Repository navigation
Releases: Brandon-Born/bga-mcp
Release list
v1.0.0-rc.7 — full-repository source inventory and clearer database coverage
This prerelease makes full-repository inspection more useful and explains why coverage is incomplete. inspect_project partitions the bounded inventory into eligible PHP, client and configuration candidates, excluded editor support, unknown source scope and other files. Eligibility is explicit; unknown files, partial listing and read limits retain unsupported results.
Database audits retain literal formatted INSERT target facts beside unsupported generated values and report readable-source availability plus two independent facts about wholly blank or ordinary-line-comment schemas. Dynamic SQL, generated values, trailing expressions and escaping are still unsupported. Pre-release hold explanations identify the observed causes.
The public command offers seven local read-only tools and three project resources over stdio. It does not enable network or Studio access. Verification covers 845 tests, 243 scenarios and 103 compatibility claims across macOS, Windows and Linux on Node 22/24. Dino Racer was inspected unchanged; the frozen usefulness repeat makes no live gameplay, GUI or productivity claim.
Use the attached signed-download acquisition companion and successful public-consumer receipt. Verify the signature and original archive digest before installation. This is an explicitly evaluated prerelease, not a whole-game correctness verdict or stable release. npm publication remains deferred.
Original source: 8bd773d2d597b7b2b2c3abd6316e41cd84c1a81c. Archive SHA-256: e1ac0af1a8f513a7fbd472a8fd1734ca91787d2f7d42f69f3382e037b15516de. Original-candidate production and isolated signing passed. Signing source: c642ed05df566964b10a27a2009a7427e41ed6bd.
Original archive publication and hosted consumer passed all four stages. Exact publisher-source CI passed all six platform/Node jobs at 5ba7746b835928f74f6de9d0b1ae9a4693b53113. Independent macOS token-free public download, signature/provenance, install/use/refusal/removal verification passed at 2026-10-04T22:13:25.796Z. The lifetime hosted consumer receipt is attached.
Acquisition and signature-verification companion. Fresh security approval exercised 68 tests and 11 required security scenarios against the signed original and scanned 274 packaged text files. Original-source production/full-graph dependency audits had zero findings at approval and immediate publication preflight; these are dated observations.
bga-mcp v1.0.0-rc.6 — signed local-only prerelease
The first signed, installable prerelease of bga-mcp is available here. It reads a local BoardGameArena game project and reports cross-file defects through seven MCP tools and three project resources.
Download bga-mcp-1.0.0-rc.6.tgz, then follow the signed-download and installation guide. The guide explains signature verification, client configuration, first use and removal. GitHub's generated source archives are separate from the signed installable package.
This release keeps the MCP local and read-only. Network and Studio flags are refused. Experimental documentation, setup and Studio capabilities are excluded. It is a prerelease, with stdio protocol 2025-11-25; the findings do not prove that a game is correct or ready for BGA publication.
The original signed package passed final security review and a token-free public download, signature/provenance verification, installation, MCP discovery, first use, unconfigured-root refusal and removal. The successful public consumer receipt is retained with this release. Existing verification metadata and signed originals remain available for the release lifetime. npm publication is deferred.
Original package SHA-256: 9ac83f5f3d643296581d10f2dd426221c792426315b6a2b468c5d3c45fd928ea.
Original source: 36a7d86f8b112c5025826e4b8aee5f7c7b7e5bd1. Certified signer: 882859f6c13643efdb7aca90d7405d2339ab9534. A checksum match alone is not signature verification.
v1.0.0-rc.5 verification evidence (candidate)
Verification evidence for v1.0.0-rc.5
This prerelease record distributes candidate verification metadata only. The npm package has not been published or approved for release.
Original source: 286f2bb
Original package SHA-256: sha256:b7cc226a512a4aab433f8daddf49f54ee00323f3dc7da6960490be1c0727eeac
Signing workflow source: a0ac5f3
The signed original observations cover seven local tools, three resources and stdio. Six other repository capabilities are explicitly excluded. Live Studio: not run. Later signing/distribution does not renew dated security observations.
Retain these assets for the lifetime of this release. Verify using the trusted repository scripts/release-evidence.ts download command; the derived summary is recomputed from signed evidence and digest-bound original inventory/manifest. BGA-400/401/405/415 retain installation, client breadth, security approval and package publication ownership.
v1.0.0-rc.4 verification evidence (candidate)
Verification evidence for v1.0.0-rc.4
This prerelease record distributes candidate verification metadata only. The npm package has not been published or approved for release.
Original source: 5c4eebd
Original package SHA-256: sha256:662c23199cdfd62365b1e94c6ec28bb61374e9d11eafd606f1f29ba1ec6ad200
Signing workflow source: b593b76
The signed original observations cover seven local tools, three resources and stdio. Six other repository capabilities are explicitly excluded. Live Studio: not run. Later signing/distribution does not renew dated security observations.
Retain these assets for the lifetime of this release. Verify using the trusted repository scripts/release-evidence.ts download command; the derived summary is recomputed from signed evidence and digest-bound original inventory/manifest. BGA-400/401/405/415 retain installation, client breadth, security approval and package publication ownership.
v1.0.0-rc.1 verification evidence (candidate)
Verification evidence for v1.0.0-rc.1
This prerelease record distributes candidate verification metadata only. The npm package has not been published or approved for release.
Original source: a2031af
Original package SHA-256: sha256:a3472a97916bbd793fe32ffb847ced3d9638fe2c45cc112867b0af0a15f3acfa
Signing workflow source: 5a3dc72
The signed original observations cover seven local tools, three resources and stdio. Six other repository capabilities are explicitly excluded. Live Studio: not run. Later signing/distribution does not renew dated security observations.
Retain these assets for the lifetime of this release. Verify using the trusted repository scripts/release-evidence.ts download command; the derived summary is recomputed from signed evidence and digest-bound original inventory/manifest. BGA-400/401/405/415 retain installation, client breadth, security approval and package publication ownership.