v0.7.1: mcp-ts-core ^0.10.10 security maintenance; tighter forecast/office-discussion descriptions
mcp-ts-core ^0.10.10 security maintenance; tighter forecast/office-discussion descriptions
Adopts the framework's security-driven transitive-dependency refresh and drops internal API-routing detail from two tool descriptions (#22).
Security:
- Clears 8 transitive advisories (2 high, 6 moderate); bun audit now 0.
- hono <4.12.25 → 4.12.27 (via mcp-ts-core): credentialed-wildcard CORS reflection (high), serve-static path traversal, Lambda Set-Cookie/Body-Limit/header-drop issues.
- vite <=8.0.15 → 8.1.2 (via vitest): server.fs.deny bypass on Windows (high), launch-editor NTLMv2 hash disclosure.
- js-yaml <3.15.0 → 3.15.0 (via depcheck): merge-key alias DoS; framework's js-yaml chain also dropped (moved to optional peer).
Changed:
- nws_get_forecast: dropped "Internally resolves coordinates to the NWS grid" and the lat/lon "Truncated to 4 decimal places" note (#22).
- nws_get_office_discussion: dropped the two-hop products-API routing note (#22).
Dependency bumps:
- @cyanheads/mcp-ts-core ^0.10.9 → ^0.10.10
262 tests pass; bun run devcheck clean.