Releases: fgjcarlos/nodered-mcp
Release list
v0.7.2
Changelog
- d08268e chore(deps): bump actions/checkout from 4.4.0 to 7.0.1 (#286)
- 7be1388 chore(deps): bump actions/download-artifact from 4.3.0 to 8.0.1 (#282)
- ee3d33e chore(deps): bump actions/upload-artifact from 4.6.2 to 7.0.1 (#285)
- b24de8d chore(deps): bump docker/login-action from 3.7.0 to 4.6.0 (#283)
- 5842075 chore(deps): bump github.com/mark3labs/mcp-go (#287)
- 941de33 chore(deps): bump goreleaser/goreleaser-action from 6.4.0 to 7.2.3 (#284)
- b4bed4e chore(release): bump package metadata to v0.7.2 (#297)
- e5a0be0 chore(release): pin and verify release toolchain (#295)
- f3a4802 ci(diag): add id-token: write for provenance generation
- 337bc37 ci(diag): remove the publish-main retry workflow (E403 root cause identified: see #281)
- e78d748 ci(diag): retry publish-main via workflow_dispatch (one-off, delete after publish)
- f5a2594 docs(npm): expand platform documentation for npm install matrix (#275)
- 7e345a7 fix(init): detect Claude Desktop before config exists (#289)
- 8992dce fix(release): serialize npm package promotion (#294)
- 840e4fb fix(security): pin release Go toolchain (#293)
v0.7.1
v0.7.0
Changelog
- d507c45 diag: NO setup-node, just direct npm
- d76254a diag: also trigger on push to bypass dispatch 422
- 306bd5e diag: check NPM_SECRET permissions (temporary) (#266)
- b311111 diag: clean residual dist-tags from previous test
- 0cf4564 diag: fix yaml heredoc syntax
- 4c965a7 diag: mirror workflow exactly with setup-node
- 07bd661 diag: pass tarball as absolute path
- 730d546 diag: publish the REAL workflow tarball
- 3101ff6 diag: real publish of dummy scoped package to test scope permissions (#267)
- 961a90d diag: tighter dist-tag cleanup
- 4c692bc diag: trivial edit to retrigger
- cdcd6b5 diag: use absolute path via env pwd
- 60e0965 feat(npm): publish native platform packages and remove postinstall downloads (#261)
- 581fbd7 fix(npm): drop --provenance from platform packages publish (#264)
- 65af83a fix(npm): drop provenance from main package.json (#272)
- 677eb45 fix(npm): drop provenance from platform package manifests (#265)
- 0225a9a fix(npm): drop the separate pack main package step (#274)
- 97ef2c0 fix(npm): normalize scoped platform tarball filenames (#263)
- c1161bb fix(npm): publish main package using NPM_SECRET bypass-2FA token, no provenance (#271)
- d66baf3 fix(npm): publish main package via OIDC (Trusted Publisher) only (#270)
- ade879b fix(npm): remove registry-url from setup-node (root cause of E404) (#269)
- f7046a1 fix(npm): restore installs from real GoReleaser archives in v0.6.3 (#259)
- adcac55 fix(npm): split workflow into publish-platforms and publish-main jobs (#273)
- 6140845 fix(npm): use absolute path for npm publish tarball (#268)
- 3c50faa fix(release): promote npm latest only after canary verification (#262)
- 97ea6ec test(release): validate real GoReleaser and npm artifacts before publication (#260)
v0.6.2
Changelog
- b9f8930 Revert: drop lifecycle foundation (#245), pivot to npm/docker/go install (#247)
- 0a51517 chore(community): add CoC, SUPPORT, FUNDING scaffold, social preview (#254)
- 5437b3f chore(release): bump version to 0.6.2
- 9718b46 chore(release): v0.6.1 — claude mcp add --scope user fix (#221)
- a3d142d docs(changelog): cut 0.6.2 release notes
- beeed1e docs(install): document goreleaser name_template layout invariant (#244)
- e72606f feat(cli): add transactional setup and doctor lifecycle foundation (#245)
- 45e785d feat(cli): define update check exit-status contract (#228) (#248)
- f2cf089 fix(ci): establish deterministic release ordering (#226) (#240)
- 1bc3838 fix(cli): omit init tokens and fail unsupported writes
- f43a9fc fix(docker): make runnable defaults require explicit auth (#225) (#239)
- 02fe842 fix(install): verify and atomically install postinstall binaries (#227) (#241)
- 6e3241c fix(npm): restore Windows npm installation (#250) (#252)
- ab0a457 fix(release): require every npm platform asset (#251) (#253)
- b1479f9 fix(release): retire bin/install.js now that goreleaser doesn't rewrite it (#249)
v0.6.1
v0.6.0
Changelog
- 89727bc chore(deps): bump actions/setup-go from 5.6.0 to 7.0.0 (#207)
- cbc734c chore(deps): bump docker/build-push-action from 6.19.2 to 7.3.0 (#206)
- 3d25515 chore(deps): bump docker/metadata-action from 5.10.0 to 6.2.0 (#205)
- 2517a7f chore(deps): bump docker/setup-buildx-action from 3.12.0 to 4.2.0 (#203)
- 0d71b6e chore(deps): bump docker/setup-qemu-action from 3.7.0 to 4.2.0 (#204)
- 3c34822 chore(release): bump to v0.6.0 (#214)
- 45fec98 chore(release): v0.6.0 fixups from Carlos's tarball (#220)
- 96521c6 docs(plan): regenerate tool catalog with all 43 entries (closes #152) (#166)
- c29f04e feat(mcp): add get_runtime_info with capability matrix (#168) (#212)
- fd2b02e feat(mcp): startup banner reports detected NR version + degraded tools (#171) (#213)
- 7c597b6 feat(nodered): central Node-RED version detection + min-version table (#170) (#211)
- a3ea3e7 feat(npm): publish Windows on the npm channel (#192) (#196)
- ee2fa1b fix(mcp): retry set_context inject once on first-call 404 (closes #158) (#165)
- 2476373 fix(mcp): surface debug-stream-disabled hint at Warn level (#163)
- c6d489c fix(mcp): translate 403 on /diagnostics to a setting hint (#169) (#209)
- 8df36b4 fix(npm): declare os: [linux, darwin] so Windows aborts before postinstall (#191)
- 2589993 fix(release): goreleaser v2 hook as plain string (was v1 map form) (#219)
- a949bbd fix(release): install syft so goreleaser SBOM step can run (#216)
- 0bc5d04 fix(release): install syft via upstream script (anchore/syft-action 404) (#217)
- ff54733 fix(release): sync bin/install.js VERSION with tag via goreleaser before-hook (#218)
- e63e783 release: bump version to 0.5.15 (#167)
v0.5.15
v0.5.14
Changelog
- 87d4633 chore(complexity): bump synthesizeFlowFromFlat baseline 15 to 16 (#155)
- e100696 chore(deps): bump golang.org/x/text to v0.40.0 (#150)
- db91e77 chore(git): enforce LF line endings across text sources (closes #67) (#124)
- d257520 chore(lint): clean 3 staticcheck findings (#151)
- 7cbc815 chore(npm): bump wrapper to 0.5.14 (#156)
- 4a9744a chore(quality): add complexity ratchet and lower normalizeFlowDoc to 6 (closes #73 part 1) (#133)
- 80788a5 chore(release): gate npm publish on bin/install.js VERSION match (#154)
- b4b4d2e chore(security): document exec trust boundary, fail-closed confirm, fix ST1005 sentinel, expand SECURITY.md (closes #71) (#126)
- 5d269d6 docs(readme): sync capabilities with the 37-tool MCP registry (closes #74) (#78)
- 7b814bb feat(mcp): subflow CRUD + inject_node payload (closes #54) (#79)
- fde981f fix(ci): disable Go module cache to unblock govulncheck (issue #66 follow-up) (#135)
- c5cd001 fix(connect_nodes): cap port index at 999 to prevent OOM
- 2f4f474 fix(init): never write or print the literal NODERED_TOKEN
- bd7de5e fix(npm): point Windows install hint at scripts/install.ps1 and tell users to uninstall (#125)
- 8229a2f fix(search_nodes): keep scoped packages like @flowfuse/node-red-dashboard
- d9f1574 fix(security): bound Streamable HTTP timeouts (closes #68) (#76)
- d592d54 fix(security): bump to Go 1.26.5 and gate govulncheck (closes #66) (#75)
- 663a4a8 fix(security): default-deny exec/system node types to mitigate RCE
- 8ef5aa3 fix(security): harden config and flow-backup filesystem writes (closes #70) (#77)
- aacd899 fix(security): isolate npm-registry TLS from NODERED_INSECURE
- d493c37 fix(security): reject non-http(s) schemes in NODERED_URL (SSRF guard)
- d8aa62b fix(set_context): validate against the real runtime id, not the constant
- f2edd90 fix(update): correct install.sh URL in standalone-binary channel (#148)
- e4d4c25 fix: QA batch 2 — validate_flow parity + wire guards (#413, #414, #415)
- beb0b75 fix: QA batch 3 — security hardening + correctness (#86, #88, #96, #97, #98)
- b5498d2 fix: QA batch 4 — HTTP hardening + flow validation (#89, #90, #99, #100, #104, #106)
- ee5a633 fix: QA batch 5 — final 10 issues (#101–#112)
- 4120dce fix: QA batch 6 — final 6 issues (#113–#118)
- b29bfe3 refactor(mcp): lower handleGetRuntimeLogs complexity to 14 (closes #73 part 4) (#137)
- 3347ed6 refactor(mcp): lower handleSetContext complexity to 10 (closes #73 part 2) (#134)
- 3733e9c refactor(mcp): split tools.go by domain without behaviour changes (closes #72) (#132)
- fb97f43 refactor(nodered): lower ValidateFlow complexity to 10 (closes #73 part 3) (#136)
- c693a5f test(cmd): skip TestExecutablePath_PrefersSymlinkTarget on Windows (#149)
- 1423355 test(coverage): add CI ratchet + first batch of MCP/CLI boundary tests (#69, part 1) (#127)
- 5a7eee9 test(coverage): cover cmd/nodered-mcp dispatch + renderFlowStatus/filterLogsByTime helpers (#69, part 5 — final) (#131)
- 431e9de test(coverage): cover flows, node and subflow handlers (#69, part 2) (#128)
- b27edcb test(coverage): cover palette, list_backups and diff_flows (#69, part 3) (#129)
- 55063d4 test(coverage): cover settings, diagnostics, plugins, runtime state and search_nodes (#69, part 4) (#130)
- e948825 test(coverage): raise cmd/nodered-mcp coverage by covering init.go seams (issue #69 part 7) (#139)
- 90c0a6a test(coverage): raise cmd/nodered-mcp coverage by covering update.go seams (issue #69 part 6) (#138)
v0.5.13
What's new
validate_flow (read)
Dry-run the structural checks (dangling wires, duplicate / missing ids, missing x/y) against a flow document. Returns the full issue list — no runtime calls. Lets a model copy the same payload it would have written, run validate, and only commit if issues is empty.
disable_flow / enable_flow (write)
Toggle the disabled flag on an existing flow tab. Routes through editFlow so the snapshot, wire-validation, and writeMu guards from the granular node tools all apply.
inject_node now accepts an optional payload
Any JSON value. When supplied, the body is wrapped in the __user_inject_props__ envelope that Node-RED 5.x reads to forward the body to msg.payload. Without payload, the inject fires with its configured payload (unchanged behaviour).
inject_node id=X # unchanged
inject_node id=X payload={"foo":1} # msg.payload = {"foo":1}
Requires Node-RED 5.x for the body to land; older releases silently ignore it.
Verified
go vet ./...
go test ./... # race + cross-build + 3 OS, all green
go build ./...
HTTP smoke against NRCC's running Node-RED 5.0.1: bare POST → 200, with envelope → 200.
v0.5.12
Changelog
- 1d33dc2 chore(release): bump to v0.5.12 (#40)
- 9a23484 fix(mcp): HTTP panic recovery + per-request logging, debug-stream onboarding (#39)
- fbc0c11 fix(mcp): accept object/array payloads on add_node and update_flow (#36)
- de0fe07 fix(nodered): fall back to GET /flows when /flow/:id 404s (#37)
- 5a9b604 fix(nodered): serialize mutations, reject dangling refs, require x/y on add_node (#38)