← Back to all sparks
Chamilo logo

Chamilo

EDTECH
Velocity6.3

LMS and EdTech platform: Chamilo

Chamilo's 3.0 beta quietly turns the LMS into an MCP server agents can author courses through.

lmsmcpagentic-authoringplatform-rewritesecurity-maintenanceself-hosted
Current state
Chamilo runs three lines at once. The legacy 1.11 branch takes security and bugfix releases roughly quarterly, 2.0 reached GA in April and has drawn three patch releases since, and a 3.0 line opened on 13 August. The 3.0 beta is where the direction sits: 456 changes spanning 88 plugin fixes, a 44-item security sweep, and a new MCP server with OAuth 2.1 that exposes course authoring and review to outside clients. The feed's own bodies are unreliable here - both 3.0 tags arrived carrying a single line of text, and the 2.0 GA release reached it only as scraped page fragments.
Where it's heading
The rewrite has stopped being the story and the agent surface has started. 2.0 spent its cycle absorbing the legacy feature set - LTI, ONLYOFFICE, the plugin catalogue - and reached GA; 3.0's first beta spends most of its weight on that same restoration work but adds something no 2.0 release contains, an MCP server with OAuth 2.1 auto-connect and tools that write rather than only read. Model providers are being wired directly into the AI helper alongside it. Security remains constant across all three branches, with 44 security items in the 3.0 beta alone.
Prediction
Expect the MCP tool surface to widen in the next 3.0 beta, since the first pass already moved past read-only lookups into course authoring and review. Whether 3.0 becomes the supported line or 2.0 keeps taking patches is the question the tags themselves do not answer.

Recent moves

  1. 15d ago

    Beta 2 tagged with no release notes

    A bare tag with no GitHub release behind it, eighteen days after beta 1. It moves the 3.0 line forward on paper without recording what changed, making this the second 3.0 tag to reach the feed without notes.

    View source ↗
  2. 1mo ago

    Chamilo 3.0 beta 1 opens an MCP server with course-authoring tools

    ⚡ SPARK

    The release that opens the 3.0 line, and the point where Chamilo stops being an LMS that is merely being rewritten and becomes one outside agents can drive. Most of its 456 changes continue the restoration work 2.0 did, but the MCP server is new to the codebase - no 2.0 release mentions it anywhere.

    View source ↗
  3. 2mo ago

    Chamilo 1.11.40: security and bugfix maintenance release

    Maintenance on the branch most production installs still run. With 2.0 at GA and 3.0 in beta, 1.11 remains the line that gets patched rather than changed.

    View source ↗
  4. 5mo ago

    Stop logging AI base-provider fallback events

    An internal change that stops logging AI base-provider fallback events, with no user-visible effect. Its body is scraped GitHub profile chrome rather than release content - one of two fragments the 2.0 GA release left behind in the feed.

    View source ↗
  5. 5mo ago

    Bump tar dependency 7.5.3 to 7.5.6

    A Dependabot bump of the tar dependency, captured as a standalone entry whose body is scraped profile chrome. Routine supply-chain maintenance on the rewrite branch.

    View source ↗
  6. 5mo ago

    Chamilo 2.0 RC3: LTI provider, ONLYOFFICE, and plugin revival

    ⚡ SPARK

    The last release candidate before 2.0 reached GA two weeks later: LTI provider and client, ONLYOFFICE editing, H5P import, and the legacy plugin set restored on the new architecture, with an eval-based RCE path removed. It is the release that made the 2.0 GA viable, and the end of the absorption phase the 3.0 beta now builds on.

    View source ↗