@AverageAiBro covered GitLab 19.4 expanding the GitLab MCP server beyond lookups into a full loop: save pipelines, pull job logs, open/update/review/merge MRs, work items, commits, and Ultimate vulnerability tools. The same release extends one governance model—read-only defaults to Always allow; write and delete default to Always ask—for Duo agents and third-party MCP clients.

Key Takeaways

  • MCP tools cover pipelines, job logs, full MR workflows, and vulnerability tools—not just lookups.
  • Governance travels with blast radius: write/delete default Always ask; read-only Always allow.
  • Official blog details automation MCP tools and one policy for Duo and third-party clients.
ADSponsored