): bump distroless/base-debian12 from
76b3162tofabbf1cby @dependabot[bot] in #3154 - build(deps): bump golang from 1.25.13-alpine to 1.27.0-alpine by @dependabot[bot] in #3153
- build(deps): bump github.com/stretchr/testify from 1.12.0 to 1.12.1 by @dependabot[bot] in #3155
New Contributors
- @Anika-Sol made their first contribution in #2900
- @plusky made their first contribution in #2998
- @joshfree made their first contribution in #3026
Full Changelog: v1.10.1...v1.11.0
GitHub MCP Server 1.10.1
What's Changed
- Fix add_issue_comment schema compatibility regression by @SamMorrowDrums in #3127
Full Changelog: v1.10.0...v1.10.1