Skip to content

Commit f6385a3

Browse files
HarmonybrewBotHarmonybrewBot
authored andcommitted
!17166 merge bump-github-mcp-server-1.10.0 into main
github-mcp-server 1.10.0 Created-by: HarmonybrewBot Commit-by: HarmonybrewBot Merged-by: HarmonybrewBot Description: Created by `brew bump` --- Created with `brew bump-formula-pr`.<details> <summary>release notes</summary> <pre>## Highlights v1.10.0 is a substantial security, reliability, and compatibility release for the GitHub MCP Server. ### Safer by default - Added confirmed repository deletion with form elicitation and protected multi-round-trip state ([#3076](github/github-mcp-server#3076)). - Restricted bearer credentials to configured GitHub authorities ([#3056](github/github-mcp-server#3056)). - Enforced HTTPS for GitHub Enterprise hosts ([#3069](github/github-mcp-server#3069)). - Made invalid static `--tools` configuration fail closed ([#3050](github/github-mcp-server#3050)). - Hardened lockdown, request limits, cache isolation, URL traversal, and response sanitization ([#3109](github/github-mcp-server#3109), [#3112](github/github-mcp-server#3112), [#3113](github/github-mcp-server#3113), [#3111](github/github-mcp-server#3111), [#3108](github/github-mcp-server#3108), [#3114](github/github-mcp-server#3114), [#3110](github/github-mcp-server#3110)). ### Better GitHub Enterprise Server compatibility - `list_issues` and `search_issues` now degrade safely when issue custom-field GraphQL types are unavailable ([#3086](github/github-mcp-server#3086), [#2897](github/github-mcp-server#2897)). - `list_issues` now returns assignee logins and stable empty arrays for unassigned issues ([#3064](github/github-mcp-server#3064)). - Validation failures expose safe ruleset details when supplied by the GitHub API ([#3081](github/github-mcp-server#3081)). ### Safer repository file operations - `get_file_contents` now identifies symbolic links and clearly labels dereferenced content. - Symbolic-link writes require explicit `allow_symlink_write: true` opt-in ([#3071](github/github-mcp-server#3071)). - Fixed binary MCP resources being base64-encoded twice ([#3098](github/github-mcp-server#3098)). ### More reliable tool contracts - Corrected `add_issue_comment` input modes ([#3085](github/github-mcp-server#3085)). - `issue_write.issue_fields[].delete: false` is now a valid no-op for strict-schema clients ([#3077](github/github-mcp-server#3077)). - Zero-parameter tools accept an omitted `arguments` property while rejecting explicit `null` and malformed JSON ([#3099](github/github-mcp-server#3099)). - Notification subscription tools explicitly advertise destructive behavior ([#2936](github/github-mcp-server#2936)). - Copilot review-request denials now return actionable guidance instead of a bare 404 ([#3119](github/github-mcp-server#3119)). ### Projects, Actions, and efficiency - Added Project view lifecycle operations and visible-field configuration ([#2961](github/github-mcp-server#2961), [#2988](github/github-mcp-server#2988)). - Reduced Actions and other successful response payloads ([#3047](github/github-mcp-server#3047), [#3055](github/github-mcp-server#3055)). - Improved sanitization performance and refreshed UI/build dependencies ([#3120](github/github-mcp-server#3120), [#3100](github/github-mcp-server#3100)). ### Behavior changes to note - Unknown static `--tools` names now prevent startup. - Symbolic-link updates require explicit opt-in. - Requests cannot relax server-enforced lockdown. - Oversized HTTP request bodies are rejected early. - `add_issue_comment` performs stricter mutually exclusive mode validation. - Repository deletion requires an eligible modern MCP client, form elicitation support, and the appropriate scopes. ## What's Changed * Reduce Actions workflow list response payloads by @tommaso-moro in github/github-mcp-server#3047 * Use minimal response types for tool results by @tommaso-moro in github/github-mcp-server#3055 * Add basic project view management by @zwick in github/github-mcp-server#2961 * Add visible fields to project views by @zwick in github/github-mcp-server#2988 * fix(actions): avoid malformed response on log download failure by @SamMorrowDrums in github/github-mcp-server#3066 * fix(security): enforce HTTPS for gh-host/GITHUB_HOST to prevent cleartext credentials by @SamMorrowDrums in github/github-mcp-server#3069 * Reject unsupported subscription streams by @SamMorrowDrums in github/github-mcp-server#3073 * build(deps): bump distroless/base-debian12 from `348dac1` to `76b3162` by @dependabot[bot] in github/github-mcp-server#3088 * build(deps): bump golang from 1.25.12-alpine to 1.25.13-alpine by @dependabot[bot] in github/github-mcp-server#3087 * build(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0 by @dependabot[bot] in github/github-mcp-server#3089 * build(deps): bump the npm_and_yarn group across 1 directory with 2 updates by @dependabot[bot] in github/github-mcp-server#3007 * build(deps): bump docker/login-action from 4.4.0 to 4.6.0 by @dependabot[bot] in github/github-mcp-server#3005 * Add confirmed repository deletion tool by @SamMorrowDrums in github/github-mcp-server#3076 * fix(issues): validate add_issue_comment input modes by @SamMorrowDrums in github/github-mcp-server#3085 * Fix static --tools validation fallback by @Mahmoud772122777 in github/github-mcp-server#3050 * Attach GitHub token only to configured GitHub hosts by @SyedAnas01 in github/github-mcp-server#3056 * Show ruleset violation details when create_branch fails by @Hashim1999164 in github/github-mcp-server#3081 * fix(notifications): mark subscription tools destructive by @SamMorrowDrums in github/github-mcp-server#2936 * Fix binary resource blob encoding by @SamMorrowDrums in github/github-mcp-server#3098 * Return assignees from list_issues by @tgockel in github/github-mcp-server#3064 * Fix list_issues on GHES schemas without issue fields by @SamMorrowDrums in github/github-mcp-server#3086 * Fix omitted tool arguments by @SamMorrowDrums in github/github-mcp-server#3099 * Clarify symlink behavior for repository file reads and writes by @theinfosecguy in github/github-mcp-server#3071 * fix(issues): allow delete:false in issue_write issue_fields by @tgockel in github/github-mcp-server#3077 * Handle unsupported issueFieldValues enrichment in search_issues by @kerobbi in github/github-mcp-server#2897 * build(deps): clear UI dependency alerts by @SamMorrowDrums in github/github-mcp-server#3100 * fix(lockdown): harden pull_request_read get_commits handling by @SamMorrowDrums in github/github-mcp-server#3109 * fix(http): make server lockdown mode an upper bound over requests by @SamMorrowDrums in github/github-mcp-server#3112 * Centralize sanitization of untrusted GitHub response fields by @SamMorrowDrums in github/github-mcp-server#3114 * Filter invisible Unicode after HTML entity normalization by @SamMorrowDrums in github/github-mcp-server#3110 * fix(raw): reject traversal segments when constructing raw content URLs by @SamMorrowDrums in github/github-mcp-server#3108 * refactor: condense lockdown comments in GetPullRequestCommits by @SamMorrowDrums in github/github-mcp-server#3115 * Limit HTTP request bodies before MCP middleware parsing by @SamMorrowDrums in github/github-mcp-server#3111 * fix(lockdown): isolate repo-access cache per caller identity by @SamMorrowDrums in github/github-mcp-server#3113 * perf(sanitize): make clean text allocation-free on the hot path by @SamMorrowDrums in github/github-mcp-server#3120 * test(sanitize): drop the optimization scaffolding by @SamMorrowDrums in github/github-mcp-server#3121 * fix(copilot): explain review request denials instead of forwarding a bare 404 by @dylanpulver in github/github-mcp-server#3119 * build(deps): bump the npm_and_yarn group across 1 directory with 4 updates by @dependabot[bot] in github/github-mcp-server#3091 ## New Contributors * @Mahmoud772122777 made their first contribution in github/github-mcp-server#3050 * @SyedAnas01 made their first contribution in github/github-mcp-server#3056 * @Hashim1999164 made their first contribution in github/github-mcp-server#3081 * @tgockel made their first contribution in github/github-mcp-server#3064 * @theinfosecguy made their first contribution in github/github-mcp-server#3071 * @dylanpulver made their first contribution in github/github-mcp-server#3119 **Full Changelog**: https://github.com/github/github-mcp- See merge request: Harmonybrew/homebrew-core!17166
2 parents 58ef83e + 33e7446 commit f6385a3

1 file changed

Lines changed: 3 additions & 3 deletions

File tree

‎Formula/g/github-mcp-server.rb‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
class GithubMcpServer < Formula
22
desc "GitHub Model Context Protocol server for AI tools"
33
homepage "https://github.com/github/github-mcp-server"
4-
url "https://github.com/github/github-mcp-server/archive/refs/tags/v1.9.0.tar.gz"
5-
sha256 "9d1e947afc54d047c345de468ca479ab835d7b9093689043d583008d51ba42d4"
4+
url "https://github.com/github/github-mcp-server/archive/refs/tags/v1.10.0.tar.gz"
5+
sha256 "de379aa3770a000523d56f619729587043330126a7f89eea629ec897b542da58"
66
license "MIT"
77
head "https://github.com/github/github-mcp-server.git", branch: "main"
88

@@ -12,7 +12,7 @@ class GithubMcpServer < Formula
1212
end
1313

1414
bottle do
15-
sha256 cellar: :any_skip_relocation, arm64_ohos: "c9a8bddeef967046587b496b20e135c2adfb67b4c592662c115752addeee49f9"
15+
sha256 cellar: :any_skip_relocation, arm64_ohos: "166583b571f29d94f9caf3a92bd374f0667d22d8b0e3b63bd47cdc0994d9c0d1"
1616
end
1717

1818
depends_on "go" => :build

0 commit comments

Comments
 (0)