You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This release focuses on security hardening, reliability improvements, and documentation accuracy β strengthening the Rust guard, tightening DIFC labeling coverage, and ensuring documentation matches actual behavior.
β¨ What's New
assign_copilot_to_issue_with_intent DIFC coverage (#9844): The new Copilot issue-assignment tool is now fully classified in write-operation guards and DIFC labeling, ensuring correct security enforcement for AI-assisted workflows.
Rust guard: GraphQL authorAssociation support (#9697): The Rust guard now correctly honors authorAssociation from GraphQL project item queries, improving trust classification accuracy for project-level events.
Pinned container base images with drift guard (#9841): MCP Gateway container base images are now pinned by digest with an automated drift guard, reducing supply-chain risk.
JSON Pointer error locations in config schema validation (#9698): Configuration schema errors now report locations as JSON Pointers (e.g., /servers/github/command), making misconfiguration easier to diagnose.
Read-only stress workflows across runtimes (#9720): New stress test workflows validate MCP Gateway under default, gVisor, and Docker sandbox runtimes, increasing confidence in multi-runtime deployments.
π Bug Fixes & Improvements
Proxy --policy default aligned (#9779): The proxy flag's default now matches the shared environment config helpers, eliminating a subtle discrepancy.
Deterministic HTTP transport reconnect tests (#9725): Flaky shutdown timing in reconnect-retry tests eliminated.
HMAC body handling refactored (#9731): Shared request-body read/restore helper removes duplication and reduces potential for body-drain bugs.
π Documentation
README and CONTRIBUTING reconciled (#9745): CLI flags, environment variables, and config behavior now accurately reflected. See the Configuration Reference.
π Release Highlights
This release focuses on security hardening, reliability improvements, and documentation accuracy β strengthening the Rust guard, tightening DIFC labeling coverage, and ensuring documentation matches actual behavior.
β¨ What's New
assign_copilot_to_issue_with_intentDIFC coverage (#9844): The new Copilot issue-assignment tool is now fully classified in write-operation guards and DIFC labeling, ensuring correct security enforcement for AI-assisted workflows.Rust guard: GraphQL
authorAssociationsupport (#9697): The Rust guard now correctly honorsauthorAssociationfrom GraphQL project item queries, improving trust classification accuracy for project-level events.Pinned container base images with drift guard (#9841): MCP Gateway container base images are now pinned by digest with an automated drift guard, reducing supply-chain risk.
JSON Pointer error locations in config schema validation (#9698): Configuration schema errors now report locations as JSON Pointers (e.g.,
/servers/github/command), making misconfiguration easier to diagnose.Read-only stress workflows across runtimes (#9720): New stress test workflows validate MCP Gateway under default, gVisor, and Docker sandbox runtimes, increasing confidence in multi-runtime deployments.
π Bug Fixes & Improvements
--policydefault aligned (#9779): The proxy flag's default now matches the shared environment config helpers, eliminating a subtle discrepancy.π Documentation
π³ Docker Image
The Docker image for this release is available at:
docker pull ghcr.io/github/gh-aw-mcpg:v0.4.4 # or docker pull ghcr.io/github/gh-aw-mcpg:latestSupported platforms:
linux/amd64,linux/arm64For complete details, see the full release notes.
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
awmgmcpgSee Network Configuration for more information.