Added
-
OPENGIST_ALLOW_TOOLSandOPENGIST_DENY_TOOLSchoose which of the 14
tools are registered. Both take comma-separated tool names or a prefix with a
trailing*, the allow list decides what is in and the deny list is subtracted
from it, andOPENGIST_ALLOW_TOOLS=essentialselects a curated seven —
list_gists,search_gists,get_gist,get_gist_file,create_gist,update_gist,delete_gist. A model picks the right tool far more reliably from seven than
from fourteen, and every visible tool costs context on every request. Nothing
changes for an installation that sets neither.A filtered tool is not registered at all, so it is absent from
tools/list
and answerstools/callwith "tool not found" — the same cut
OPENGIST_READ_ONLYalready makes, not a second, weaker one.An entry that matches no tool stops the server at startup, naming the
entry and listing the real names, rather than being ignored: an ignored typo
leaves a tool missing fromtools/listwith nothing pointing at the cause.
Changed
- The README now carries the same eight badges, in the same order, as every other
MCP server in this family, all of them reading from npm rather than hard-coded;
the opening follows one shape; and the standalone "Full documentation" line is
gone, because the docs badge three lines above it points at the same page.
Fixed
- The container image no longer ships OpenSSL 3.5.7-r0, which carries
CVE-2026-14456 (denial of service via unbounded memory growth). The pinned
node:24-alpinedigest is already the newest one; Alpine's fixed 3.5.8-r0 has
simply not been rebuilt into it yet, so the runtime stage now upgrades
libcrypto3andlibssl3by name. Upgrading those two rather than running a
blanketapk upgradekeeps the rest of the image exactly as the digest pins
it. The step can go once the base image ships the fix.