⚠️ BREAKING CHANGES
1. Smaller default tool set: only the core toolset is enabled when GITLAB_TOOLSETS is unset (#547)
If you do not set GITLAB_TOOLSETS (or --toolsets), the server now exposes the lean core toolset plus the always-on discover_tools meta-tool: 39 tools instead of 118 in v2.1.70. 79 tools that used to be on by default are no longer listed, including:
- Merge requests:
merge_merge_request,approve_merge_request,unapprove_merge_request,create_merge_request_note, MR discussion note create/update/delete, draft notes (create_draft_note,publish_draft_note,bulk_publish_draft_notes, …), emoji reactions - Repository and branches:
create_branch,delete_branch,push_files,create_or_update_file,fork_repository,create_repository, protected-branch tools - Issues and others:
create_note,delete_issue, issue links,list_todos/mark_todo_done,get_users/get_user,list_group_projects,list_group_members,update_project, label CRUD,validate_ci_lint/validate_project_ci_lint, CI catalog, commit statuses,list_events
Agents that relied on these tools (create a branch → push → open and merge an MR) will no longer see them unless you change your configuration.
How to restore, pick one:
- Restore exactly the previous default set:
GITLAB_TOOLSETS=merge_requests,issues,repositories,branches,projects,labels,ci,groups,users - Enable every toolset:
GITLAB_TOOLSETS=all - Add individual tools on top of
core:GITLAB_TOOLS=merge_merge_request,create_branch,push_files - Or let the agent call
discover_toolsto activate a category for the current session (requires a client that handlestools/list_changed).
Legacy USE_PIPELINE, USE_MILESTONE and USE_GITLAB_WIKI still add their tools on top of the default (now core); they do not restore the old default set. See Environment variables → GITLAB_TOOLSETS.
2. Local OAuth scopes now follow GITLAB_PERMISSION_MODE (#784)
With local OAuth (GITLAB_USE_OAUTH=true, including tokens created by zereight-mcp-gitlab auth), the requested scope is now read_api when GITLAB_PERMISSION_MODE=readonly (or the deprecated GITLAB_READ_ONLY_MODE=true) and api otherwise. Previously only GITLAB_READ_ONLY_MODE=true switched to read_api. Granted scopes are now recorded in the token file. If the recorded scopes do not match the current mode, the server starts a new authorization instead of reusing the token. Token files from older versions have no recorded scopes and keep working until the next refresh, which records the scopes GitLab returns.
Who must act: OAuth users running with GITLAB_PERMISSION_MODE=readonly.
- Enable the
read_apiscope on your GitLab OAuth application (apps configured with onlyapiwill fail the new authorization), then log in again when prompted. - If you run instances with different permission modes, give each one its own
GITLAB_OAUTH_TOKEN_PATHso they do not force each other to re-authorize. - Personal access token (PAT) users and
GITLAB_OAUTH_TOKEN_SCRIPTusers are not affected.
This release also makes the deprecation warnings stronger for GITLAB_READ_ONLY_MODE, GITLAB_ALLOWED_GROUPS and USE_GITLAB_WIKI / USE_MILESTONE / USE_PIPELINE. These variables still work but will be removed in the next major version. Use GITLAB_PERMISSION_MODE, GITLAB_OAUTH_ALLOWED_GROUPS and GITLAB_TOOLSETS instead.
Changes in v2.2.0
✨ Features
- feat: strengthen deprecated env warnings #784
⚡ Performance
- perf: defer HTTP startup work and cache tool listings #787
🔨 Chore
- chore(deps): bump the npm_and_yarn group across 2 directories with 3 updates #794
- chore(release): skip bot PRs in release notes #796
Other Changes
- Reduce default GitLab MCP tool surface #547