--- since: 1.1.3 --- ## Release Title **gitaiflow v1.1.3 — First public release of MCP server, Claude Desktop extension, and signed AOT binaries** --- ## Release Details This release introduces the Model Context Protocol (MCP) server and its Claude Desktop extension (`.mcpb`), a restructured release pipeline with cryptographic signing, and a breaking change to how change summaries are generated. The MCP server runs as a standalone service (stdio or streamable-HTTP) with bearer-token auth, rate limiting, and six tools for change summaries, changelogs, release notes, usage stats, and model listing. The Desktop Extension packages the server and the AOT CLI into a single installable bundle for macOS (Apple Silicon), Linux (x86_64/arm64), and Windows (x86_64). A new signing infrastructure rotates Ed25519 keys, verifies releases on install, and cleans up binaries that fail verification. #### Breaking Changes - **Change summaries now diff against HEAD** instead of the remote base branch. `SummaryService.generate_summary` compares the working tree (staged + unstaged tracked changes + untracked files) to HEAD. The remote/base-branch is still resolved as metadata for the artifact's `base_ref` field used by changelog cross-checks, but it no longer drives the diff itself. #### Highlights **MCP Server** — A new `mcp_server` package provides a FastAPI/Starlette-based MCP server with six tools (`change_summary`, `last_summary`, `changelog`, `release_notes`, `usage`, `list_models`). It supports both stdio and streamable-HTTP transports, bearer-token authentication, fixed-window rate limiting, workspace allow-listing (multi-root, Git-repo-root enforcement), and lazy binary resolution with automatic installer fallback. Configuration loads from environment variables and a `.mcp.env` file. **MCP Desktop Extension (`.mcpb`)** — The `mcpb/` directory defines a Claude Desktop extension (v1.1.3, compatible with Claude Desktop ≥0.10.0) that bundles the MCP server launcher and the AOT CLI binary. `scripts/mcp/build_mcpb.sh` uses PyInstaller to produce a single-file executable per platform (darwin-arm64, linux-amd64, linux-arm64, windows-amd64) and packages it with `manifest.json` and an icon into a `.mcpb` file. The manifest declares user-configurable allowed workspaces (required), a git remote (defaults to `origin`), and an optional developer binary path override. AI provider credentials (`AI_PROVIDER`, `AI_API_KEY`, `AI_MODEL`, ...) are configured separately via `.mcp.env`, not through the extension's manifest. **MCP Server Deployment** — A `Dockerfile.mcp` (python:3.12-slim) and `cloudrun.env.example` enable containerized deployment to Cloud Run. The image includes a pre-built `gitaiflow-linux-arm64` binary, exposes port 8080, and runs the MCP server module. A `claude_desktop_config.example.json` shows the Docker-based integration for Claude Desktop. **Release Signing & Key Rotation** — Ed25519 signing keys have been rotated. `scripts/release/sign_release.sh` generates `SHA256SUMS` and a detached `.sig` for each release directory; `gitai_r2.sh` auto-signs when `GITAIFLOW_SIGNING_KEY_FILE` is set. The public key is baked into `install.sh` and `mcp_server/binary.py`; the private key stays offline in CI secrets. `verify_release_signing_key.sh` derives the public key from the Keychain private key, compares it against the embedded key, and verifies the live R2 `SHA256SUMS` signature. On signature verification failure, the freshly installed binary is deleted to prevent a permanent trust bypass. **Restructured CI/Release Pipeline** — The monolithic `tag_release.sh` is replaced by granular `tag.sh` and `release.sh` scripts with per-product (AOT/MCP) and per-host (GitLab/GitHub) targets. Versioning splits into `AOT_VERSION`, `MCP_VERSION`, and `MCP_AOT_VERSION`. R2 layout separates AOT and MCP tracks under `installers/AOT/` and `installers/MCP/` with independent `latest.txt` pointers. GitLab CI jobs are now disabled by default (`SKIP_*` flags); local scripts are the authoritative release path. **Installer Hardening** — Both `install.sh` and `install.ps1` now enforce mandatory SHA-256 checksum verification (abort on mismatch or missing entry). `install.sh` adds best-effort Ed25519 signature verification over `SHA256SUMS` (requires OpenSSL ≥3.2); `install.ps1` documents that signature checks run on the MCP path. `install.ps1` uses atomic temp-file download + move and emits detailed expected/actual checksums on failure. A retry with exponential backoff (3 attempts, 1.5 s base) and a `curl/8.7.1` User-Agent absorb transient network failures and avoid Cloudflare 403s on R2. **Changelog Enrichment** — `ChangelogService` adds `_get_branch_commits` (commits unique to the current branch since `merge-base(base_ref, HEAD)` within a date range) and `_merge_commits` (authoritative change-summary commits + branch commits as gap-fill, deduped by first message line). `DiffGenerationService.generate` accepts a new `diff_ref` parameter to bypass remote/base-branch resolution (e.g., `HEAD`). **Deleted-File Handling in Diffs** — `_get_changed_files` switches from `--name-only` to `--name-status` so deleted files (status `D`) are no longer dropped. `_tracked_at_ref` detects files tracked at a given ref (catching staged deletions via `git cat-file`), and `_get_file_timestamp` uses `git log` on the path, working for deleted files too. Staged deletions now report "deleted" instead of "added" in status and diff output. #### Fixes - Underlying exceptions are now included in `_verify_release_signature` error messages. - Workspace validation error messages clarify that the repository must be within gitaiflow's MCP workspace. - Missing EOF newlines fixed in `compile.sh` and `install.sh`; assorted test-formatting fixes. #### Dependencies - Added `requirements-mcp.txt` with `mcp==2.2.0`, `uvicorn>=0.35,<1`, and `cryptography>=42` for the MCP server. - Docker images install `git` and `ca-certificates` as system dependencies. #### Documentation - Manifest description changed from "local repositories" to "code repositories". #### Tests - New regression suite `test_change_summary_head_diff.py` covers HEAD-based diffs and deleted-file handling. - Changelog enrichment tests verify earlier commits without artifacts appear, artifact-covered commits aren't duplicated, and no extra branch commits produces no output change. - Comprehensive MCP server test suites added for allowed workspaces, config, Docker binary resolution, executor, launcher, middleware (auth + rate limiting), native binary resolution, stdio transport, and workspace validation. - Installer tests enabled with `SHA256SUMS` generation for fake release assets; Linux/Windows Docker platform tests commented out. #### Build & CI - `build_mcpb.sh` stamps each `.mcpb` manifest with a unique `+build.` suffix so Claude Desktop reinstalls on key rotation without a version bump. - `gitai_r2.sh` splits sync into two passes: critical manifests (`SHA256SUMS`, `SHA256SUMS.sig`, `latest.txt`) uploaded with `Cache-Control: no-store`; binaries uploaded separately with normal caching. - Added `.dockerignore` excluding dev files from Docker builds. - CI job comments clarify `deploy-telemetry` independence and `github-mirror` source-only mirroring. #### Chores - Version bumped from 1.1.0 → 1.1.2 → 1.1.3 in `pyproject.toml`. - `.gitignore` updated for `.mcp.env`, release signing keys (`release-signing.key*`, `*.signing.key*`), and `KEY_ROTATIONS.log`. #### Installation **gitaiflow CLI** -- macOS & Linux (bash), installs to `~/.local/bin`, no `sudo` needed: ```bash # latest curl -fsSL https://install.djangoplay.org/gitaiflow | bash # specific version curl -fsSL https://install.djangoplay.org/gitaiflow | bash -s -- v1.1.3 ``` Windows (PowerShell): ```powershell # latest irm https://install.djangoplay.org/gitaiflow.ps1 | iex # specific version $env:GITAIFLOW_VERSION = "v1.1.3"; irm https://install.djangoplay.org/gitaiflow.ps1 | iex ``` Direct binary downloads for macOS (Apple Silicon), Linux (x86_64/arm64), and Windows are attached to this release. **Claude Desktop extension (MCPB)** -- no source checkout, Docker, Python, or manual MCP config needed. macOS & Linux: ```bash curl -fsSL https://install.djangoplay.org/gitaiflow-mcp | bash ``` Windows (PowerShell): ```powershell irm https://install.djangoplay.org/gitaiflow-mcp.ps1 | iex ``` Downloads the platform `.mcpb` file to your Downloads folder -- open it with Claude Desktop to install. **Self-hosting the MCP server** (Docker, Cloud Run, or from source) is covered in the [MCP Documentation Index](../mcp/documentation-map.md). #### Full Changelog See [CHANGELOG.md](../changelog/CHANGELOG.md) for the complete list of additions, fixes, and test coverage.