Dependencies and SBOM
The dependency list GitLab builds from a project’s dependency scanning, filtered by package manager, and the software bill of materials it exports from a pipeline: dependency.export_create starts a CycloneDX export, dependency.export_get reports whether it is ready, and dependency.export_download fetches the document.
Sample questions
Section titled “Sample questions”- “List the npm dependencies of project 42”
- “Export an SBOM for pipeline 1234”
- “Download the finished SBOM export”
How to call it
Section titled “How to call it”- Dynamic, the default surface: call
gitlab_execute_actionwithactionset to the action’s ID, such asdependency.export_create, and its parameters inparams.gitlab_find_actionfinds an ID from a description of the task. - Meta (
GITLAB_MCP_TOOL_SURFACE=meta): callgitlab_dependencywithactionset to the action’s name, such asexport_create, and its parameters inparams. - Individual (
GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such asgitlab_create_dependency_list_export, with its parameters as the arguments.
Availability
Section titled “Availability”How many of these actions an instance serves at each tier, out of a total of 4:
- Free: 0
- Premium: 0
- Ultimate: 4
Read-only actions: 3 of 4, the ones a deployment in read-only mode keeps.
Actions
Section titled “Actions”The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served.
| Action | Individual |
|---|---|
dependency.export_create | gitlab_create_dependency_list_export |
dependency.export_download | gitlab_download_dependency_list_export |
dependency.export_get | gitlab_get_dependency_list_export |
dependency.list | gitlab_list_project_dependencies |
dependency.export_create
Section titled “dependency.export_create”Create a dependency list export from a pipeline.
- Meta-tool:
gitlab_dependency, actionexport_create - Individual tool:
gitlab_create_dependency_list_export - Tier: Ultimate
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
pipeline_id | integer | yes | Pipeline ID to export dependencies from |
export_type | string | no | Export type (default: sbom) |
dependency.export_download
Section titled “dependency.export_download”Download generated dependency list export content.
- Meta-tool:
gitlab_dependency, actionexport_download - Individual tool:
gitlab_download_dependency_list_export - Tier: Ultimate
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
export_id | integer | yes | Dependency list export ID |
dependency.export_get
Section titled “dependency.export_get”Get dependency list export status and metadata.
- Meta-tool:
gitlab_dependency, actionexport_get - Individual tool:
gitlab_get_dependency_list_export - Tier: Ultimate
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
export_id | integer | yes | Dependency list export ID |
dependency.list
Section titled “dependency.list”List project dependency inventory.
- Meta-tool:
gitlab_dependency, actionlist - Individual tool:
gitlab_list_project_dependencies - Tier: Ultimate
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or URL-encoded path |
order_by | string | no | Column to order keyset-paginated results by |
package_manager | string (bundler, composer, conan, go, gradle, maven, npm, nuget, pip, pipenv, pnpm, yarn, sbt, setuptools) | no | Filter by package manager (bundler, composer, conan, go, gradle, maven, npm, nuget, pip, pipenv, pnpm, yarn, sbt, setuptools) |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
page_token | string | no | Keyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’. |
pagination | string | no | Pagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |
sort | string (asc, desc) | no | Sort order for keyset-paginated results: asc or desc |