Customer release versions and version lookup
Customer release versions. Image releases on customer channels now carry
a simple customer-facing version (
1.1, 1.2, …) minted once per pushed
image. Each version maps to exactly one git SHA and image digest, so “you are
on 1.1” is always an exact, pinnable statement.Look up a release by version. New endpoint:
GET /releases/{channel}/{version}
resolves a version to its release. The path version matches either the
customer release version (for example 1.1) or the Gecko scanner version
(for example 1.1.0), and the response includes the digest-pinned
image_ref to pull.GitLab token expiry reminders and rotation API
GitLab token expiry reminders. Gecko now checks your GitLab token’s
expiration date daily and emails team admins 7 days before it expires and
again when it has expired or been revoked, so the integration never goes
dark by surprise. See
Token expiry and rotation.Rotate the GitLab token via the API. New v1 endpoints:
GET /integrations/gitlab
returns the connection state including the token expiry date, and
PATCH /integrations/gitlab
swaps in a fresh token, built for secret managers and rotation scripts.
New tokens are validated against your instance, including the required
api scope, before they’re stored.AI agents, MCP server, and API v1 redesign
Connect your AI tools. Gecko now hosts a remote MCP server at
https://app.gecko.security/api/mcp. Connect Claude, Claude Code, ChatGPT,
Codex, Cursor, and other MCP clients via OAuth or an API key, with
role-capped scopes, packaged security prompts, and per-team consent. See
Connect AI tools. Manage connections under
Settings > Integrations > Agents.Redesigned v1 API. Consistent response envelope, cursor pagination,
tier-aware rate limits, idempotency keys, and request IDs, plus new
endpoints for triaging vulnerabilities, updating repository settings, scan
schedules, and outbound webhook events with
HMAC-signed deliveries. The API is self-describing: live
OpenAPI spec, interactive
docs, and a machine-readable changelog at /api/v1/changelog.API keys are now visible to the whole team with owner attribution and
per-request usage logging, and can be sent as Authorization: Bearer.Connected accounts. Settings > Authentication now shows your
identities across GitHub, GitLab, Slack, Linear, and Jira, with suggested
matches you can confirm or remove. GitLab identities are tracked per
instance.Docs refresh
Reworked the docs navigation to add top-level Guides, API Reference,
and Changelog tabs.Added a Gecko-specific Okta SAML onboarding guide and refreshed local preview
instructions.