Skip to content

Releases: aegisgatesecurity/aegisgate-mcp

v1.4.2 — SSE WriteTimeout, Signature Verification, Concurrent Write Race

Choose a tag to compare

@jcolvin1056 jcolvin1056 released this 09 Oct 19:03
v1.4.2
e0743bd

Council-Style Assessment #2 — Critical Fixes

Three production-impacting issues found in v1.4.1 and fixed.

🔴 Critical Fixes

  1. SSE connections killed after 60 seconds — The HTTP server's WriteTimeout: 60s silently terminated long-lived SSE connections after one minute, breaking server-initiated notification delivery. Fixed: WriteTimeout: 0 (disabled). Connection protection remains via ReadHeaderTimeout, ReadTimeout, IdleTimeout, and handler context cancellation.

  2. Signature verification missing from HTTP and stdio transports — ECDSA P-256 signature verification only worked on TCP. Now all three transports (TCP, HTTP, stdio) include the full security chain: auth → signature verification → guardrails → response scan → handler.

  3. Concurrent SSE writes race condition — broadcastNotification() wrote to http.ResponseWriter without per-connection synchronization. Fixed: added sync.Mutex to sseConn struct.

🟡 Other Changes

  • Removed dead evasionDetector field (instantiated but never wired)
  • SECURITY.md: 21→22 layers, HMAC-SHA256→ECDSA P-256, removed dead evasion row
  • README.md: corrected test count (480→429) and coverage (90.8%/91.4%)

🧪 Tests

  • 429 tests, 10 benchmarks, 3 fuzz targets
  • 90.8% coverage (non-CGO), 91.4% (CGO)
  • New: TestBroadcastNotificationConcurrent, TestSSEServerWriteTimeoutZero
  • go test -race -count=1 ./... — all pass

What's Changed

  • docs: sync all doc versions to v1.4.1 by @jcolvin1056 in #34
  • test: add SSE GET stream tests to restore CI coverage above 90% by @jcolvin1056 in #35
  • fix(v1.4.2): SSE WriteTimeout, signature verification on all transports, concurrent SSE write race by @jcolvin1056 in #36

Full Changelog: v1.4.1...v1.4.2

v1.4.1 — Notification Pipeline Fix

Choose a tag to compare

@jcolvin1056 jcolvin1056 released this 09 Oct 18:17
v1.4.1
0878920

Critical Fixes for v1.4.0 Notification Delivery

Fixed

  • Notification JSON-RPC format: Created JSONRPCNotification type with top-level method field per JSON-RPC 2.0 spec. Was incorrectly wrapped in JSONRPCResponse.Result — no MCP client could parse it
  • Notification callback wired in production: SetNotifyCallback() now called in ServeWithOptions() for HTTP transport. Previously NotifyCallback was nil in production — all notification methods were silent no-ops
  • Long-lived SSE connections: SSE connections now held open after initial response. Per-session connection registry for broadcast delivery. Added GET /mcp endpoint per MCP 2025-06-18 spec
  • comparison.md: "21-layer" → "22-layer"

Added

  • JSONRPCNotification type (proper JSON-RPC 2.0 notification format)
  • SSE connection registry (sseConns) with broadcastNotification()
  • GET /mcp endpoint for pure notification streams
  • handleSSEStream() handler
  • End-to-end notification test (handler → broadcast → SSE → client)

Changed

  • writeSSEResponse() holds connection open, registers for notifications
  • Removed makeNotificationCallback() (per-request), replaced with broadcast model
  • 480 tests, 90.1% coverage, race-free

What's Changed

  • fix: sync all v1.3.0 references to v1.4.0 across repo by @jcolvin1056 in #32
  • fix(v1.4.1): fix notification pipeline, long-lived SSE, proper JSON-RPC format by @jcolvin1056 in #33

Full Changelog: v1.4.0...v1.4.1

v1.4.0

Choose a tag to compare

@github-actions github-actions released this 09 Oct 15:38
v1.4.0
0a6d2a8

What's Changed

  • chore: harden .gitignore with additional ignore patterns by @jcolvin1056 in #24
  • chore: bump server.json to v1.3.0 for MCP Registry submission by @jcolvin1056 in #25
  • chore: trim server.json description for MCP Registry (95 chars) by @jcolvin1056 in #26
  • fix: Docker badge rendering as '404 badge not found' by @jcolvin1056 in #27
  • docs: integrator documentation update for v1.3.0 by @jcolvin1056 in #28
  • chore: update Go 1.26.6 → 1.26.9 to resolve 14 CVE alerts by @jcolvin1056 in #29
  • feat: v1.4.0 — server notifications, resource subscriptions, templates by @jcolvin1056 in #30
  • fix: update workflows to Go 1.26.9 for release builds by @jcolvin1056 in #31

Full Changelog: v1.3.0...v1.4.0

v1.3.0 — SSE Streaming

Choose a tag to compare

@jcolvin1056 jcolvin1056 released this 08 Oct 21:30
v1.3.0
59d7f55

SSE Streaming for Streamable HTTP Transport

Added

  • SSE streaming responses. When a client sends POST with Accept: text/event-stream, the server responds with Content-Type: text/event-stream and streams JSON-RPC responses as Server-Sent Events (data: {json}\n\n). Notifications receive a comment ack (: ack\n\n).
  • SSE headers: Cache-Control: no-cache, Connection: keep-alive
  • Content negotiation between application/json and text/event-stream

Compatibility

  • Clients without Accept: text/event-stream continue to receive plain JSON — fully backward compatible with v1.2.2
  • SSE mode is opt-in only

Stats

  • 426 tests, 91.3% coverage
  • All tests pass with -race detector
  • 22 security layers, zero external dependencies

What's Changed

  • chore: add MCP Registry submission files (server.json, Docker LABEL) by @jcolvin1056 in #22
  • feat: v1.3.0 — SSE streaming responses for Streamable HTTP transport by @jcolvin1056 in #23

Full Changelog: v1.2.2...v1.3.0

v1.2.2 — Session Management & Honesty Fixes

Choose a tag to compare

@jcolvin1056 jcolvin1056 released this 08 Oct 20:44
v1.2.2
0669df1

Session Management & Honesty Fixes

Changed

  • Streamable HTTP transport: implemented Mcp-Session-Id support per MCP 2025-06-18 spec. Server generates 256-bit session ID on initialize, returns it in the Mcp-Session-Id response header, and validates it on all subsequent requests. Sessions expire after 30 minutes of inactivity. Clients can terminate a session by sending DELETE to /mcp with the session ID header (204 No Content).
  • Removed fake resources/subscribe and resources/unsubscribe stubs. These methods previously returned empty success without implementing anything. They now return method not found (JSON-RPC error code -32601).
  • Rewrote Streamable HTTP documentation comments. Previous comments claimed SSE streaming support that did not exist. Comments now accurately describe request/response mode only, with SSE noted as planned v1.3.0.

Added

  • DELETE method support on /mcp endpoint for session termination
  • Session lifecycle: creation, validation, touch on activity, expiry, client-initiated termination
  • 8 new tests (420 total)
  • v1.3.0 roadmap document

Security

  • Session IDs: 256 bits of cryptographic randomness
  • Invalid/expired sessions receive 404 Not Found
  • DELETE without session header receives 400 Bad Request

Stats

  • 420 tests, 91.2% coverage
  • All tests pass with -race detector
  • 22 security layers, zero external dependencies

What's Changed

  • feat: v1.2.2 — Mcp-Session-Id support, honest comments, kill fake subscribe stubs by @jcolvin1056 in #21

Full Changelog: v1.2.1...v1.2.2

v1.2.1 — Protocol Compliance

Choose a tag to compare

@jcolvin1056 jcolvin1056 released this 08 Oct 20:17
v1.2.1
06cf89d

Protocol Compliance Release

Changed

  • Removed unimplemented capability advertisements from initialize response: listChanged (tools/resources/prompts) and subscribe (resources) are no longer advertised. The server only advertises what it actually implements.
  • Version bumped from 1.2.0 to 1.2.1

Added

  • Cursor-based pagination for tools/list, resources/list, prompts/list per MCP 2025-06-18 spec. Clients pass a cursor parameter; server returns nextCursor if more items are available. Default page size: 100 items.
  • notifications/cancelled — client-initiated cancellation notification (MCP 2025-06-18). Logged and acknowledged; tool execution cancellation handled via existing context timeouts.

Security

  • Honesty in capability advertisements: the server no longer claims to support features it doesn't implement.

Stats

  • 396 tests (non-CGO) / 400 (CGO), 90.6% / 91.3% coverage
  • All tests pass with -race detector
  • 22 security layers, zero external dependencies

Assets

Signed binaries and SHA256 checksums will be attached when the release workflow completes.

What's Changed

  • docs: polish README to match Rampart/Platform formatting by @jcolvin1056 in #18
  • feat: v1.2.0 — Protocol 2025-06-18, Streamable HTTP, Tool Poisoning, Resources/Prompts, Model Hot-Swap by @jcolvin1056 in #19
  • feat: v1.2.1 — Honest capabilities, cursor pagination, notifications/cancelled by @jcolvin1056 in #20

Full Changelog: v1.1.0...v1.2.1

v1.1.0

Choose a tag to compare

@github-actions github-actions released this 08 Oct 16:22
v1.1.0
326dc1e

What's Changed

  • feat: add ML wiring tests and .so hash verification by @jcolvin1056 in #7
  • fix: resolve gosec/staticcheck findings, update deps, fix CI coverage by @jcolvin1056 in #8
  • fix: add .gitleaks.toml to trivy skip-files by @jcolvin1056 in #9
  • fix: upgrade Go 1.26.6, document accepted Debian CVEs by @jcolvin1056 in #10
  • feat: multi-arch ARM64 Docker support by @jcolvin1056 in #11
  • docs: trim README, fix trademark claims, broaden framing by @jcolvin1056 in #12
  • feat: add ML inference throttle to prevent Platform dilution by @jcolvin1056 in #13
  • docs: fix docs/ trademark, OT/ICS framing, Go version; add Platform upgrade path by @jcolvin1056 in #14
  • docs: enable Discussions, add contact links, rewrite README with threat→solution narrative by @jcolvin1056 in #15
  • fix: resolve release artifact download conflict by @jcolvin1056 in #16
  • fix: use pattern-based artifact download to skip dockerbuild records by @jcolvin1056 in #17

New Contributors

Full Changelog: https://github.com/aegisgatesecurity/aegisgate-mcp/commits/v1.1.0