Skip to content

2.9.0

Latest

Choose a tag to compare

@cliffhall cliffhall released this 30 Sep 22:23
ae865a1

What's Changed

  • docs(pr-flow): make an exhaustive Copilot review loop the step after opening a PR by @cliffhall in #2466
  • docs(pr-flow): assign the issue to yourself when work starts by @cliffhall in #2468
  • fix(skills): require ttlMs and cacheScope on modern skills/get results by @cliffhall in #2469
  • fix(skills): report a "dynamic" skill as unverifiable, not verified by @cliffhall in #2474
  • fix(web): mask the tail of a form secret split by a raw & by @cliffhall in #2475
  • fix(gate-lease): serve queued local:gate runs in arrival order by @cliffhall in #2476
  • fix(core): advertise the MCP Apps UI extension only from a client that renders Apps by @cliffhall in #2471
  • fix(remote): re-arm relay waits for string progress tokens by @cliffhall in #2478
  • fix(cli): end the long-lived stream cleanly on EPIPE by @cliffhall in #2479
  • docs(skills): get Copilot's testing → test-servers hand-off to 100% (#2459) by @cliffhall in #2477
  • fix(tui): cap rendered request/response body lines by @cliffhall in #2480
  • docs(pr-flow): make the In Progress / In Review card moves runnable, with a check by @cliffhall in #2472
  • docs(pr-flow): read the issue and all its comments before starting work by @cliffhall in #2491
  • fix(cli): redact URL query secrets in the error envelope by @cliffhall in #2488
  • chore(smoke): run smoke:tui for real in GitHub CI by @cliffhall in #2489
  • chore(deps): upgrade the MCP TypeScript SDK to 2.1.0 by @cliffhall in #2492
  • fix(web): prompt a reconnect when custom headers change on a live connection by @cliffhall in #2493
  • chore(scripts): fail fast when node_modules is older than its lockfile by @cliffhall in #2495
  • fix(cli): bound the OAuth browser open and say when it fails by @cliffhall in #2499
  • chore(tui): justify every exhaustive-deps suppression by @cliffhall in #2500
  • test(launcher,cli): assert Windows backslash paths survive argv forwarding by @cliffhall in #2501
  • fix(core): enforce one deadline per RequestInit in withOAuthRequestTimeout by @cliffhall in #2503
  • fix(docker): derive the HEALTHCHECK probe address from HOST by @cliffhall in #2504
  • chore(smoke): surface the app's connect error on a connect timeout by @cliffhall in #2505
  • fix(scripts): fail the Dependabot sweep clearly on a bad alert listing by @cliffhall in #2502
  • fix(auth): pin the AES-GCM auth tag length in FileSecretStore by @cliffhall in #2509
  • ci: split the npm release job so install scripts never hold the OIDC token by @cliffhall in #2506
  • fix(web): report the Inspector version as clientInfo.version by @cliffhall in #2511
  • test: stop the useServers render loop and guard against its return by @cliffhall in #2513
  • fix(docker): skip the web healthcheck probe under --cli/--tui by @cliffhall in #2510
  • test(web): configure React's act environment and wrap the updates it exposes by @cliffhall in #2514
  • SHA-pin the actions in credential-holding workflow jobs by @cliffhall in #2512
  • feat(auth): store acquired OAuth tokens in the secret store; clobber-safe oauth.json writes by @BobDickinson in #2482
  • docs: add MCP Inspector: Our AI Software Factory by @BobDickinson in #2498
  • fix(deps): make @modelcontextprotocol/server-legacy a devDependency by @cliffhall in #2520
  • chore(deps): upgrade the MCP TypeScript SDK to 2.2.0 by @cliffhall in #2526
  • chore(deps): upgrade the MCP Apps extension SDK to 2.0.3 by @cliffhall in #2527
  • chore(release): npm audit fixes and bump version to 2.9.0 by @cliffhall in #2529
  • fix(cli): catch an opener that cannot be spawned instead of crashing by @cliffhall in #2534
  • fix(core): redact a form secret's raw-& tail in recorded bodies by @cliffhall in #2535
  • fix(cli): split trailing punctuation off redacted URLs in linear time by @cliffhall in #2541
  • chore(release): merge v2/main into main for v2.9.0 by @cliffhall in #2536
  • fix(ci): publish the tarball by a ./ path so npm reads it as a file by @cliffhall in #2552
  • chore(release): merge v2/main into main for the v2.9.0 re-release (publish fix) by @cliffhall in #2553

Full Changelog: 2.8.0...2.9.0
Smoke test ledger for milestone branch: v2/chore/milestone-merge-v2.9.0

Known issue

OAuth profiles that share a server can overwrite each other's tokens (#2549). If you use MCP_INSPECTOR_OAUTH_STATE_PATH to keep separate OAuth profiles against the same server, give each profile its own secret store too: set MCP_INSPECTOR_SECRET_STORE=file and a distinct MCP_INSPECTOR_SECRET_FILE per profile (or a per-profile MCP_STORAGE_DIR). The default single-profile setup is unaffected. A fix is planned for 2.10.0.

Thanks for helping us improve

This release addresses issues reported by these community members. Thank you for taking the time to file them: