---
summary: "Adopt @cyanheads/mcp-ts-core ^0.10.9: two new devcheck guards (floating dependency specifiers, plugin marketplace manifest correctness), ctx.content collector, Canvas SQL gate invalid_sql classification, DuckdbProvider.describe() filter fix; biome 2.5 + re-synced skills and scripts"
breaking: false
security: false
---

# 0.2.9 — 2026-06-20

## Added

- **`check-dependency-specifiers` devcheck step** — new `scripts/check-dependency-specifiers.ts`, registered in the devcheck run; hard-fails on floating specifiers (`latest`, `*`, pre-release dist-tags) in `package.json`'s dependency sections and `bun.lock`'s `workspaces` map. Catches a `latest` dist-tag written into the lock by `bun update --latest`, which otherwise lets the next `bun install` silently re-resolve past the manifest range. ([cyanheads/mcp-ts-core#246](https://github.com/cyanheads/mcp-ts-core/issues/246))
- **Plugin marketplace manifest checks in `lint:packaging`** — validates `.claude-plugin/plugin.json` and `.codex-plugin/plugin.json` (display fields carry the unscoped machine name; the `npx -y` install arg carries the full scoped package name). Gated by the new `devcheck.config.json` `packaging.pluginManifests` flag (on). ([cyanheads/mcp-ts-core#240](https://github.com/cyanheads/mcp-ts-core/issues/240))

## Changed

- **`@cyanheads/mcp-ts-core` ^0.10.6 → ^0.10.9.** Notable framework changes available to this server:
  - **`ctx.content`** — always-present collector on `Context` for non-text content blocks (image/audio bytes). Blocks are prepended to `content[]` after `format()` and never enter `structuredContent`. ([cyanheads/mcp-ts-core#239](https://github.com/cyanheads/mcp-ts-core/issues/239))
  - **Canvas SQL gate** — a `SELECT`-shaped statement that parses but fails to prepare (mistyped column, unknown function) now throws `ValidationError` with `data.reason: 'invalid_sql'` and the DuckDB binder detail, instead of the misleading `non_select_statement`. ([cyanheads/mcp-ts-core#236](https://github.com/cyanheads/mcp-ts-core/issues/236))
  - **`DuckdbProvider.describe({ tableName })`** — qualified the pushed `WHERE` filters with the `t` alias, fixing a DuckDB Binder Error (ambiguous column) on every filtered `describe()`. ([cyanheads/mcp-ts-core#235](https://github.com/cyanheads/mcp-ts-core/issues/235))
  - **Fresh-scaffold devcheck guards** — changelog-sync, TODO/secret/antipattern, and skill-version checks now skip cleanly when `.git` is absent. ([cyanheads/mcp-ts-core#242](https://github.com/cyanheads/mcp-ts-core/issues/242), [#243](https://github.com/cyanheads/mcp-ts-core/issues/243), [#237](https://github.com/cyanheads/mcp-ts-core/issues/237))
- **Re-synced skills and scripts** — 14 `skills/<name>/SKILL.md` files and 6 `scripts/*.ts` regenerated against the framework templates (biome 2.5 migration, the new dependency-specifier and plugin-manifest checks, `git-wrapup`/`orchestrations`/`polish-docs-meta` guidance refresh). ([cyanheads/mcp-ts-core#238](https://github.com/cyanheads/mcp-ts-core/issues/238))

### Dependency bumps

- `@cyanheads/mcp-ts-core` ^0.10.6 → ^0.10.9
- `@types/node` ^25.9.3 → ^26.0.0
