v3.2.2
OilPriceAPI MCP 3.2.2
This is the production publication of the reviewed 3.2 product-contract release. It supersedes the publication-halted v3.2.1 tag, for which no npm package or MCP Registry entry was created.
Product contract
- Adds typed product-facts v2 discovery while preserving a checksum-bound bridge for the currently deployed v1 contract.
- Fails closed on unknown fields, incompatible identity, future-dated remote reviews, malformed metadata, and checksum drift.
- Keeps pinned, canonical, and cached facts immutable once their checksum is assigned.
Runtime and packaging
- Reports tool inventory from the actual runtime registry for read and write scopes.
- Ships deterministic build metadata, exact capability metadata, and a pinned non-root Node container.
- Removes stale fixed catalog, allowance, plan, freshness, and tool-count claims from authored and packed surfaces.
Release integrity
- Requires protected-main release provenance and immutable workflow dependencies.
- Publishes the exact verified tarball with source-bound npm provenance.
- Treats only an exact npm Registry 404 as unpublished; malformed, conflicting, or unavailable registry responses fail closed.
- Validates the complete official MCP Registry record before npm publication and verifies public npm and Registry readback afterward.
The standard production smoke is read-only. Subscription create/delete coverage remains explicit opt-in and was not enabled for this release.