v2.1.1
Patch release.
- Security (#35): pin a
qsoverride (^6.15.2) to clear the transitive npm-audit DoS advisory (GHSA-q8mj-m7cp-5q26) and reinstate a cleannpm auditgate. No runtime behavior change. - Deps (#34): grouped minor+patch Dependabot bump (lockfile-only refresh of 5 transitive packages). No behavior changes.
Published to npm with provenance + submitted to the MCP Registry via publish-registry.yml.