v3.2.1
Pre-release
Pre-release
Publication halted: the verified release candidate did not publish to npm because the recovery preflight misclassified npm's 404 response. No
oilpriceapi-mcp@3.2.1npm artifact or MCP Registry entry was created. This immutable tag is retained for audit history and is superseded by 3.2.2.
OilPriceAPI MCP 3.2.1
Product contract
- Adds typed product-facts v2 discovery while preserving a checksum-bound bridge for the currently deployed v1 contract.
- Fails closed on unknown fields, incompatible identity, future-dated remote reviews, malformed metadata, and checksum drift.
- Keeps pinned, canonical, and cached facts immutable once their checksum is assigned.
Runtime and packaging
- Reports tool inventory from the actual runtime registry for read and write scopes.
- Ships deterministic build metadata, exact capability metadata, and a pinned non-root Node container.
- Removes stale fixed catalog, allowance, plan, freshness, and tool-count claims from authored and packed surfaces.
Release integrity
- Requires protected-main release provenance and immutable workflow dependencies.
- Publishes the exact verified tarball with source-bound npm provenance.
- Validates the complete official MCP Registry record before npm publication and verifies public npm and Registry readback afterward.
The standard production smoke remains read-only. Subscription create/delete coverage is still explicit opt-in and was not enabled for this release.