---
summary: "Fixed: unpaired date-range boundaries silently ignored (#22) and confusing GDELT query-rejection errors (#18); mcp-ts-core ^0.10.9 → ^0.10.14 clears 8 transitive advisories; new install-time supply-chain guard"
breaking: false
security: false
---

# 0.2.3 — 2026-07-15

## Added

- **Supply-chain install guard** — `bunfig.toml` sets `minimumReleaseAge = 259200` (3 days), blocking freshly published package versions at install time (`@cyanheads/mcp-ts-core` is excluded via `minimumReleaseAgeExcludes`, adopted same-day). `[install.security].scanner` wires in `@socketsecurity/bun-security-scanner` for pre-install malware/typosquat/CVE scanning.

## Changed

- **`@cyanheads/mcp-ts-core`** `^0.10.9` → `^0.10.14`, with vendored `skills/` and `scripts/*.ts` re-synced to match.
- **`scripts/devcheck.ts`** — the Outdated check no longer flags a row held back solely by `minimumReleaseAge` (`Update` == `Current`, marked `*` by `bun outdated`); a genuine available update still fails the check.
- **`devcheck.config.json`** — `outdated.allowlist` now holds `typescript` (major-version hold against 7.0.2, outside the `^6` range) in place of the framework package.
- **`Dockerfile`** — pins `oven/bun:1.3.14` (was floating `1.3`/`1.3-slim`), adds a BuildKit cache mount for the Bun install cache, and passes `--ignore-scripts` on the build-stage install.

## Fixed

- **`gdelt_search_articles`, `gdelt_get_coverage_timeline`, `gdelt_get_tone_distribution`, `gdelt_get_coverage_breakdown`, `gdelt_search_tv`, `gdelt_get_tv_clips`, `gdelt_get_tv_context`** — a lone `startDatetime` or `endDatetime` was silently dropped, running the query against GDELT's default window instead of the requested one ([#22](https://github.com/cyanheads/gdelt-mcp-server/issues/22)). Both fields now carry a `.regex()` format constraint via a new shared `src/mcp-server/tools/date-range.ts` module (`GDELT_DATETIME_PATTERN`, serialized into the advertised JSON Schema as `pattern` — a malformed value is rejected by the SDK as `InvalidParams`/-32602), and every handler rejects an unpaired boundary via a new `invalid_date_range` `ValidationError`/-32007 reason (`isUnpairedDateRange`) before the service call runs.
- **Same seven tools** — GDELT's HTTP-200 plain-text query rejections (no TV station selected, keyword too short/long, unbalanced parenthesis, illegal character) surfaced as a generic `SerializationError` ("unparseable response") instead of an actionable error ([#18](https://github.com/cyanheads/gdelt-mcp-server/issues/18)). `parseGdeltJson` (now exported for direct testing) matches the known rejection bodies and throws a new `invalid_query` `ValidationError`/-32007 reason with a hint tailored to what GDELT rejected.
- **`stations` field description** on `gdelt_search_tv`, `gdelt_get_tv_clips`, `gdelt_get_tv_context` — corrected; omitting `stations` is rejected by the GDELT TV API, it does not fall back to "all stations" as previously described.

## Dependencies

Clears 8 transitive advisories from this release's dependency refresh (2 high, 6 moderate) — `bun audit` is clean.

- **`hono`** `4.12.26` → `4.12.28`, **`js-yaml`** `3.14.2` → `3.15.0` — pulled in by the `@cyanheads/mcp-ts-core` bump above.
  - High: [GHSA-88fw-hqm2-52qc](https://github.com/advisories/GHSA-88fw-hqm2-52qc) — hono CORS middleware reflects any Origin with credentials when `origin` defaults to the wildcard.
  - Moderate: [GHSA-wwfh-h76j-fc44](https://github.com/advisories/GHSA-wwfh-h76j-fc44) hono `serve-static` Windows path traversal, [GHSA-j6c9-x7qj-28xf](https://github.com/advisories/GHSA-j6c9-x7qj-28xf) hono Lambda `Set-Cookie` merge, [GHSA-rv63-4mwf-qqc2](https://github.com/advisories/GHSA-rv63-4mwf-qqc2) hono Lambda body-limit bypass, [GHSA-wgpf-jwqj-8h8p](https://github.com/advisories/GHSA-wgpf-jwqj-8h8p) hono Lambda@Edge header drop, [GHSA-h67p-54hq-rp68](https://github.com/advisories/GHSA-h67p-54hq-rp68) js-yaml quadratic-complexity DoS.
- **`vite`** `8.0.14` → `8.1.4` — pulled in by the `vitest` `^4.1.9` → `^4.1.10` bump below.
  - High: [GHSA-fx2h-pf6j-xcff](https://github.com/advisories/GHSA-fx2h-pf6j-xcff) — `server.fs.deny` bypass on Windows alternate paths.
  - Moderate: [GHSA-v6wh-96g9-6wx3](https://github.com/advisories/GHSA-v6wh-96g9-6wx3) — `launch-editor` NTLMv2 hash disclosure via UNC path handling on Windows.

### Dependency bumps

- `@cyanheads/mcp-ts-core` `^0.10.9` → `^0.10.14`
- `@socketsecurity/bun-security-scanner` added, `^1.1.2`
- `@types/node` `^26.0.0` → `^26.1.1`
- `ignore` `^7.0.5` → `^7.0.6`
- `tsc-alias` `^1.8.17` → `^1.9.0`
- `vitest` `^4.1.9` → `^4.1.10`
