What's Changed
- docs(pr-flow): make an exhaustive Copilot review loop the step after opening a PR by @cliffhall in #2466
- docs(pr-flow): assign the issue to yourself when work starts by @cliffhall in #2468
- fix(skills): require ttlMs and cacheScope on modern skills/get results by @cliffhall in #2469
- fix(skills): report a "dynamic" skill as unverifiable, not verified by @cliffhall in #2474
- fix(web): mask the tail of a form secret split by a raw & by @cliffhall in #2475
- fix(gate-lease): serve queued local:gate runs in arrival order by @cliffhall in #2476
- fix(core): advertise the MCP Apps UI extension only from a client that renders Apps by @cliffhall in #2471
- fix(remote): re-arm relay waits for string progress tokens by @cliffhall in #2478
- fix(cli): end the long-lived stream cleanly on EPIPE by @cliffhall in #2479
- docs(skills): get Copilot's testing → test-servers hand-off to 100% (#2459) by @cliffhall in #2477
- fix(tui): cap rendered request/response body lines by @cliffhall in #2480
- docs(pr-flow): make the In Progress / In Review card moves runnable, with a check by @cliffhall in #2472
- docs(pr-flow): read the issue and all its comments before starting work by @cliffhall in #2491
- fix(cli): redact URL query secrets in the error envelope by @cliffhall in #2488
- chore(smoke): run smoke:tui for real in GitHub CI by @cliffhall in #2489
- chore(deps): upgrade the MCP TypeScript SDK to 2.1.0 by @cliffhall in #2492
- fix(web): prompt a reconnect when custom headers change on a live connection by @cliffhall in #2493
- chore(scripts): fail fast when node_modules is older than its lockfile by @cliffhall in #2495
- fix(cli): bound the OAuth browser open and say when it fails by @cliffhall in #2499
- chore(tui): justify every exhaustive-deps suppression by @cliffhall in #2500
- test(launcher,cli): assert Windows backslash paths survive argv forwarding by @cliffhall in #2501
- fix(core): enforce one deadline per RequestInit in withOAuthRequestTimeout by @cliffhall in #2503
- fix(docker): derive the HEALTHCHECK probe address from HOST by @cliffhall in #2504
- chore(smoke): surface the app's connect error on a connect timeout by @cliffhall in #2505
- fix(scripts): fail the Dependabot sweep clearly on a bad alert listing by @cliffhall in #2502
- fix(auth): pin the AES-GCM auth tag length in FileSecretStore by @cliffhall in #2509
- ci: split the npm release job so install scripts never hold the OIDC token by @cliffhall in #2506
- fix(web): report the Inspector version as clientInfo.version by @cliffhall in #2511
- test: stop the useServers render loop and guard against its return by @cliffhall in #2513
- fix(docker): skip the web healthcheck probe under --cli/--tui by @cliffhall in #2510
- test(web): configure React's act environment and wrap the updates it exposes by @cliffhall in #2514
- SHA-pin the actions in credential-holding workflow jobs by @cliffhall in #2512
- feat(auth): store acquired OAuth tokens in the secret store; clobber-safe oauth.json writes by @BobDickinson in #2482
- docs: add MCP Inspector: Our AI Software Factory by @BobDickinson in #2498
- fix(deps): make @modelcontextprotocol/server-legacy a devDependency by @cliffhall in #2520
- chore(deps): upgrade the MCP TypeScript SDK to 2.2.0 by @cliffhall in #2526
- chore(deps): upgrade the MCP Apps extension SDK to 2.0.3 by @cliffhall in #2527
- chore(release): npm audit fixes and bump version to 2.9.0 by @cliffhall in #2529
- fix(cli): catch an opener that cannot be spawned instead of crashing by @cliffhall in #2534
- fix(core): redact a form secret's raw-& tail in recorded bodies by @cliffhall in #2535
- fix(cli): split trailing punctuation off redacted URLs in linear time by @cliffhall in #2541
- chore(release): merge v2/main into main for v2.9.0 by @cliffhall in #2536
- fix(ci): publish the tarball by a ./ path so npm reads it as a file by @cliffhall in #2552
- chore(release): merge v2/main into main for the v2.9.0 re-release (publish fix) by @cliffhall in #2553
Full Changelog: 2.8.0...2.9.0
Smoke test ledger for milestone branch: v2/chore/milestone-merge-v2.9.0
Known issue
OAuth profiles that share a server can overwrite each other's tokens (#2549). If you use MCP_INSPECTOR_OAUTH_STATE_PATH to keep separate OAuth profiles against the same server, give each profile its own secret store too: set MCP_INSPECTOR_SECRET_STORE=file and a distinct MCP_INSPECTOR_SECRET_FILE per profile (or a per-profile MCP_STORAGE_DIR). The default single-profile setup is unaffected. A fix is planned for 2.10.0.
Thanks for helping us improve
This release addresses issues reported by these community members. Thank you for taking the time to file them: