Skip to content

Dependencies and SBOM

The dependency list GitLab builds from a project’s dependency scanning, filtered by package manager, and the software bill of materials it exports from a pipeline: dependency.export_create starts a CycloneDX export, dependency.export_get reports whether it is ready, and dependency.export_download fetches the document.

  • “List the npm dependencies of project 42”
  • “Export an SBOM for pipeline 1234”
  • “Download the finished SBOM export”
  • Dynamic, the default surface: call gitlab_execute_action with action set to the action’s ID, such as dependency.export_create, and its parameters in params. gitlab_find_action finds an ID from a description of the task.
  • Meta (GITLAB_MCP_TOOL_SURFACE=meta): call gitlab_dependency with action set to the action’s name, such as export_create, and its parameters in params.
  • Individual (GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such as gitlab_create_dependency_list_export, with its parameters as the arguments.

How many of these actions an instance serves at each tier, out of a total of 4:

  • Free: 0
  • Premium: 0
  • Ultimate: 4

Read-only actions: 3 of 4, the ones a deployment in read-only mode keeps.

The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served.

ActionIndividual
dependency.export_creategitlab_create_dependency_list_export
dependency.export_downloadgitlab_download_dependency_list_export
dependency.export_getgitlab_get_dependency_list_export
dependency.listgitlab_list_project_dependencies

Create a dependency list export from a pipeline.

  • Meta-tool: gitlab_dependency, action export_create
  • Individual tool: gitlab_create_dependency_list_export
  • Tier: Ultimate
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
pipeline_idintegeryesPipeline ID to export dependencies from
export_typestringnoExport type (default: sbom)

Download generated dependency list export content.

  • Meta-tool: gitlab_dependency, action export_download
  • Individual tool: gitlab_download_dependency_list_export
  • Tier: Ultimate
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
export_idintegeryesDependency list export ID

Get dependency list export status and metadata.

  • Meta-tool: gitlab_dependency, action export_get
  • Individual tool: gitlab_get_dependency_list_export
  • Tier: Ultimate
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
export_idintegeryesDependency list export ID

List project dependency inventory.

  • Meta-tool: gitlab_dependency, action list
  • Individual tool: gitlab_list_project_dependencies
  • Tier: Ultimate
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
order_bystringnoColumn to order keyset-paginated results by
package_managerstring (bundler, composer, conan, go, gradle, maven, npm, nuget, pip, pipenv, pnpm, yarn, sbt, setuptools)noFilter by package manager (bundler, composer, conan, go, gradle, maven, npm, nuget, pip, pipenv, pnpm, yarn, sbt, setuptools)
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (asc, desc)noSort order for keyset-paginated results: asc or desc