Highlights
- Publishes npm releases through Trusted Publishing with automatic provenance and no long-lived write token.
- Publishes the matching server metadata to the official MCP Registry through GitHub OIDC.
- Rejects releases whose GitHub tag does not exactly match every package and runtime version.
- Extends the authenticated smoke test so maintainers can validate the exact public npm launcher.
Verified
- 112 typed MCP tools with approval-gated writes.
- 79 Python tests with 100% statement and branch coverage.
- 6 npm packaging and release-contract tests.
- macOS and Linux CI, real stdio handshake, authenticated live read-only smoke test, and CodeQL.
Install
npx -y @sickn33/tidal-mcp authThen configure any stdio-compatible MCP client to run npx -y @sickn33/tidal-mcp.