---
summary: "Fixed: unenumerated GDELT query-rejection sentences no longer serialize as server errors (#25); rate-limit responses fail fast instead of burning the retry budget (#26); mcp-ts-core ^0.10.15 clears 2 of 3 bun audit advisories"
breaking: false
security: false
---

# 0.2.6 — 2026-07-24

## Fixed

- **`parseGdeltJson`** — an unenumerated GDELT query-rejection sentence (e.g. `Queries containing OR'd terms must be surrounded by ().` from DOC, `Boolean OR's may only appear inside of a () clause.` from TV) fell through to a server-fault SerializationError instead of the caller-fault `invalid_query` contract #18 added. The enumerated marker list is now backed by positive identification (`looksLikeGdeltRejection`): a short, non-JSON, sentence-shaped body classifies as `invalid_query` with a generic recovery hint even when no marker matches, so the next unenumerated wording won't silently regress to a server-fault report. The two OR-parenthesization wordings above also gained their own tailored hints. Affects every tool funneling through `gdeltFetch`, not just `gdelt_search_articles` ([#25](https://github.com/cyanheads/gdelt-mcp-server/issues/25)).
- **`gdeltFetch`** — an HTTP 429 or an HTTP-200 rate-limit body (plain-text or HTML) was retried up to 4× by `withRetry`, with every replay landing inside GDELT's still-closed cooldown window. Rate-limit rejections now carry `data.retryable: false`, failing fast on the first attempt with GDELT's "retry after 5 seconds" cue instead of after four wasted requests. `GDELT_REQUEST_DELAY_MS` default raised `5100 → 5300` for jitter headroom above GDELT's 5000ms floor ([#26](https://github.com/cyanheads/gdelt-mcp-server/issues/26)).

## Dependencies

- **`@cyanheads/mcp-ts-core`** `^0.10.14` → `^0.10.15` — the #26 fix adopts the new `expectedStatuses` option on `fetchWithTimeout` to keep an expected 429 at `debug` instead of `error` in the logs.
- **`@biomejs/biome`** (dev) resolved `2.5.3` → `2.5.5` within the existing `^2.5.0` range; bundled `skills/` copies re-synced to the framework's updated versions.
- `bun audit` cleared 2 of 3 advisories (`fast-uri` high; one `@hono/node-server` moderate). One moderate remains — [GHSA-frvp-7c67-39w9](https://github.com/advisories/GHSA-frvp-7c67-39w9), a transitive `@hono/node-server` path-traversal pinned under the MCP SDK's own `^1.19.9` dependency range — not fixable from this repo without an out-of-range override, which was not forced.
