Repository navigation
Releases: aegisgatesecurity/aegisgate-mcp
Release list
v1.4.2 — SSE WriteTimeout, Signature Verification, Concurrent Write Race
Council-Style Assessment #2 — Critical Fixes
Three production-impacting issues found in v1.4.1 and fixed.
🔴 Critical Fixes
-
SSE connections killed after 60 seconds — The HTTP server's
WriteTimeout: 60ssilently terminated long-lived SSE connections after one minute, breaking server-initiated notification delivery. Fixed:WriteTimeout: 0(disabled). Connection protection remains viaReadHeaderTimeout,ReadTimeout,IdleTimeout, and handler context cancellation. -
Signature verification missing from HTTP and stdio transports — ECDSA P-256 signature verification only worked on TCP. Now all three transports (TCP, HTTP, stdio) include the full security chain: auth → signature verification → guardrails → response scan → handler.
-
Concurrent SSE writes race condition —
broadcastNotification()wrote tohttp.ResponseWriterwithout per-connection synchronization. Fixed: addedsync.MutextosseConnstruct.
🟡 Other Changes
- Removed dead
evasionDetectorfield (instantiated but never wired) - SECURITY.md: 21→22 layers, HMAC-SHA256→ECDSA P-256, removed dead evasion row
- README.md: corrected test count (480→429) and coverage (90.8%/91.4%)
🧪 Tests
- 429 tests, 10 benchmarks, 3 fuzz targets
- 90.8% coverage (non-CGO), 91.4% (CGO)
- New:
TestBroadcastNotificationConcurrent,TestSSEServerWriteTimeoutZero go test -race -count=1 ./...— all pass
What's Changed
- docs: sync all doc versions to v1.4.1 by @jcolvin1056 in #34
- test: add SSE GET stream tests to restore CI coverage above 90% by @jcolvin1056 in #35
- fix(v1.4.2): SSE WriteTimeout, signature verification on all transports, concurrent SSE write race by @jcolvin1056 in #36
Full Changelog: v1.4.1...v1.4.2
v1.4.1 — Notification Pipeline Fix
Critical Fixes for v1.4.0 Notification Delivery
Fixed
- Notification JSON-RPC format: Created
JSONRPCNotificationtype with top-levelmethodfield per JSON-RPC 2.0 spec. Was incorrectly wrapped inJSONRPCResponse.Result— no MCP client could parse it - Notification callback wired in production:
SetNotifyCallback()now called inServeWithOptions()for HTTP transport. PreviouslyNotifyCallbackwas nil in production — all notification methods were silent no-ops - Long-lived SSE connections: SSE connections now held open after initial response. Per-session connection registry for broadcast delivery. Added GET /mcp endpoint per MCP 2025-06-18 spec
- comparison.md: "21-layer" → "22-layer"
Added
JSONRPCNotificationtype (proper JSON-RPC 2.0 notification format)- SSE connection registry (
sseConns) withbroadcastNotification() GET /mcpendpoint for pure notification streamshandleSSEStream()handler- End-to-end notification test (handler → broadcast → SSE → client)
Changed
writeSSEResponse()holds connection open, registers for notifications- Removed
makeNotificationCallback()(per-request), replaced with broadcast model - 480 tests, 90.1% coverage, race-free
What's Changed
- fix: sync all v1.3.0 references to v1.4.0 across repo by @jcolvin1056 in #32
- fix(v1.4.1): fix notification pipeline, long-lived SSE, proper JSON-RPC format by @jcolvin1056 in #33
Full Changelog: v1.4.0...v1.4.1
v1.4.0
What's Changed
- chore: harden .gitignore with additional ignore patterns by @jcolvin1056 in #24
- chore: bump server.json to v1.3.0 for MCP Registry submission by @jcolvin1056 in #25
- chore: trim server.json description for MCP Registry (95 chars) by @jcolvin1056 in #26
- fix: Docker badge rendering as '404 badge not found' by @jcolvin1056 in #27
- docs: integrator documentation update for v1.3.0 by @jcolvin1056 in #28
- chore: update Go 1.26.6 → 1.26.9 to resolve 14 CVE alerts by @jcolvin1056 in #29
- feat: v1.4.0 — server notifications, resource subscriptions, templates by @jcolvin1056 in #30
- fix: update workflows to Go 1.26.9 for release builds by @jcolvin1056 in #31
Full Changelog: v1.3.0...v1.4.0
v1.3.0 — SSE Streaming
SSE Streaming for Streamable HTTP Transport
Added
- SSE streaming responses. When a client sends POST with Accept: text/event-stream, the server responds with Content-Type: text/event-stream and streams JSON-RPC responses as Server-Sent Events (data: {json}\n\n). Notifications receive a comment ack (: ack\n\n).
- SSE headers: Cache-Control: no-cache, Connection: keep-alive
- Content negotiation between application/json and text/event-stream
Compatibility
- Clients without Accept: text/event-stream continue to receive plain JSON — fully backward compatible with v1.2.2
- SSE mode is opt-in only
Stats
- 426 tests, 91.3% coverage
- All tests pass with -race detector
- 22 security layers, zero external dependencies
What's Changed
- chore: add MCP Registry submission files (server.json, Docker LABEL) by @jcolvin1056 in #22
- feat: v1.3.0 — SSE streaming responses for Streamable HTTP transport by @jcolvin1056 in #23
Full Changelog: v1.2.2...v1.3.0
v1.2.2 — Session Management & Honesty Fixes
Session Management & Honesty Fixes
Changed
- Streamable HTTP transport: implemented
Mcp-Session-Idsupport per MCP 2025-06-18 spec. Server generates 256-bit session ID on initialize, returns it in theMcp-Session-Idresponse header, and validates it on all subsequent requests. Sessions expire after 30 minutes of inactivity. Clients can terminate a session by sendingDELETEto/mcpwith the session ID header (204 No Content). - Removed fake
resources/subscribeandresources/unsubscribestubs. These methods previously returned empty success without implementing anything. They now return method not found (JSON-RPC error code -32601). - Rewrote Streamable HTTP documentation comments. Previous comments claimed SSE streaming support that did not exist. Comments now accurately describe request/response mode only, with SSE noted as planned v1.3.0.
Added
DELETEmethod support on/mcpendpoint for session termination- Session lifecycle: creation, validation, touch on activity, expiry, client-initiated termination
- 8 new tests (420 total)
- v1.3.0 roadmap document
Security
- Session IDs: 256 bits of cryptographic randomness
- Invalid/expired sessions receive 404 Not Found
- DELETE without session header receives 400 Bad Request
Stats
- 420 tests, 91.2% coverage
- All tests pass with -race detector
- 22 security layers, zero external dependencies
What's Changed
- feat: v1.2.2 — Mcp-Session-Id support, honest comments, kill fake subscribe stubs by @jcolvin1056 in #21
Full Changelog: v1.2.1...v1.2.2
v1.2.1 — Protocol Compliance
Protocol Compliance Release
Changed
- Removed unimplemented capability advertisements from initialize response: listChanged (tools/resources/prompts) and subscribe (resources) are no longer advertised. The server only advertises what it actually implements.
- Version bumped from 1.2.0 to 1.2.1
Added
- Cursor-based pagination for tools/list, resources/list, prompts/list per MCP 2025-06-18 spec. Clients pass a cursor parameter; server returns nextCursor if more items are available. Default page size: 100 items.
- notifications/cancelled — client-initiated cancellation notification (MCP 2025-06-18). Logged and acknowledged; tool execution cancellation handled via existing context timeouts.
Security
- Honesty in capability advertisements: the server no longer claims to support features it doesn't implement.
Stats
- 396 tests (non-CGO) / 400 (CGO), 90.6% / 91.3% coverage
- All tests pass with -race detector
- 22 security layers, zero external dependencies
Assets
Signed binaries and SHA256 checksums will be attached when the release workflow completes.
What's Changed
- docs: polish README to match Rampart/Platform formatting by @jcolvin1056 in #18
- feat: v1.2.0 — Protocol 2025-06-18, Streamable HTTP, Tool Poisoning, Resources/Prompts, Model Hot-Swap by @jcolvin1056 in #19
- feat: v1.2.1 — Honest capabilities, cursor pagination, notifications/cancelled by @jcolvin1056 in #20
Full Changelog: v1.1.0...v1.2.1
v1.1.0
What's Changed
- feat: add ML wiring tests and .so hash verification by @jcolvin1056 in #7
- fix: resolve gosec/staticcheck findings, update deps, fix CI coverage by @jcolvin1056 in #8
- fix: add .gitleaks.toml to trivy skip-files by @jcolvin1056 in #9
- fix: upgrade Go 1.26.6, document accepted Debian CVEs by @jcolvin1056 in #10
- feat: multi-arch ARM64 Docker support by @jcolvin1056 in #11
- docs: trim README, fix trademark claims, broaden framing by @jcolvin1056 in #12
- feat: add ML inference throttle to prevent Platform dilution by @jcolvin1056 in #13
- docs: fix docs/ trademark, OT/ICS framing, Go version; add Platform upgrade path by @jcolvin1056 in #14
- docs: enable Discussions, add contact links, rewrite README with threat→solution narrative by @jcolvin1056 in #15
- fix: resolve release artifact download conflict by @jcolvin1056 in #16
- fix: use pattern-based artifact download to skip dockerbuild records by @jcolvin1056 in #17
New Contributors
- @jcolvin1056 made their first contribution in #7
Full Changelog: https://github.com/aegisgatesecurity/aegisgate-mcp/commits/v1.1.0