From 40a8f5626d7f8d71d9cae30fdcb133a9ce0fcb10 Mon Sep 17 00:00:00 2001 From: escott- Date: Fri, 2 Oct 2026 23:38:21 -0700 Subject: [PATCH] chore(release): prepare MCP 1.0.12 Bumps the workspace, npm package, MCP Registry metadata, and the boundary self-test to 1.0.12, and adds the 1.0.12 changelog covering #139, #140, #144, and #145. Updates rustls 0.23.40 -> 0.23.45 and rustls-webpki 0.103.13 -> 0.103.15 for RUSTSEC-2026-0285. The advisory predates 1.0.10 and was present in 1.0.10 and 1.0.11; cargo audit and cargo deny flagged it while validating #139, #140, #144, and #145 together. No other lockfile entries change. Co-Authored-By: Claude Sonnet 5.5 Signed-off-by: escott- --- .github/scripts/test_public_boundary.py | 2 +- CHANGELOG.md | 28 +++++++++++++++++++++++++ Cargo.lock | 24 ++++++++++----------- Cargo.toml | 14 ++++++------- package.json | 2 +- server.json | 4 ++-- 6 files changed, 51 insertions(+), 23 deletions(-) diff --git a/.github/scripts/test_public_boundary.py b/.github/scripts/test_public_boundary.py index b2ede0b..5d060ae 100644 --- a/.github/scripts/test_public_boundary.py +++ b/.github/scripts/test_public_boundary.py @@ -26,7 +26,7 @@ def test_private_search_names_are_rejected_in_public_comments_and_copy(self) -> boundary.verify_paths_and_source(root) def test_repository_satisfies_public_boundary(self) -> None: - self.assertEqual(boundary.verify(REPOSITORY_ROOT), "1.0.11") + self.assertEqual(boundary.verify(REPOSITORY_ROOT), "1.0.12") def test_forbidden_private_source_is_detected(self) -> None: with tempfile.TemporaryDirectory(prefix="public-boundary-") as temporary: diff --git a/CHANGELOG.md b/CHANGELOG.md index c27e18b..00b3090 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,33 @@ # Changelog +## 1.0.12 + +- Security: rustls 0.23.45 and rustls-webpki 0.103.15 replace 0.23.40 and + 0.103.13, which RUSTSEC-2026-0285 flags. rustls accepted TLS 1.3 handshake + messages sent at the wrong encryption level. The advisory is medium severity + (5.3) and does not let a network attacker alter or complete a handshake. +- Hooks: initialization is tracked per host session, so starting or resuming a + second session in the same checkout no longer blocks an initialized session + with "First call required". A successful `init` or `context` result completes + initialization, and the managed post-tool matcher now includes `context` and + `session` (#144). +- An empty project no longer reports `canonical_index_ready`: a reported file + count of 0 now outranks a "ready" label, so agents are not sent to an empty + search (#145). +- Shell code search (`rg`, `grep -r`, `find -name`) in a checkout with no + recorded index gets a non-blocking nudge to run `project(action="index")`, at + most once every 10 minutes per checkout (#145). +- `context()` keeps `instructions`, `matched_skills`, `coordination_inbox`, and + `grounding_hits` under the wire budget, trimming the large duplicate fields + first (#145). +- Global rules are written without a workspace identity, so setup runs in + different directories no longer leave different workspaces in the one global + file (#145). +- `testing/adoption` measures ContextStream search against shell search from + local agent transcripts (#145). +- Dependencies: hyper-util 0.1.21, tiktoken-rs 0.12.1, ignore 0.4.33, + tokio-test 0.4.6, and console 0.16.6 (#139). CI action pins updated (#140). + ## 1.0.11 - Optional deep project learning starts off. Interactive setup offers a separate review, diff --git a/Cargo.lock b/Cargo.lock index 18f371f..20ac56f 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -1624,7 +1624,7 @@ checksum = "47e1ffaa40ddd1f3ed91f717a33c8c0ee23fff369e3aa8772b9605cc1d22f4c3" [[package]] name = "mcp-acceleration-products" -version = "1.0.11" +version = "1.0.12" dependencies = [ "async-trait", "chrono", @@ -1642,7 +1642,7 @@ dependencies = [ [[package]] name = "mcp-client" -version = "1.0.11" +version = "1.0.12" dependencies = [ "anyhow", "base64 0.23.1", @@ -1670,7 +1670,7 @@ dependencies = [ [[package]] name = "mcp-model-registry" -version = "1.0.11" +version = "1.0.12" dependencies = [ "mcp-types", "serde", @@ -1679,7 +1679,7 @@ dependencies = [ [[package]] name = "mcp-server" -version = "1.0.11" +version = "1.0.12" dependencies = [ "anyhow", "async-trait", @@ -1736,7 +1736,7 @@ dependencies = [ [[package]] name = "mcp-session" -version = "1.0.11" +version = "1.0.12" dependencies = [ "chrono", "dashmap", @@ -1755,7 +1755,7 @@ dependencies = [ [[package]] name = "mcp-tools" -version = "1.0.11" +version = "1.0.12" dependencies = [ "anyhow", "async-trait", @@ -1791,7 +1791,7 @@ dependencies = [ [[package]] name = "mcp-types" -version = "1.0.11" +version = "1.0.12" dependencies = [ "async-trait", "chrono", @@ -2517,9 +2517,9 @@ dependencies = [ [[package]] name = "rustls" -version = "0.23.40" +version = "0.23.45" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "ef86cd5876211988985292b91c96a8f2d298df24e75989a43a3c73f2d4d8168b" +checksum = "0d41d731c7d2f962d1ccc364cec258de3c0e93b38c2fb3ba97ac74513048d634" dependencies = [ "once_cell", "ring", @@ -2541,9 +2541,9 @@ dependencies = [ [[package]] name = "rustls-webpki" -version = "0.103.13" +version = "0.103.15" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "61c429a8649f110dddef65e2a5ad240f747e85f7758a6bccc7e5777bd33f756e" +checksum = "f3c3cf1d8b1e7d4927e2d154c3fcb02979afb9939629c62cd9048d4f07b60ac2" dependencies = [ "ring", "rustls-pki-types", @@ -2870,7 +2870,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "32497e9a4c7b38532efcdebeef879707aa9f794296a4f0244f6f69e9bc8574bd" dependencies = [ "fastrand", - "getrandom 0.4.2", + "getrandom 0.3.4", "once_cell", "rustix", "windows-sys 0.61.2", diff --git a/Cargo.toml b/Cargo.toml index 0ff9a70..87073e2 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -11,7 +11,7 @@ members = [ ] [workspace.package] -version = "1.0.11" +version = "1.0.12" edition = "2021" rust-version = "1.95" license = "MIT" @@ -90,12 +90,12 @@ fs2 = "0.4" notify = "8" # Workspace crates -mcp-types = { version = "=1.0.11", path = "crates/mcp-types" } -mcp-client = { version = "=1.0.11", path = "crates/mcp-client" } -mcp-session = { version = "=1.0.11", path = "crates/mcp-session" } -mcp-tools = { version = "=1.0.11", path = "crates/mcp-tools" } -mcp-model-registry = { version = "=1.0.11", path = "crates/mcp-model-registry" } -mcp-acceleration-products = { version = "=1.0.11", path = "crates/mcp-acceleration-products" } +mcp-types = { version = "=1.0.12", path = "crates/mcp-types" } +mcp-client = { version = "=1.0.12", path = "crates/mcp-client" } +mcp-session = { version = "=1.0.12", path = "crates/mcp-session" } +mcp-tools = { version = "=1.0.12", path = "crates/mcp-tools" } +mcp-model-registry = { version = "=1.0.12", path = "crates/mcp-model-registry" } +mcp-acceleration-products = { version = "=1.0.12", path = "crates/mcp-acceleration-products" } # Testing mockall = "0.15" diff --git a/package.json b/package.json index 550caa1..f38072c 100644 --- a/package.json +++ b/package.json @@ -1,7 +1,7 @@ { "name": "@contextstream/mcp-server", "mcpName": "io.github.contextstream/mcp-server", - "version": "1.0.11", + "version": "1.0.12", "description": "Verified npm launcher for the open-source ContextStream Rust MCP server", "type": "module", "license": "MIT", diff --git a/server.json b/server.json index 1604caf..47bc168 100644 --- a/server.json +++ b/server.json @@ -3,7 +3,7 @@ "name": "io.github.contextstream/mcp-server", "title": "ContextStream MCP Server", "description": "Project memory, semantic code search, and grounded agent context.", - "version": "1.0.11", + "version": "1.0.12", "repository": { "url": "https://github.com/contextstream/mcp-server", "source": "github" @@ -20,7 +20,7 @@ "registryType": "npm", "registryBaseUrl": "https://registry.npmjs.org", "identifier": "@contextstream/mcp-server", - "version": "1.0.11", + "version": "1.0.12", "transport": { "type": "stdio" },