Skip to content

v0.7.1: mcp-ts-core ^0.10.10 security maintenance; tighter forecast/office-discussion descriptions

Choose a tag to compare

@cyanheads cyanheads released this 01 Jul 00:25
v0.7.1
61dfa5a

mcp-ts-core ^0.10.10 security maintenance; tighter forecast/office-discussion descriptions

Adopts the framework's security-driven transitive-dependency refresh and drops internal API-routing detail from two tool descriptions (#22).

Security:

  • Clears 8 transitive advisories (2 high, 6 moderate); bun audit now 0.
  • hono <4.12.25 → 4.12.27 (via mcp-ts-core): credentialed-wildcard CORS reflection (high), serve-static path traversal, Lambda Set-Cookie/Body-Limit/header-drop issues.
  • vite <=8.0.15 → 8.1.2 (via vitest): server.fs.deny bypass on Windows (high), launch-editor NTLMv2 hash disclosure.
  • js-yaml <3.15.0 → 3.15.0 (via depcheck): merge-key alias DoS; framework's js-yaml chain also dropped (moved to optional peer).

Changed:

  • nws_get_forecast: dropped "Internally resolves coordinates to the NWS grid" and the lat/lon "Truncated to 4 decimal places" note (#22).
  • nws_get_office_discussion: dropped the two-hop products-API routing note (#22).

Dependency bumps:

  • @cyanheads/mcp-ts-core ^0.10.9 → ^0.10.10

262 tests pass; bun run devcheck clean.