-
Notifications
You must be signed in to change notification settings - Fork 308
Closed
Labels
automationcookieIssue Monster Loves Cookies!Issue Monster Loves Cookies!dependenciesPull requests that update a dependency filePull requests that update a dependency file
Description
Summary
- MCP Gateway updated: v0.1.19 → v0.1.20 (released 2026-03-20)
constants.goupdated andmake recompilerun successfully (177/177 workflows compiled)- Other tracked tools with new versions use
"latest"pinning (no constant changes needed):- Claude Code: 2.1.79 → 2.1.80
- Codex: 0.115.0 → 0.116.0
Update MCP Gateway v0.1.19 → v0.1.20
- Previous: v0.1.19 → New: v0.1.20
- Released: 2026-03-20
- Docker image:
ghcr.io/github/gh-aw-mcpg:v0.1.20
Breaking Changes
None
Key Features
- GitHub API Proxy Mode — new dedicated proxy mode that applies DIFC filtering to GitHub API requests; see https://github.com/github/gh-aw-mcpg/blob/main/docs/PROXY_MODE.md
- Configurable Trusted Bots List — operators can define custom trusted bots with elevated
approvedintegrity levels (spec §4.1.3.4); see https://github.com/github/gh-aw-mcpg/blob/main/docs/CONFIGURATION.md - DIFC-Filtered Items Notice — gateway now appends a notice when DIFC filtering removes items from tool responses (e.g.
[DIFC] 3 item(s) removed by integrity policy), preventing agents from concluding result sets are empty
View Full Changelog
Bug Fixes & Improvements
- Hardened DIFC proxy enforcement — fail closed throughout pipeline (no silent info leaks on DIFC errors)
- Human-readable secrecy level names in write-denial reasons (e.g.
private:owner/repo) - Fixed crash when
ParseToolArgumentsreceived nilParams - Empty/invalid
trusted_botsentries now caught at config load time (TOML and stdin JSON paths) - Rust guard: removed dead params from
issue_integrity, fixed heap-allocating string comparison
Merged PRs (from GitHub)
- chore(deps): bump github.com/modelcontextprotocol/go-sdk from 1.4.0 to 1.4.1 in the go_modules group across 1 directory gh-aw-mcpg#2149 — bump go-sdk 1.4.0 → 1.4.1
- rust-guard: remove dead params from
issue_integrity+ fix heap-allocating string comparison gh-aw-mcpg#2152 — rust-guard cleanup - fix: handle nil Params in ParseToolArguments gh-aw-mcpg#2172 — fix nil Params in ParseToolArguments
- Surface DIFC-filtered items in tool responses to prevent targeted dispatch drift gh-aw-mcpg#2175 — surface DIFC-filtered items in tool responses
- fix: harden proxy DIFC enforcement — fail closed throughout pipeline gh-aw-mcpg#2188 — harden proxy DIFC enforcement
- feat: add proxy mode for GitHub API DIFC filtering gh-aw-mcpg#2176 — feat: add proxy mode for GitHub API DIFC filtering
- feat: add configurable trusted bots list with approved integrity elevation gh-aw-mcpg#2204 — feat: configurable trusted bots list
- fix(difc): use human-readable secrecy level in write-denial reason gh-aw-mcpg#2205 — fix: human-readable secrecy level in write-denial
- fix: improve DIFC error messages and replace issue:#0 sentinel gh-aw-mcpg#2202 — fix: improve DIFC error messages
- fix: validate empty trusted_bots at config load time gh-aw-mcpg#2215 — fix: validate empty trusted_bots at config load time
Impact Assessment
- Risk: Low
- Affects: MCP Gateway sandbox container; DIFC enforcement pipeline
- Migration: No breaking changes; new proxy mode and trusted bots features are additive
Package Links
- Repository: https://github.com/github/gh-aw-mcpg
- Release Notes: https://github.com/github/gh-aw-mcpg/releases/tag/v0.1.20
Other Version Updates (no constant changes required)
| Tool | Previous | Latest | Notes |
|---|---|---|---|
| Claude Code | 2.1.79 | 2.1.80 | Uses "latest" — no constant change |
| Codex | 0.115.0 | 0.116.0 | Uses "latest" — no constant change |
Codex 0.116.0 Highlights
- App-server TUI now supports device-code ChatGPT sign-in during onboarding with token refresh
- New
userpromptsubmithook for blocking/augmenting prompts before execution - Smoother plugin/connector setup with automatic missing plugin installation prompts
- Realtime sessions begin with recent thread context; fewer self-interruptions during audio playback
- Fixed websocket prewarm delays causing first-turn stalls
References:
Generated by CLI Version Checker · ◷
- expires on Mar 22, 2026, 10:02 AM UTC
Reactions are currently unavailable
Metadata
Metadata
Labels
automationcookieIssue Monster Loves Cookies!Issue Monster Loves Cookies!dependenciesPull requests that update a dependency filePull requests that update a dependency file
Type
Fields
Give feedbackNo fields configured for issues without a type.