Verifying this release
Build provenance is attested with Sigstore. Verify before running:
gh attestation verify dist/cveasy-mcp --repo CVEasy/cveasy-mcpPinning the tool surface
Secure MCP profile control (a). This release advertises tool manifest digest:
9c8fdf423c47b653d8d66aa1a45d0f9cdc8df50eda6e5a0cfcbeaaf466af37c6
Set CVEASY_PINNED_MANIFEST to that value. If a later build offers different
tool definitions the pin fails, mutating tools are withheld, and tool_manifest
reports which per-tool digests changed so consent can be re-sought.
Pinning detects CHANGE. It does not certify that the pinned definition was
ever benign — see SECURITY.md.
What's Changed
- Fix conflated risk scores, expose the authoritative tenant-scoped TRIS, and implement the Secure MCP profile by @CVEasy in #1
- Stateless Streamable HTTP transport + public-repo hardening by @CVEasy in #2
New Contributors
Full Changelog: https://github.com/CVEasy/cveasy-mcp/commits/v0.1.0