Skip to content

v0.9.0-alpha

Pre-release
Pre-release

Choose a tag to compare

@nicotem nicotem released this 30 Jul 10:07
· 546 commits to main since this release

QualCoder MCP is now on PyPI. Install with one command:

pip install qualcoder-mcp

(or pipx install qualcoder-mcp / uv tool install qualcoder-mcp for an isolated install). Full setup — including the Claude Desktop / Claude Code configuration — is in the README and INSTALL.md.

This is an alpha. Please work on copies of your projects, never originals.

What's in this release

This is a packaging and hardening release — no new analysis features (those land in 0.10). It exists to make the tool easy to install and update, and to close what a full security review found.

  • PyPI packaging — pip install qualcoder-mcp, and updates become pip install --upgrade qualcoder-mcp. No more git clone.
  • Whole-codebase security audit — an adversarial review of all 67 tools. It found the architecture sound (no attacker-reachable vulnerability) and produced three fixes: the write-cleanup guarantee extended to three older tools, an export path-resolution hardening, and SHA-pinned CI actions.
  • Critical dependency fix — capped the mcp SDK at <2. Its 2.0.0 removed the module this server is built on, which was silently breaking fresh installs; capped and verified.
  • Upgrade guide for existing testers — if you installed via git clone before 0.9, see INSTALL.md → Upgrading from an earlier (git) install. You can stay on git or switch to the PyPI install; your projects and AI-coding sessions are untouched by upgrading, and jumping 0.6/0.7/0.8 → 0.9 in one step is fine (no data migration).

Requires

Python 3.10+, a Claude client (Desktop or Code), QualCoder 3.8.x with at least one project. macOS, Linux, or Windows.

Support & privacy

Bugs, questions, ideas → GitHub Issues (SUPPORT.md).

One important note: by design this tool sends your project content — including interview text — to Claude (Anthropic) for analysis. Please use synthetic or consented data and check your ethics/GDPR position before pointing it at real participant data — PRIVACY.md explains exactly what flows where.

Full changelog: CHANGELOG.md. MIT licensed, no warranty.