Releases: Byte-Ventures/borg-mcp-server
Releases · Byte-Ventures/borg-mcp-server
Release list
borgmcp-server 4.2.0
Package
- Registry: https://www.npmjs.com/package/borgmcp-server/v/4.2.0
- Live integrity:
sha512-xH69OBCWx76ZRFRMDlOxX9gDi+kEHjScWcPH9tXh/GCjA3PkpHAIV/Wq9St2xswYG7udAvfljElntuxU3aNjeg== - Published through npm Trusted Publishing with provenance.
Source
News and fixes
borgmcp-server 4.2.0
- The terminal dashboard is rebuilt as the Command dashboard: the sensor scope now reads retained message timestamps and sender identities in one SQLite snapshot, buckets each message once, and distinguishes quiet periods, partial coverage, and unknown history before the retained pruning horizon. Volume and sender presence share one axis with proportional heights, sender ordinals match the drone board, and omitted rows are counted.
- The wide two-column layout now switches at the documented 100-column breakpoint (the previous code used 144). Compact 40×10 and plain fallback views remain, and constrained heights budget the focused drone board before the feed and cube list.
- Full and background-only ANSI resets restore the dark canvas after shorter repaints and resizes.
- Five production-renderer captures (168×64, 120×40, 80×30, 40×10, 39×9) are committed under
test/fixtures/dashboard-command/, and the operator reference describes the data semantics and layout. - The server now pins
borgmcp-shared2.2.0, which adds the design-reference guidance to the shared role templates.
borgmcp-server 4.1.0
Package
- Registry: https://www.npmjs.com/package/borgmcp-server/v/4.1.0
- Live integrity:
sha512-hRoctltsH2dqI4SF2bxFCscad0bfUXf0pobhiX1q+4sEAGQW5yrpLy/lj8wpb9LzAtuJ4fddMbwuUqf/gaXkhQ== - Published through npm Trusted Publishing with provenance.
Source
News and fixes
borgmcp-server 4.1.0
- The platform Queen playbook now explains the decision registry, cube directive, cube documents, and repository
AGENTS.mdas distinct durable layers. - Decision-registry capacity refusals now name all four layers and direct cleanup in order: relocate rules, supersede stale choices, then remove obsolete entries.
- The server now pins
borgmcp-shared2.1.0 for matching template guidance and the typed decision contract.
borgmcp-server 4.0.2
borgmcp-server 4.0.2
- Coordinator playbooks now stop active polling after the first receipt signal and use one dormant activation deadline followed by one resettable supervision wake for active work.
- The lifecycle distinguishes receipt from activation, evaluates overdue transitions once, and preserves operator control over reassignment. The bundled Software Development template and the server fallback now provide the same behavior.
npm: borgmcp-server@4.0.2 — integrity sha512-FJotK2HlWXzahfgmkKaEovVqcfjZykbT9pK3Bs/WuHQmDVTgkAQzWxWflVuaZiQZsMiDoALWoO1370Xqg9DVOg==
borgmcp-server 4.0.1
borgmcp-server 4.0.1
- SQLite transaction handling now uses one internal helper across the store, preserving the originating storage error when rollback also fails.
- Store activity infrastructure and database row decoding are split into focused internal modules with no protocol or public API change.
npm: borgmcp-server@4.0.1 — integrity sha512-uraYJkrVKFzbCele2hC3Cmjy+/2PI6mJo5hZ3/29+uN/ufERAJ4s+5ASkg9ZOgtq94FzGEY+NLF9h73cKC2RWA==
borgmcp-server 4.0.0
borgmcp-server 4.0.0
- Breaking: The server now uses
borgmcp-shared2.0.0 and protocol tag 14. Protocol tags must match exactly: protocol-13 clients receive HTTP 426. Upgrade borgmcp and borgmcp-server to their protocol-14 releases together. - Activity-log read responses no longer include the cube-wide
claimscollection. Claim visibility remains available through acknowledgement status, roster claim counts, and diagnostics. Removing the unbounded collection prevents accumulated claims from invalidating every activity-log read after the shared decoder limit was exceeded. (#379)
borgmcp-server 3.4.1
Package
- Registry: https://www.npmjs.com/package/borgmcp-server/v/3.4.1
- Live integrity:
sha512-20otM/QUzJTiwfh/pb43/BsG6/gcV7YjLuHzzEcjFtfgSNBdNSA0Yo/OmFSQj5RkBuZ5bDOusI5zewZh7oaKIQ== - Published through npm Trusted Publishing with provenance.
Source
News and fixes
borgmcp-server 3.4.1
- Managed-service lifecycle commands no longer reject Borg service definitions written with mode 0644 by versions released before 2026-08-14. This defect prevented affected installations from updating, stopping, reinstalling, uninstalling, or rolling back the managed service.
- When a trusted, owner-owned regular service definition has extra read permission but no group or other write permission, the lifecycle command repairs its mode to 0600, re-inspects it, and continues.
- Foreign-owned, symbolic-linked, hard-linked, non-regular, oversized, and group- or other-writable definitions remain refused. The refusal identifies the definition path and states the required replacement and mode.
borgmcp-server 3.4.0
Package
- Registry: https://www.npmjs.com/package/borgmcp-server/v/3.4.0
- Live integrity:
sha512-ygun4Pt/LrShu9F/cRDw7LmQNnYUV0Cp7AbGjtIQfp2tluBxw5wADD6P4hAseVUGRX33jCoJk7a+3W6+GddsVg== - Published through npm Trusted Publishing with provenance.
Source
News and fixes
borgmcp-server 3.4.0
- The server now uses
borgmcp-shared1.2.0 while protocol tag 13 remains unchanged. This release adds input refusals without changing protocol shapes. - Migration 29 makes cube names unique per owner and role names unique per cube using ASCII case-insensitive comparison. Existing spelling and capitalization remain unchanged. A database containing names that differ only by ASCII letter case refuses to migrate, and the failed migration leaves its schema and rows unchanged.
- Creating a same-owner cube or same-cube role whose name differs from an existing name only by ASCII letter case now returns HTTP 409. Different owners may continue to use the same cube name, and a role may be renamed by changing only its capitalization.
- Role names must contain 1 to 64 bytes, start with an ASCII letter or number, and otherwise use only ASCII letters, numbers, spaces, periods, underscores, or hyphens.
- Repository association conformance now accepts a second repository association to the same cube and verifies that both associations remain observable.
- After borgmcp 4.9.0 is published, install borgmcp-server 3.4.0 and restart the live server. Migration 29 applies during that restart; report a collision refusal to the operator and never bypass it.
borgmcp-server 3.3.0
borgmcp-server 3.3.0
- The server now uses
borgmcp-shared1.1.0 and protocol tag 13. Protocol tags must match exactly: tag-12 clients receive HTTP 426, so borgmcp 4.6.x and earlier cannot talk to this server. Upgrade the client to borgmcp 4.7.0 or later together with this server release. - Migration 28 relabels legacy
defaultmetadata asstarterfor protocol-13 compatibility while existing Coordinator/Builder role state, grants, repository associations, and retry keys remain unchanged.selected_templaterecords creation provenance and presentation; roles remain independently mutable. After a store is opened by 3.3.0, older servers refuse its schema, so back up before upgrading if you may need to roll back. - Lifecycle commands now refuse obsolete or incomplete runtime locks and markerless historical launchd/systemd definitions instead of adopting them; stop the owning process or service, preserve or remove the obsolete state, then retry the same lifecycle command, following any leftover-registration command reported by uninstall. (#365)
- Managed-service controller actions now bind to the definition loaded by launchd or systemd before acting on the user-global service identity. Definition inspection requires the expected canonical, owner-owned, private regular file and covers the absent-job path, preventing an isolated lifecycle operation from acting on a live server owned by another runtime root. (#386)
- Teardown no longer retains a write-only failed-runtime set; failure paths still preserve the runtime lock when listener or store closure cannot be confirmed. (#366)
- The orphaned SBOM normalizer, verifier, dedicated tests, and release pins are removed. The release workflow continues to generate and ship no SBOM. (#367)
- Bootstrap results no longer expose the already-consumed initial owner invitation; owner enrollment and portable credential persistence are unchanged. (#369)
- Dormant test gates, the historical cube-binding operator harness, and test-only production exports are removed without changing supported runtime or package entry points. (#370)
borgmcp-server 3.2.3
Package
- Registry: https://www.npmjs.com/package/borgmcp-server/v/3.2.3
- Live integrity:
sha512-HUcrnBO+dhdEaAPIiJ9WjDkt8dDbWF/A6b6unyy3JFSuiHZLm/dPWhjDF0e+3yU6WzUusiItKxsbCksF2Y8gag== - Published through npm Trusted Publishing with provenance.
Source
News and fixes
borgmcp-server 3.2.3
- Activity reads enrich a page with three statements (entries with drone and role, recipients, document citations) instead of three statements per entry; a 500-entry page goes from 1,505 prepared statements to 8. Page payloads, ordering, cursors, counts and claims are unchanged. Tracked in #371.
- Runtime telemetry, including
slow_requestandslow_liveness_scan, now writes to<server data directory>/logs/runtime.log(10 MiB, three generations) instead oflogs/managed.stderr.log; existing managed stderr logs are preserved, and managed stderr remains the sink for startup, crash, debug, and liveness-failure output. (#373) - The runtime log sink is bounded in memory (1,024 records / 1 MiB) with a reserve so
slow_requestandslow_liveness_scansurvive saturation, repairs partial writes, validates and repairs the log tail at startup, and shuts down within a one-second bound. An unsafe log file (symlink, foreign owner, group/other access) disables runtime telemetry with one sanitized stderr warning; the server keeps serving. Recovery is documented in the operator reference. - No migration: schema stays at 27; 3.2.2 ↔ 3.2.3 stores are interchangeable.
- This release changes no API shape and no request behaviour.
borgmcp-server 3.2.2
Package
- Registry: https://www.npmjs.com/package/borgmcp-server/v/3.2.2
- Live integrity:
sha512-TGE0Fp+dIYY3kshAUsxF7T1tzWzIuovL+gSEDje1MrRWLX9Y91AzVFVzm9aWqxHGCweyqWlNYrA8g6WthOmFSg== - Published through npm Trusted Publishing with provenance.
Source
News and fixes
borgmcp-server 3.2.2
- The 60-second liveness scan runs as one transaction per tick instead of one autocommitted write per candidate; its SQL is cube/listener-scoped and keyset-batched; migration 26 adds a partial covering index on
activity_log(cube_id, created_at, id) WHERE visibility='direct'. Wake semantics are unchanged. This work is tracked in #371. - Roster reads (
GET /api/cubes/:cube_id/drones, plain andsince=) compute wake state for all drones in one set statement instead of one query per drone; payloads are unchanged field for field. - Activity append no longer sorts the expired-cursor ledger on every write; migration 27 adds an index on
expired_activity_cursors(cube_id, created_at, entry_id)and the ledger trim is one indexed set delete. Cap and cursor-expiry semantics are unchanged. - Every runtime log line now carries a UTC
tsfield; no other log field changes. - Migrations 26 and 27 are additive indexes applied on first open. A store that has been opened by 3.2.2 (schema 27) is refused by 3.2.1 with
MigrationCompatibilityError("Database migrations do not exactly match this server version."); 3.2.1 does not open it. Back up before upgrading if you may need to return to 3.2.1. - This release changes no API shape and no request behaviour. The measured effect on live stall frequency will be recorded on #371 from the 3.2.2 runtime log after deployment.