diff --git a/.changeset/everything-async-task-tools.md b/.changeset/everything-async-task-tools.md deleted file mode 100644 index ed0f3bc84a..0000000000 --- a/.changeset/everything-async-task-tools.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-everything": patch ---- - -Fix the async task tools: `trigger-elicitation-request-async` now stops polling before the 10-minute TTL it requests for the client's task runs out, instead of polling past it and failing on a task the client has expired (#4986); and `trigger-sampling-request-async` reports the status message of a client task that is already finished when it is created, instead of "No message" (#4987). `trigger-elicitation-request-async` had the same flaw and gets the same fix. diff --git a/.changeset/everything-blob-mime-type.md b/.changeset/everything-blob-mime-type.md deleted file mode 100644 index 8129a3a1e7..0000000000 --- a/.changeset/everything-blob-mime-type.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-everything": patch ---- - -Label dynamic blob resources `application/octet-stream`, matching their resource template, instead of `text/plain`. This applies to `resources/read`, the `get-resource-reference` and `get-resource-links` tools, and the `resource-prompt` prompt; blob resource links are now described as "binary blob resource". diff --git a/.changeset/everything-conditional-tools-4792.md b/.changeset/everything-conditional-tools-4792.md deleted file mode 100644 index 7e9a6c5656..0000000000 --- a/.changeset/everything-conditional-tools-4792.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-everything": patch ---- - -Server instructions no longer tell every client to use tools that are registered only for clients declaring a capability; they list those tools and the capability each needs (#4792, ported from #4835). `trigger-elicitation-request` and `trigger-elicitation-request-async` are now registered only for clients that support form-mode elicitation, so a client that declared only URL-mode elicitation no longer sees tools it cannot answer (#4985). diff --git a/.changeset/everything-no-tests-in-dist.md b/.changeset/everything-no-tests-in-dist.md deleted file mode 100644 index 3be8be9adf..0000000000 --- a/.changeset/everything-no-tests-in-dist.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-everything": patch ---- - -Stop shipping the compiled test suite and Vitest config in the published package: the build now excludes `__tests__/`, `*.test.ts`, `*.spec.ts` and `vitest.config.ts`, as the other TypeScript servers' builds do. diff --git a/.changeset/everything-session-resources-per-server.md b/.changeset/everything-session-resources-per-server.md deleted file mode 100644 index caea9ac495..0000000000 --- a/.changeset/everything-session-resources-per-server.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-everything": patch ---- - -Session resources are now tracked per server, so two sessions that create a session resource with the same name (for example via `gzip-file-as-resource`) no longer evict each other's resource (#4808). diff --git a/.changeset/everything-sse-session-errors.md b/.changeset/everything-sse-session-errors.md deleted file mode 100644 index 974a314da9..0000000000 --- a/.changeset/everything-sse-session-errors.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-everything": patch ---- - -The HTTP+SSE transport now answers requests for sessions it cannot serve instead of leaving them hanging or failing with a 500: `POST /message` for an unknown session returns `404` (and `400` with no `sessionId`), and `GET /sse?sessionId=…` returns `409` for a session that already has its stream and `404` for an unknown one. Each carries a JSON-RPC error body. diff --git a/.changeset/everything-streamable-http-sessions.md b/.changeset/everything-streamable-http-sessions.md deleted file mode 100644 index 721e1f7f0e..0000000000 --- a/.changeset/everything-streamable-http-sessions.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-everything": patch ---- - -Streamable HTTP: answer an unknown or ended session ID with `404 Not Found` (carrying the request's `id` on a POST) instead of `400`; replay only the resumed stream's events after a `Last-Event-ID`, and refuse an unknown one; close every open session on shutdown. diff --git a/.changeset/everything-testable-transports.md b/.changeset/everything-testable-transports.md deleted file mode 100644 index 5f8b911475..0000000000 --- a/.changeset/everything-testable-transports.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-everything": patch ---- - -Internal refactor for in-process testing, with no change in behavior: the launcher only starts a transport when run as the binary, and the stdio, SSE and Streamable HTTP transport modules export their start-up (`startStdioServer`, `startSseServer`, `startStreamableHttpServer`, and `createApp()` for the HTTP transports) instead of starting a server when imported. diff --git a/.changeset/filesystem-create-server.md b/.changeset/filesystem-create-server.md deleted file mode 100644 index 7c26e314d5..0000000000 --- a/.changeset/filesystem-create-server.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-filesystem": patch ---- - -Internal: the server is now built by a `createServer()` factory in `server.ts`, and `index.ts` starts it over stdio only when run as the bin, with each server instance holding its own allowed directories. No change to the tools, their results, or how the allowed directories are resolved from arguments and Roots. diff --git a/.changeset/filesystem-edit-line-endings-indent.md b/.changeset/filesystem-edit-line-endings-indent.md deleted file mode 100644 index 3e362fd793..0000000000 --- a/.changeset/filesystem-edit-line-endings-indent.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-filesystem": patch ---- - -`edit_file` keeps a file's line endings: a CRLF file is written back with CRLF instead of being converted to LF. When `oldText` has no exact match and the whitespace-tolerant matcher is used, each replacement line now takes the indentation of the file line it replaces, shifted by its indentation relative to the matching `oldText` line, instead of only the first line being reindented. diff --git a/.changeset/filesystem-in-place-write.md b/.changeset/filesystem-in-place-write.md deleted file mode 100644 index 45ec2c4648..0000000000 --- a/.changeset/filesystem-in-place-write.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-filesystem": patch ---- - -`write_file` and `edit_file` now overwrite an existing file in place instead of renaming a temp file over it, so the file keeps its inode, creation time (birthtime), hard links and permission bits (#4512), and an overwrite no longer fails with `EPERM` on Windows when another process holds the file open (#3199). A symlink swapped in after the path was validated is still refused rather than written through, now by an `O_NOFOLLOW` open (on POSIX) and a check that the opened file is the one validated (on every platform). The overwrite is no longer crash-atomic. A read-only file is now refused (`EACCES`, or `EPERM` on Windows) instead of being replaced, since writing in place opens the file itself for writing. diff --git a/.changeset/filesystem-initial-roots.md b/.changeset/filesystem-initial-roots.md deleted file mode 100644 index b887385c51..0000000000 --- a/.changeset/filesystem-initial-roots.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-filesystem": patch ---- - -Tool calls now wait for the client's initial roots before checking paths, so a call sent right after connecting is no longer refused with "Access denied" (#3204). A server started with no directories, connected to a client without Roots support, now fails visibly: it logs the reason, closes the connection and exits with status 1, instead of staying up and refusing every call (#4992). diff --git a/.changeset/filesystem-schema-dialect.md b/.changeset/filesystem-schema-dialect.md deleted file mode 100644 index 0579ae918b..0000000000 --- a/.changeset/filesystem-schema-dialect.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-filesystem": patch ---- - -Every tool's input and output schema in `tools/list` now declares `"$schema": "https://json-schema.org/draft/2020-12/schema"` instead of draft-07, so clients that validate tool schemas strictly against JSON Schema 2020-12 no longer reject every tool. The schemas are otherwise unchanged. diff --git a/.changeset/filesystem-unc-share-root.md b/.changeset/filesystem-unc-share-root.md deleted file mode 100644 index df29e88f31..0000000000 --- a/.changeset/filesystem-unc-share-root.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-filesystem": patch ---- - -On Windows, a UNC share root given as an allowed directory (`\\server\share` or `\\server\share\`) now admits the files and subdirectories under it. Before, only the share root itself was accessible and every path below it was refused. Sibling shares such as `\\server\share-evil` are still refused. diff --git a/.changeset/filesystem-unicode-paths.md b/.changeset/filesystem-unicode-paths.md deleted file mode 100644 index 1f24c07e6d..0000000000 --- a/.changeset/filesystem-unicode-paths.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-filesystem": patch ---- - -Paths that differ from the names on disk only in Unicode form now resolve (#1970). An NFC spelling of an allowed directory whose name is stored NFD (macOS "Capture d’écran", Japanese dakuten) is no longer refused as outside the allowed directories, and a request that spells a U+202F or U+00A0 in a name as a plain space (the macOS screenshot "Screenshot … at 2.40.40 PM.png") finds the file instead of failing with ENOENT. The exact spelling still wins when it exists, and a name matching two entries is refused as ambiguous. diff --git a/.changeset/memory-create-entities-skipped.md b/.changeset/memory-create-entities-skipped.md deleted file mode 100644 index 5ed174763d..0000000000 --- a/.changeset/memory-create-entities-skipped.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-memory": patch ---- - -`create_entities` now reports the entities it skipped because their name already exists (or repeats earlier in the same call): the structured result lists them in a new optional `skipped` array, a second text item names them and points to `add_observations`, and the tool description says so. Skipped entities are still not created and their observations are still not added (#4887). diff --git a/.changeset/memory-create-server-factory.md b/.changeset/memory-create-server-factory.md deleted file mode 100644 index 710e9243ca..0000000000 --- a/.changeset/memory-create-server-factory.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-memory": patch ---- - -Build the server with an exported `createServer()` factory and start stdio only when the package is run as a program, so importing the module no longer starts a server. Behavior over stdio is unchanged. diff --git a/.changeset/memory-cross-process-lock.md b/.changeset/memory-cross-process-lock.md deleted file mode 100644 index 32b61ec2d8..0000000000 --- a/.changeset/memory-cross-process-lock.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-memory": patch ---- - -Two server processes sharing one memory file no longer silently discard each other's writes: every write tool now holds an exclusive lock file (`.lock`) while it reads, changes and saves the graph, and a lock left by a crashed server is recovered automatically (#4797). diff --git a/.changeset/memory-file-path-base-dir.md b/.changeset/memory-file-path-base-dir.md deleted file mode 100644 index ec2f84b554..0000000000 --- a/.changeset/memory-file-path-base-dir.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-memory": patch ---- - -Internal: `ensureMemoryFilePath` accepts the directory its default files live in, so the server's tests no longer write into the package directory. No change to how the server chooses or migrates its memory file. diff --git a/.changeset/memory-keep-unreadable-lines.md b/.changeset/memory-keep-unreadable-lines.md deleted file mode 100644 index 71a30793ff..0000000000 --- a/.changeset/memory-keep-unreadable-lines.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-memory": patch ---- - -Lines in the memory file that the server cannot read (malformed JSON, an entity or relation that fails validation, an unknown record type) are no longer deleted by the next write. They are still left out of the graph, and are now written back unchanged after the graph's own lines. diff --git a/.changeset/memory-no-tests-in-dist.md b/.changeset/memory-no-tests-in-dist.md deleted file mode 100644 index 8d7588cd11..0000000000 --- a/.changeset/memory-no-tests-in-dist.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-memory": patch ---- - -Stop shipping the compiled test helper `dist/__tests__/helpers.js` in the published package: the build now excludes everything under `__tests__/`, not just `*.test.ts`. diff --git a/.changeset/memory-preserve-file-mode.md b/.changeset/memory-preserve-file-mode.md deleted file mode 100644 index a0180a0f66..0000000000 --- a/.changeset/memory-preserve-file-mode.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-memory": patch ---- - -Saving the knowledge graph keeps the memory file's permission bits (an operator's `0600` no longer comes back `0644`), and a write to a read-only memory file now fails with `EACCES` instead of silently replacing it (#4827). diff --git a/.changeset/sequentialthinking-annotations.md b/.changeset/sequentialthinking-annotations.md deleted file mode 100644 index 6c4974d857..0000000000 --- a/.changeset/sequentialthinking-annotations.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-sequential-thinking": patch ---- - -Advertise the `sequentialthinking` tool as `readOnlyHint: false` and `idempotentHint: false`. Every call appends to the server's thought history, and a call with both `branchFromThought` and `branchId` also appends to that branch, so the tool was never read-only or idempotent. `destructiveHint` and `openWorldHint` stay `false`. (#4721) diff --git a/.changeset/sequentialthinking-create-server.md b/.changeset/sequentialthinking-create-server.md deleted file mode 100644 index 91f8072d8a..0000000000 --- a/.changeset/sequentialthinking-create-server.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-sequential-thinking": patch ---- - -Build the server with an exported `createServer()` factory and attach stdio only when `index.js` runs as the binary, so the server can be tested in-process. No change to the tool, its schemas or its results. diff --git a/.changeset/sequentialthinking-log-header.md b/.changeset/sequentialthinking-log-header.md deleted file mode 100644 index aca9fdcfdf..0000000000 --- a/.changeset/sequentialthinking-log-header.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-sequential-thinking": patch ---- - -The thought log on stderr no longer prints "undefined" in its headers: a revision with no `revisesThought` reads "Revision N/M", and a branch with no `branchId` reads "(from thought N)" with no ID. The box border is sized from the header's visible text, so colour escape codes no longer make it wider than its text. diff --git a/.changeset/sequentialthinking-no-tests-in-dist.md b/.changeset/sequentialthinking-no-tests-in-dist.md deleted file mode 100644 index 7b760969f9..0000000000 --- a/.changeset/sequentialthinking-no-tests-in-dist.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-sequential-thinking": patch ---- - -Stop shipping the compiled test helper `dist/__tests__/helpers.js` in the published package: the build now excludes everything under `__tests__/`, not just `*.test.ts`. diff --git a/.changeset/sequentialthinking-prototype-branchid.md b/.changeset/sequentialthinking-prototype-branchid.md deleted file mode 100644 index dbc380da45..0000000000 --- a/.changeset/sequentialthinking-prototype-branchid.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-sequential-thinking": patch ---- - -A `branchId` that names an `Object.prototype` key, such as `"constructor"` or `"__proto__"`, now creates and lists its branch like any other id instead of failing the call. A call that fails no longer adds its thought to the history first, so `thoughtHistoryLength` counts only thoughts that were accepted. diff --git a/.changeset/sse-port-in-use.md b/.changeset/sse-port-in-use.md deleted file mode 100644 index 59c5dbd55e..0000000000 --- a/.changeset/sse-port-in-use.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@modelcontextprotocol/server-everything": patch ---- - -The HTTP+SSE transport no longer prints "Server is running" and stays up when its port is already in use: it reports the port and exits non-zero, as Streamable HTTP does. Streamable HTTP no longer prints its listening line before that error. diff --git a/package-lock.json b/package-lock.json index 6cdfdc7427..9c8c9a11db 100644 --- a/package-lock.json +++ b/package-lock.json @@ -5450,7 +5450,7 @@ }, "src/everything": { "name": "@modelcontextprotocol/server-everything", - "version": "1.0.0", + "version": "1.0.1", "license": "SEE LICENSE IN LICENSE", "dependencies": { "@modelcontextprotocol/sdk": "^1.30.0", @@ -5473,7 +5473,7 @@ }, "src/filesystem": { "name": "@modelcontextprotocol/server-filesystem", - "version": "1.0.0", + "version": "1.0.1", "license": "SEE LICENSE IN LICENSE", "dependencies": { "@modelcontextprotocol/sdk": "^1.30.0", @@ -5497,7 +5497,7 @@ }, "src/memory": { "name": "@modelcontextprotocol/server-memory", - "version": "1.0.0", + "version": "1.0.1", "license": "SEE LICENSE IN LICENSE", "dependencies": { "@modelcontextprotocol/sdk": "^1.30.0", @@ -5516,7 +5516,7 @@ }, "src/sequentialthinking": { "name": "@modelcontextprotocol/server-sequential-thinking", - "version": "1.0.0", + "version": "1.0.1", "license": "SEE LICENSE IN LICENSE", "dependencies": { "@modelcontextprotocol/sdk": "^1.30.0", diff --git a/src/everything/CHANGELOG.md b/src/everything/CHANGELOG.md new file mode 100644 index 0000000000..68f6f8da45 --- /dev/null +++ b/src/everything/CHANGELOG.md @@ -0,0 +1,23 @@ +# @modelcontextprotocol/server-everything + +## 1.0.1 + +### Patch Changes + +- [#5014](https://github.com/modelcontextprotocol/servers/pull/5014) [`8ea5e05`](https://github.com/modelcontextprotocol/servers/commit/8ea5e0541a448abc10f179dcb7807995336cde6e) Thanks [@cliffhall](https://github.com/cliffhall)! - Fix the async task tools: `trigger-elicitation-request-async` now stops polling before the 10-minute TTL it requests for the client's task runs out, instead of polling past it and failing on a task the client has expired ([#4986](https://github.com/modelcontextprotocol/servers/issues/4986)); and `trigger-sampling-request-async` reports the status message of a client task that is already finished when it is created, instead of "No message" ([#4987](https://github.com/modelcontextprotocol/servers/issues/4987)). `trigger-elicitation-request-async` had the same flaw and gets the same fix. + +- [#5005](https://github.com/modelcontextprotocol/servers/pull/5005) [`63dc92f`](https://github.com/modelcontextprotocol/servers/commit/63dc92f0e95992faf9d3e339cb8a51b1090d138b) Thanks [@cliffhall](https://github.com/cliffhall)! - Label dynamic blob resources `application/octet-stream`, matching their resource template, instead of `text/plain`. This applies to `resources/read`, the `get-resource-reference` and `get-resource-links` tools, and the `resource-prompt` prompt; blob resource links are now described as "binary blob resource". + +- [#5034](https://github.com/modelcontextprotocol/servers/pull/5034) [`6bed4c5`](https://github.com/modelcontextprotocol/servers/commit/6bed4c5f7c219e77fe90b9e4b14cdb9f3f7e9503) Thanks [@cliffhall](https://github.com/cliffhall)! - Server instructions no longer tell every client to use tools that are registered only for clients declaring a capability; they list those tools and the capability each needs ([#4792](https://github.com/modelcontextprotocol/servers/issues/4792), ported from [#4835](https://github.com/modelcontextprotocol/servers/issues/4835)). `trigger-elicitation-request` and `trigger-elicitation-request-async` are now registered only for clients that support form-mode elicitation, so a client that declared only URL-mode elicitation no longer sees tools it cannot answer ([#4985](https://github.com/modelcontextprotocol/servers/issues/4985)). + +- [#5053](https://github.com/modelcontextprotocol/servers/pull/5053) [`c63255a`](https://github.com/modelcontextprotocol/servers/commit/c63255ae9616b110d6089fa343fcfdf3f5def534) Thanks [@cliffhall](https://github.com/cliffhall)! - Stop shipping the compiled test suite and Vitest config in the published package: the build now excludes `__tests__/`, `*.test.ts`, `*.spec.ts` and `vitest.config.ts`, as the other TypeScript servers' builds do. + +- [#5032](https://github.com/modelcontextprotocol/servers/pull/5032) [`d4fb2f4`](https://github.com/modelcontextprotocol/servers/commit/d4fb2f4f11efc084d97958dbecefa12c03020bd9) Thanks [@cliffhall](https://github.com/cliffhall)! - Session resources are now tracked per server, so two sessions that create a session resource with the same name (for example via `gzip-file-as-resource`) no longer evict each other's resource ([#4808](https://github.com/modelcontextprotocol/servers/issues/4808)). + +- [#5020](https://github.com/modelcontextprotocol/servers/pull/5020) [`f7af617`](https://github.com/modelcontextprotocol/servers/commit/f7af617ead2d4c7faf10338159a280d6387a1475) Thanks [@cliffhall](https://github.com/cliffhall)! - The HTTP+SSE transport now answers requests for sessions it cannot serve instead of leaving them hanging or failing with a 500: `POST /message` for an unknown session returns `404` (and `400` with no `sessionId`), and `GET /sse?sessionId=…` returns `409` for a session that already has its stream and `404` for an unknown one. Each carries a JSON-RPC error body. + +- [#5006](https://github.com/modelcontextprotocol/servers/pull/5006) [`dbd1b2e`](https://github.com/modelcontextprotocol/servers/commit/dbd1b2e699714074c6355ddf60e1fb832f139d7f) Thanks [@cliffhall](https://github.com/cliffhall)! - Streamable HTTP: answer an unknown or ended session ID with `404 Not Found` (carrying the request's `id` on a POST) instead of `400`; replay only the resumed stream's events after a `Last-Event-ID`, and refuse an unknown one; close every open session on shutdown. + +- [#4970](https://github.com/modelcontextprotocol/servers/pull/4970) [`c449b5e`](https://github.com/modelcontextprotocol/servers/commit/c449b5e71b7c9cc926a39799a2dcf0ec401d3a20) Thanks [@cliffhall](https://github.com/cliffhall)! - Internal refactor for in-process testing, with no change in behavior: the launcher only starts a transport when run as the binary, and the stdio, SSE and Streamable HTTP transport modules export their start-up (`startStdioServer`, `startSseServer`, `startStreamableHttpServer`, and `createApp()` for the HTTP transports) instead of starting a server when imported. + +- [#4936](https://github.com/modelcontextprotocol/servers/pull/4936) [`feb251d`](https://github.com/modelcontextprotocol/servers/commit/feb251d2fd0057570125ba0ba25e98c84f8c5b5c) Thanks [@cliffhall](https://github.com/cliffhall)! - The HTTP+SSE transport no longer prints "Server is running" and stays up when its port is already in use: it reports the port and exits non-zero, as Streamable HTTP does. Streamable HTTP no longer prints its listening line before that error. diff --git a/src/everything/package.json b/src/everything/package.json index e65007cdc4..3640f43f8b 100644 --- a/src/everything/package.json +++ b/src/everything/package.json @@ -1,6 +1,6 @@ { "name": "@modelcontextprotocol/server-everything", - "version": "1.0.0", + "version": "1.0.1", "description": "MCP server that exercises all the features of the MCP protocol", "license": "SEE LICENSE IN LICENSE", "mcpName": "io.github.modelcontextprotocol/server-everything", diff --git a/src/filesystem/CHANGELOG.md b/src/filesystem/CHANGELOG.md new file mode 100644 index 0000000000..95b169345a --- /dev/null +++ b/src/filesystem/CHANGELOG.md @@ -0,0 +1,19 @@ +# @modelcontextprotocol/server-filesystem + +## 1.0.1 + +### Patch Changes + +- [#4970](https://github.com/modelcontextprotocol/servers/pull/4970) [`3a63f52`](https://github.com/modelcontextprotocol/servers/commit/3a63f52e751882e20b24e8f0c840d402348bbd72) Thanks [@cliffhall](https://github.com/cliffhall)! - Internal: the server is now built by a `createServer()` factory in `server.ts`, and `index.ts` starts it over stdio only when run as the bin, with each server instance holding its own allowed directories. No change to the tools, their results, or how the allowed directories are resolved from arguments and Roots. + +- [#5011](https://github.com/modelcontextprotocol/servers/pull/5011) [`d8ebdbe`](https://github.com/modelcontextprotocol/servers/commit/d8ebdbef770768c05d9fddbb663bc6f380a08867) Thanks [@cliffhall](https://github.com/cliffhall)! - `edit_file` keeps a file's line endings: a CRLF file is written back with CRLF instead of being converted to LF. When `oldText` has no exact match and the whitespace-tolerant matcher is used, each replacement line now takes the indentation of the file line it replaces, shifted by its indentation relative to the matching `oldText` line, instead of only the first line being reindented. + +- [#5022](https://github.com/modelcontextprotocol/servers/pull/5022) [`7dc802f`](https://github.com/modelcontextprotocol/servers/commit/7dc802f914a727e840b65712b0a9fbaf7fe1c2b5) Thanks [@cliffhall](https://github.com/cliffhall)! - `write_file` and `edit_file` now overwrite an existing file in place instead of renaming a temp file over it, so the file keeps its inode, creation time (birthtime), hard links and permission bits ([#4512](https://github.com/modelcontextprotocol/servers/issues/4512)), and an overwrite no longer fails with `EPERM` on Windows when another process holds the file open ([#3199](https://github.com/modelcontextprotocol/servers/issues/3199)). A symlink swapped in after the path was validated is still refused rather than written through, now by an `O_NOFOLLOW` open (on POSIX) and a check that the opened file is the one validated (on every platform). The overwrite is no longer crash-atomic. A read-only file is now refused (`EACCES`, or `EPERM` on Windows) instead of being replaced, since writing in place opens the file itself for writing. + +- [#5025](https://github.com/modelcontextprotocol/servers/pull/5025) [`2309e08`](https://github.com/modelcontextprotocol/servers/commit/2309e089b12385650e52784e26668aabdbc9b74b) Thanks [@cliffhall](https://github.com/cliffhall)! - Tool calls now wait for the client's initial roots before checking paths, so a call sent right after connecting is no longer refused with "Access denied" ([#3204](https://github.com/modelcontextprotocol/servers/issues/3204)). A server started with no directories, connected to a client without Roots support, now fails visibly: it logs the reason, closes the connection and exits with status 1, instead of staying up and refusing every call ([#4992](https://github.com/modelcontextprotocol/servers/issues/4992)). + +- [#5030](https://github.com/modelcontextprotocol/servers/pull/5030) [`5c04d74`](https://github.com/modelcontextprotocol/servers/commit/5c04d74ff6430ae82763aae76b3b1e585f5f13fd) Thanks [@cliffhall](https://github.com/cliffhall)! - Every tool's input and output schema in `tools/list` now declares `"$schema": "https://json-schema.org/draft/2020-12/schema"` instead of draft-07, so clients that validate tool schemas strictly against JSON Schema 2020-12 no longer reject every tool. The schemas are otherwise unchanged. + +- [#5010](https://github.com/modelcontextprotocol/servers/pull/5010) [`fd4dff7`](https://github.com/modelcontextprotocol/servers/commit/fd4dff7da877068734bee9419fa935213d66e359) Thanks [@cliffhall](https://github.com/cliffhall)! - On Windows, a UNC share root given as an allowed directory (`\\server\share` or `\\server\share\`) now admits the files and subdirectories under it. Before, only the share root itself was accessible and every path below it was refused. Sibling shares such as `\\server\share-evil` are still refused. + +- [#5009](https://github.com/modelcontextprotocol/servers/pull/5009) [`f621c75`](https://github.com/modelcontextprotocol/servers/commit/f621c75a92347738f28f26c9461286764beba3c8) Thanks [@cliffhall](https://github.com/cliffhall)! - Paths that differ from the names on disk only in Unicode form now resolve ([#1970](https://github.com/modelcontextprotocol/servers/issues/1970)). An NFC spelling of an allowed directory whose name is stored NFD (macOS "Capture d’écran", Japanese dakuten) is no longer refused as outside the allowed directories, and a request that spells a U+202F or U+00A0 in a name as a plain space (the macOS screenshot "Screenshot … at 2.40.40 PM.png") finds the file instead of failing with ENOENT. The exact spelling still wins when it exists, and a name matching two entries is refused as ambiguous. diff --git a/src/filesystem/package.json b/src/filesystem/package.json index 5ee6d9498f..ac78e67d6b 100644 --- a/src/filesystem/package.json +++ b/src/filesystem/package.json @@ -1,6 +1,6 @@ { "name": "@modelcontextprotocol/server-filesystem", - "version": "1.0.0", + "version": "1.0.1", "description": "MCP server for filesystem access", "license": "SEE LICENSE IN LICENSE", "mcpName": "io.github.modelcontextprotocol/server-filesystem", diff --git a/src/memory/CHANGELOG.md b/src/memory/CHANGELOG.md new file mode 100644 index 0000000000..76775a9af7 --- /dev/null +++ b/src/memory/CHANGELOG.md @@ -0,0 +1,19 @@ +# @modelcontextprotocol/server-memory + +## 1.0.1 + +### Patch Changes + +- [#5008](https://github.com/modelcontextprotocol/servers/pull/5008) [`bb8aa6f`](https://github.com/modelcontextprotocol/servers/commit/bb8aa6fd73b2a2fd68bc7084292296d2b0084780) Thanks [@cliffhall](https://github.com/cliffhall)! - `create_entities` now reports the entities it skipped because their name already exists (or repeats earlier in the same call): the structured result lists them in a new optional `skipped` array, a second text item names them and points to `add_observations`, and the tool description says so. Skipped entities are still not created and their observations are still not added ([#4887](https://github.com/modelcontextprotocol/servers/issues/4887)). + +- [#4970](https://github.com/modelcontextprotocol/servers/pull/4970) [`a8127ba`](https://github.com/modelcontextprotocol/servers/commit/a8127ba956c12c7f6597b43765f1f7a68aee0d7e) Thanks [@cliffhall](https://github.com/cliffhall)! - Build the server with an exported `createServer()` factory and start stdio only when the package is run as a program, so importing the module no longer starts a server. Behavior over stdio is unchanged. + +- [#5037](https://github.com/modelcontextprotocol/servers/pull/5037) [`7be08e9`](https://github.com/modelcontextprotocol/servers/commit/7be08e97f399721c215de52bfb74a5030c20f78f) Thanks [@cliffhall](https://github.com/cliffhall)! - Two server processes sharing one memory file no longer silently discard each other's writes: every write tool now holds an exclusive lock file (`.lock`) while it reads, changes and saves the graph, and a lock left by a crashed server is recovered automatically ([#4797](https://github.com/modelcontextprotocol/servers/issues/4797)). + +- [#4937](https://github.com/modelcontextprotocol/servers/pull/4937) [`478db6a`](https://github.com/modelcontextprotocol/servers/commit/478db6a5d5bc0bec3196e2c8c9461ec1597ded34) Thanks [@cliffhall](https://github.com/cliffhall)! - Internal: `ensureMemoryFilePath` accepts the directory its default files live in, so the server's tests no longer write into the package directory. No change to how the server chooses or migrates its memory file. + +- [#5035](https://github.com/modelcontextprotocol/servers/pull/5035) [`2b1305f`](https://github.com/modelcontextprotocol/servers/commit/2b1305fc0db794cdf1bd57ca83d13fb8a195e869) Thanks [@cliffhall](https://github.com/cliffhall)! - Lines in the memory file that the server cannot read (malformed JSON, an entity or relation that fails validation, an unknown record type) are no longer deleted by the next write. They are still left out of the graph, and are now written back unchanged after the graph's own lines. + +- [#5053](https://github.com/modelcontextprotocol/servers/pull/5053) [`c63255a`](https://github.com/modelcontextprotocol/servers/commit/c63255ae9616b110d6089fa343fcfdf3f5def534) Thanks [@cliffhall](https://github.com/cliffhall)! - Stop shipping the compiled test helper `dist/__tests__/helpers.js` in the published package: the build now excludes everything under `__tests__/`, not just `*.test.ts`. + +- [#5013](https://github.com/modelcontextprotocol/servers/pull/5013) [`819ae90`](https://github.com/modelcontextprotocol/servers/commit/819ae904cc08ab0b208ccb91addc3169b3ece85b) Thanks [@cliffhall](https://github.com/cliffhall)! - Saving the knowledge graph keeps the memory file's permission bits (an operator's `0600` no longer comes back `0644`), and a write to a read-only memory file now fails with `EACCES` instead of silently replacing it ([#4827](https://github.com/modelcontextprotocol/servers/issues/4827)). diff --git a/src/memory/package.json b/src/memory/package.json index 3ce170f295..bdefe4b095 100644 --- a/src/memory/package.json +++ b/src/memory/package.json @@ -1,6 +1,6 @@ { "name": "@modelcontextprotocol/server-memory", - "version": "1.0.0", + "version": "1.0.1", "description": "MCP server for enabling memory for Claude through a knowledge graph", "license": "SEE LICENSE IN LICENSE", "mcpName": "io.github.modelcontextprotocol/server-memory", diff --git a/src/sequentialthinking/CHANGELOG.md b/src/sequentialthinking/CHANGELOG.md new file mode 100644 index 0000000000..95a9c84d50 --- /dev/null +++ b/src/sequentialthinking/CHANGELOG.md @@ -0,0 +1,15 @@ +# @modelcontextprotocol/server-sequential-thinking + +## 1.0.1 + +### Patch Changes + +- [#5015](https://github.com/modelcontextprotocol/servers/pull/5015) [`8a4139c`](https://github.com/modelcontextprotocol/servers/commit/8a4139c3d71b66e95d2f7cd2bc485d4781ecf1d7) Thanks [@cliffhall](https://github.com/cliffhall)! - Advertise the `sequentialthinking` tool as `readOnlyHint: false` and `idempotentHint: false`. Every call appends to the server's thought history, and a call with both `branchFromThought` and `branchId` also appends to that branch, so the tool was never read-only or idempotent. `destructiveHint` and `openWorldHint` stay `false`. ([#4721](https://github.com/modelcontextprotocol/servers/issues/4721)) + +- [#4970](https://github.com/modelcontextprotocol/servers/pull/4970) [`86806cc`](https://github.com/modelcontextprotocol/servers/commit/86806cc3870a112f56870e86cd36bae8239edb02) Thanks [@cliffhall](https://github.com/cliffhall)! - Build the server with an exported `createServer()` factory and attach stdio only when `index.js` runs as the binary, so the server can be tested in-process. No change to the tool, its schemas or its results. + +- [#5031](https://github.com/modelcontextprotocol/servers/pull/5031) [`bc52d0e`](https://github.com/modelcontextprotocol/servers/commit/bc52d0e07a1d9dca505746165b30f4c99f8cc79b) Thanks [@cliffhall](https://github.com/cliffhall)! - The thought log on stderr no longer prints "undefined" in its headers: a revision with no `revisesThought` reads "Revision N/M", and a branch with no `branchId` reads "(from thought N)" with no ID. The box border is sized from the header's visible text, so colour escape codes no longer make it wider than its text. + +- [#5053](https://github.com/modelcontextprotocol/servers/pull/5053) [`c63255a`](https://github.com/modelcontextprotocol/servers/commit/c63255ae9616b110d6089fa343fcfdf3f5def534) Thanks [@cliffhall](https://github.com/cliffhall)! - Stop shipping the compiled test helper `dist/__tests__/helpers.js` in the published package: the build now excludes everything under `__tests__/`, not just `*.test.ts`. + +- [#5036](https://github.com/modelcontextprotocol/servers/pull/5036) [`b5c5ccc`](https://github.com/modelcontextprotocol/servers/commit/b5c5cccb79a5d43b41247065fb9efd174363e799) Thanks [@cliffhall](https://github.com/cliffhall)! - A `branchId` that names an `Object.prototype` key, such as `"constructor"` or `"__proto__"`, now creates and lists its branch like any other id instead of failing the call. A call that fails no longer adds its thought to the history first, so `thoughtHistoryLength` counts only thoughts that were accepted. diff --git a/src/sequentialthinking/package.json b/src/sequentialthinking/package.json index 91814c7de7..21b484a110 100644 --- a/src/sequentialthinking/package.json +++ b/src/sequentialthinking/package.json @@ -1,6 +1,6 @@ { "name": "@modelcontextprotocol/server-sequential-thinking", - "version": "1.0.0", + "version": "1.0.1", "description": "MCP server for sequential thinking and problem solving", "license": "SEE LICENSE IN LICENSE", "mcpName": "io.github.modelcontextprotocol/server-sequential-thinking",