v0.2.0
Added
-
MEALIE_ALLOW_TOOLSandMEALIE_DENY_TOOLSchoose which of the 52
tools are registered. Both take comma-separated tool names or a prefix with a
trailing*, the allow list decides what is in and the deny list is subtracted
from it, andMEALIE_ALLOW_TOOLS=essentialselects a curated eight —
search_recipes,get_recipe,import_recipe_from_url,create_recipe,get_todays_meals,create_mealplan_entry,list_shopping_lists,add_recipe_to_shopping_list. A model picks the right tool far more reliably from eight than
from fifty-two, and every visible tool costs context on every request. Nothing
changes for an installation that sets neither.A filtered tool is not registered at all, so it is absent from
tools/list
and answerstools/callwith "tool not found" — the same cut
MEALIE_READ_ONLYalready makes, not a second, weaker one.An entry that matches no tool stops the server at startup, naming the
entry and listing the real names, rather than being ignored: an ignored typo
leaves a tool missing fromtools/listwith nothing pointing at the cause.
Changed
- The README now carries the same eight badges, in the same order, as every other
MCP server in this family, all of them reading from npm rather than hard-coded;
the opening follows one shape; and the standalone "Full documentation" line is
gone, because the docs badge three lines above it points at the same page.
Fixed
- The container image no longer ships OpenSSL 3.5.7-r0, which carries
CVE-2026-14456 (denial of service via unbounded memory growth). The pinned
node:24-alpinedigest is already the newest one; Alpine's fixed 3.5.8-r0 has
simply not been rebuilt into it yet, so the runtime stage now upgrades
libcrypto3andlibssl3by name. Upgrading those two rather than running a
blanketapk upgradekeeps the rest of the image exactly as the digest pins
it. The step can go once the base image ships the fix.