Skip to content

Releases: fgjcarlos/nodered-mcp

v0.7.2

Choose a tag to compare

@github-actions github-actions released this 24 Aug 11:07
b4bed4e

Changelog

  • d08268e chore(deps): bump actions/checkout from 4.4.0 to 7.0.1 (#286)
  • 7be1388 chore(deps): bump actions/download-artifact from 4.3.0 to 8.0.1 (#282)
  • ee3d33e chore(deps): bump actions/upload-artifact from 4.6.2 to 7.0.1 (#285)
  • b24de8d chore(deps): bump docker/login-action from 3.7.0 to 4.6.0 (#283)
  • 5842075 chore(deps): bump github.com/mark3labs/mcp-go (#287)
  • 941de33 chore(deps): bump goreleaser/goreleaser-action from 6.4.0 to 7.2.3 (#284)
  • b4bed4e chore(release): bump package metadata to v0.7.2 (#297)
  • e5a0be0 chore(release): pin and verify release toolchain (#295)
  • f3a4802 ci(diag): add id-token: write for provenance generation
  • 337bc37 ci(diag): remove the publish-main retry workflow (E403 root cause identified: see #281)
  • e78d748 ci(diag): retry publish-main via workflow_dispatch (one-off, delete after publish)
  • f5a2594 docs(npm): expand platform documentation for npm install matrix (#275)
  • 7e345a7 fix(init): detect Claude Desktop before config exists (#289)
  • 8992dce fix(release): serialize npm package promotion (#294)
  • 840e4fb fix(security): pin release Go toolchain (#293)

v0.7.1

Choose a tag to compare

@github-actions github-actions released this 06 Aug 12:58
2cdde9f

Changelog

  • 2cdde9f fix(npm): publish-main via NPM_SECRET while Trusted Publisher is disabled, bump to 0.7.1, scope guard (#279)
  • eb2cce1 fix(update): accept platform-package neighbour as npm channel (#276) (#277)

v0.7.0

Choose a tag to compare

@github-actions github-actions released this 05 Aug 22:48
0225a9a

Changelog

  • d507c45 diag: NO setup-node, just direct npm
  • d76254a diag: also trigger on push to bypass dispatch 422
  • 306bd5e diag: check NPM_SECRET permissions (temporary) (#266)
  • b311111 diag: clean residual dist-tags from previous test
  • 0cf4564 diag: fix yaml heredoc syntax
  • 4c965a7 diag: mirror workflow exactly with setup-node
  • 07bd661 diag: pass tarball as absolute path
  • 730d546 diag: publish the REAL workflow tarball
  • 3101ff6 diag: real publish of dummy scoped package to test scope permissions (#267)
  • 961a90d diag: tighter dist-tag cleanup
  • 4c692bc diag: trivial edit to retrigger
  • cdcd6b5 diag: use absolute path via env pwd
  • 60e0965 feat(npm): publish native platform packages and remove postinstall downloads (#261)
  • 581fbd7 fix(npm): drop --provenance from platform packages publish (#264)
  • 65af83a fix(npm): drop provenance from main package.json (#272)
  • 677eb45 fix(npm): drop provenance from platform package manifests (#265)
  • 0225a9a fix(npm): drop the separate pack main package step (#274)
  • 97ef2c0 fix(npm): normalize scoped platform tarball filenames (#263)
  • c1161bb fix(npm): publish main package using NPM_SECRET bypass-2FA token, no provenance (#271)
  • d66baf3 fix(npm): publish main package via OIDC (Trusted Publisher) only (#270)
  • ade879b fix(npm): remove registry-url from setup-node (root cause of E404) (#269)
  • f7046a1 fix(npm): restore installs from real GoReleaser archives in v0.6.3 (#259)
  • adcac55 fix(npm): split workflow into publish-platforms and publish-main jobs (#273)
  • 6140845 fix(npm): use absolute path for npm publish tarball (#268)
  • 3c50faa fix(release): promote npm latest only after canary verification (#262)
  • 97ea6ec test(release): validate real GoReleaser and npm artifacts before publication (#260)

v0.6.2

Choose a tag to compare

@github-actions github-actions released this 05 Aug 11:23

Changelog

  • b9f8930 Revert: drop lifecycle foundation (#245), pivot to npm/docker/go install (#247)
  • 0a51517 chore(community): add CoC, SUPPORT, FUNDING scaffold, social preview (#254)
  • 5437b3f chore(release): bump version to 0.6.2
  • 9718b46 chore(release): v0.6.1 — claude mcp add --scope user fix (#221)
  • a3d142d docs(changelog): cut 0.6.2 release notes
  • beeed1e docs(install): document goreleaser name_template layout invariant (#244)
  • e72606f feat(cli): add transactional setup and doctor lifecycle foundation (#245)
  • 45e785d feat(cli): define update check exit-status contract (#228) (#248)
  • f2cf089 fix(ci): establish deterministic release ordering (#226) (#240)
  • 1bc3838 fix(cli): omit init tokens and fail unsupported writes
  • f43a9fc fix(docker): make runnable defaults require explicit auth (#225) (#239)
  • 02fe842 fix(install): verify and atomically install postinstall binaries (#227) (#241)
  • 6e3241c fix(npm): restore Windows npm installation (#250) (#252)
  • ab0a457 fix(release): require every npm platform asset (#251) (#253)
  • b1479f9 fix(release): retire bin/install.js now that goreleaser doesn't rewrite it (#249)

v0.6.1

Choose a tag to compare

@github-actions github-actions released this 04 Aug 12:23

Changelog

  • 1145aa7 chore(release): bump to v0.6.1
  • aea5776 fix(init): register the Claude Code server with --scope user

v0.6.0

Choose a tag to compare

@github-actions github-actions released this 04 Aug 11:45
45fec98

Changelog

  • 89727bc chore(deps): bump actions/setup-go from 5.6.0 to 7.0.0 (#207)
  • cbc734c chore(deps): bump docker/build-push-action from 6.19.2 to 7.3.0 (#206)
  • 3d25515 chore(deps): bump docker/metadata-action from 5.10.0 to 6.2.0 (#205)
  • 2517a7f chore(deps): bump docker/setup-buildx-action from 3.12.0 to 4.2.0 (#203)
  • 0d71b6e chore(deps): bump docker/setup-qemu-action from 3.7.0 to 4.2.0 (#204)
  • 3c34822 chore(release): bump to v0.6.0 (#214)
  • 45fec98 chore(release): v0.6.0 fixups from Carlos's tarball (#220)
  • 96521c6 docs(plan): regenerate tool catalog with all 43 entries (closes #152) (#166)
  • c29f04e feat(mcp): add get_runtime_info with capability matrix (#168) (#212)
  • fd2b02e feat(mcp): startup banner reports detected NR version + degraded tools (#171) (#213)
  • 7c597b6 feat(nodered): central Node-RED version detection + min-version table (#170) (#211)
  • a3ea3e7 feat(npm): publish Windows on the npm channel (#192) (#196)
  • ee2fa1b fix(mcp): retry set_context inject once on first-call 404 (closes #158) (#165)
  • 2476373 fix(mcp): surface debug-stream-disabled hint at Warn level (#163)
  • c6d489c fix(mcp): translate 403 on /diagnostics to a setting hint (#169) (#209)
  • 8df36b4 fix(npm): declare os: [linux, darwin] so Windows aborts before postinstall (#191)
  • 2589993 fix(release): goreleaser v2 hook as plain string (was v1 map form) (#219)
  • a949bbd fix(release): install syft so goreleaser SBOM step can run (#216)
  • 0bc5d04 fix(release): install syft via upstream script (anchore/syft-action 404) (#217)
  • ff54733 fix(release): sync bin/install.js VERSION with tag via goreleaser before-hook (#218)
  • e63e783 release: bump version to 0.5.15 (#167)

v0.5.15

Choose a tag to compare

@github-actions github-actions released this 03 Aug 21:03

Changelog

  • 96521c6 docs(plan): regenerate tool catalog with all 43 entries (closes #152) (#166)
  • ee2fa1b fix(mcp): retry set_context inject once on first-call 404 (closes #158) (#165)
  • 2476373 fix(mcp): surface debug-stream-disabled hint at Warn level (#163)
  • e3f1945 release: bump version to 0.5.15

v0.5.14

Choose a tag to compare

@github-actions github-actions released this 03 Aug 12:06
3f48cf4

Changelog

  • 87d4633 chore(complexity): bump synthesizeFlowFromFlat baseline 15 to 16 (#155)
  • e100696 chore(deps): bump golang.org/x/text to v0.40.0 (#150)
  • db91e77 chore(git): enforce LF line endings across text sources (closes #67) (#124)
  • d257520 chore(lint): clean 3 staticcheck findings (#151)
  • 7cbc815 chore(npm): bump wrapper to 0.5.14 (#156)
  • 4a9744a chore(quality): add complexity ratchet and lower normalizeFlowDoc to 6 (closes #73 part 1) (#133)
  • 80788a5 chore(release): gate npm publish on bin/install.js VERSION match (#154)
  • b4b4d2e chore(security): document exec trust boundary, fail-closed confirm, fix ST1005 sentinel, expand SECURITY.md (closes #71) (#126)
  • 5d269d6 docs(readme): sync capabilities with the 37-tool MCP registry (closes #74) (#78)
  • 7b814bb feat(mcp): subflow CRUD + inject_node payload (closes #54) (#79)
  • fde981f fix(ci): disable Go module cache to unblock govulncheck (issue #66 follow-up) (#135)
  • c5cd001 fix(connect_nodes): cap port index at 999 to prevent OOM
  • 2f4f474 fix(init): never write or print the literal NODERED_TOKEN
  • bd7de5e fix(npm): point Windows install hint at scripts/install.ps1 and tell users to uninstall (#125)
  • 8229a2f fix(search_nodes): keep scoped packages like @flowfuse/node-red-dashboard
  • d9f1574 fix(security): bound Streamable HTTP timeouts (closes #68) (#76)
  • d592d54 fix(security): bump to Go 1.26.5 and gate govulncheck (closes #66) (#75)
  • 663a4a8 fix(security): default-deny exec/system node types to mitigate RCE
  • 8ef5aa3 fix(security): harden config and flow-backup filesystem writes (closes #70) (#77)
  • aacd899 fix(security): isolate npm-registry TLS from NODERED_INSECURE
  • d493c37 fix(security): reject non-http(s) schemes in NODERED_URL (SSRF guard)
  • d8aa62b fix(set_context): validate against the real runtime id, not the constant
  • f2edd90 fix(update): correct install.sh URL in standalone-binary channel (#148)
  • e4d4c25 fix: QA batch 2 — validate_flow parity + wire guards (#413, #414, #415)
  • beb0b75 fix: QA batch 3 — security hardening + correctness (#86, #88, #96, #97, #98)
  • b5498d2 fix: QA batch 4 — HTTP hardening + flow validation (#89, #90, #99, #100, #104, #106)
  • ee5a633 fix: QA batch 5 — final 10 issues (#101–#112)
  • 4120dce fix: QA batch 6 — final 6 issues (#113–#118)
  • b29bfe3 refactor(mcp): lower handleGetRuntimeLogs complexity to 14 (closes #73 part 4) (#137)
  • 3347ed6 refactor(mcp): lower handleSetContext complexity to 10 (closes #73 part 2) (#134)
  • 3733e9c refactor(mcp): split tools.go by domain without behaviour changes (closes #72) (#132)
  • fb97f43 refactor(nodered): lower ValidateFlow complexity to 10 (closes #73 part 3) (#136)
  • c693a5f test(cmd): skip TestExecutablePath_PrefersSymlinkTarget on Windows (#149)
  • 1423355 test(coverage): add CI ratchet + first batch of MCP/CLI boundary tests (#69, part 1) (#127)
  • 5a7eee9 test(coverage): cover cmd/nodered-mcp dispatch + renderFlowStatus/filterLogsByTime helpers (#69, part 5 — final) (#131)
  • 431e9de test(coverage): cover flows, node and subflow handlers (#69, part 2) (#128)
  • b27edcb test(coverage): cover palette, list_backups and diff_flows (#69, part 3) (#129)
  • 55063d4 test(coverage): cover settings, diagnostics, plugins, runtime state and search_nodes (#69, part 4) (#130)
  • e948825 test(coverage): raise cmd/nodered-mcp coverage by covering init.go seams (issue #69 part 7) (#139)
  • 90c0a6a test(coverage): raise cmd/nodered-mcp coverage by covering update.go seams (issue #69 part 6) (#138)

v0.5.13

Choose a tag to compare

@fgjcarlos fgjcarlos released this 28 Jul 22:06
24b3b11

What's new

validate_flow (read)

Dry-run the structural checks (dangling wires, duplicate / missing ids, missing x/y) against a flow document. Returns the full issue list — no runtime calls. Lets a model copy the same payload it would have written, run validate, and only commit if issues is empty.

disable_flow / enable_flow (write)

Toggle the disabled flag on an existing flow tab. Routes through editFlow so the snapshot, wire-validation, and writeMu guards from the granular node tools all apply.

inject_node now accepts an optional payload

Any JSON value. When supplied, the body is wrapped in the __user_inject_props__ envelope that Node-RED 5.x reads to forward the body to msg.payload. Without payload, the inject fires with its configured payload (unchanged behaviour).

inject_node id=X                          # unchanged
inject_node id=X payload={"foo":1}        # msg.payload = {"foo":1}

Requires Node-RED 5.x for the body to land; older releases silently ignore it.

Verified

go vet ./...
go test ./...            # race + cross-build + 3 OS, all green
go build ./...

HTTP smoke against NRCC's running Node-RED 5.0.1: bare POST → 200, with envelope → 200.

Closes #53, #54.

v0.5.12

Choose a tag to compare

@github-actions github-actions released this 27 Jul 23:08
1d33dc2

Changelog

  • 1d33dc2 chore(release): bump to v0.5.12 (#40)
  • 9a23484 fix(mcp): HTTP panic recovery + per-request logging, debug-stream onboarding (#39)
  • fbc0c11 fix(mcp): accept object/array payloads on add_node and update_flow (#36)
  • de0fe07 fix(nodered): fall back to GET /flows when /flow/:id 404s (#37)
  • 5a9b604 fix(nodered): serialize mutations, reject dangling refs, require x/y on add_node (#38)