Release / / with v1.10.0, v1.10.1
GitHub MCP Server v1.11.0
Delete a GitHub repository after confirming its exact name.
Before you upgrade to v1.11.0
4 to fixCorrect unknown names in static `--tools` configuration before starting the server.
Read the evidence
Set `allow_symlink_write: true` explicitly when intentionally updating a symbolic link.
Read the evidence
For `add_issue_comment`, supply `body` or `reaction`; use `comment_id` only with `reaction`, never with `body`.
Read the evidence
Requests cannot disable server-enforced lockdown; repository access caches are isolated by caller.
Read the evidence
Oversized request bodies are rejected before MCP parsing. Configure `--authorization-server` for OAuth metadata and use CORS across OAuth discovery routes.
Zero-argument tools accept omitted `arguments` but reject explicit null and malformed JSON; successful responses are more compact. OAuth scope checks request the permissions needed for each tool invocation.
What changed in v1.11.0
Repository deletion uses confirmation; stricter host, tool and write validation changes several client contracts.
Release binary or container v1.11.0; requires a compatible MCP client and GitHub credentials. Feature-specific opt-ins and permissions apply.
New things you can do
Use `delete_repository` and complete its confirmation form.
Read the evidence
Fixed and improved
Create and manage Project views and configure their visible fields.
Read the evidence
Issue listing and search tolerate GHES schemas without custom issue-field types.
Read the evidence
Binary MCP resources are no longer base64-encoded twice; file reads identify symbolic links.
Read the evidence
Strict-schema clients can pass `delete: false` as a no-op.
Read the evidence
The `add_issue_comment` schema compatibility regression is fixed. Create a parent issue and sub-issues atomically.
Seeded by @iluxav with Codex, from the release's public sources. Each change links to its evidence.