---
summary: "Maintenance: @cyanheads/mcp-ts-core ^0.10.6 → ^0.10.9 (fresh-scaffold devcheck guards, ctx.content, SQL gate classification), new dependency-specifier + plugin-manifest devcheck steps, @types/node ^26"
breaking: false
security: false
---

# 0.1.4 — 2026-06-20

## Added

- **`scripts/check-dependency-specifiers.ts`** — new `devcheck` step (`Dependency Specifiers`, flag `--no-dep-specifiers`) that hard-fails on floating specifiers (`latest`, `*`, pre-release dist-tags) in `package.json`'s dependency sections and `bun.lock`'s `workspaces` map. Catches `bun update --latest` writing a literal `latest` dist-tag into the lock's workspace map. ([cyanheads/mcp-ts-core#246](https://github.com/cyanheads/mcp-ts-core/issues/246))
- **Plugin marketplace manifest checks** — `scripts/lint-packaging.ts` gains check 10, validating `.claude-plugin/plugin.json` and `.codex-plugin/{plugin,mcp}.json` for non-empty descriptions, unscoped display fields, and the full package name in the `npx -y` install arg. Gated by the new `devcheck.config.json` `packaging.pluginManifests` flag (on). The `devcheck` "Packaging" gate now runs when any plugin manifest is present, not only with `manifest.json`. ([cyanheads/mcp-ts-core#240](https://github.com/cyanheads/mcp-ts-core/issues/240))

## Changed

- **Fresh-scaffold `devcheck` guards** — `scripts/devcheck.ts` skips the git-dependent checks (TODOs/FIXMEs, Tracked Secrets, Framework Antipatterns) via a shared `isGitRepo()` guard when `.git` is absent; `scripts/build-changelog.ts`, `scripts/check-framework-antipatterns.ts`, and `scripts/check-skill-versions.ts` self-guard against an empty changelog tree, a non-repo invocation, and a worktree-deleted `SKILL.md` respectively. ([cyanheads/mcp-ts-core#237](https://github.com/cyanheads/mcp-ts-core/issues/237), [#242](https://github.com/cyanheads/mcp-ts-core/issues/242), [#243](https://github.com/cyanheads/mcp-ts-core/issues/243))
- **Project skills re-synced** to mcp-ts-core 0.10.9 — `api-context` documents the new `ctx.content` collector for image/audio blocks; `git-wrapup` v1.4 (one-line tag context) and `orchestrations` v1.4; version bumps across `add-tool`, `api-auth`, `api-canvas`, `api-config`, `api-errors`, `api-services`, `api-telemetry`, `field-test`, `polish-docs-meta`, `report-issue-local`, `tool-defs-analysis`.

### Dependency bumps

- `@cyanheads/mcp-ts-core` ^0.10.6 → ^0.10.9
- `@types/node` ^25.9.3 → ^26.0.0
- `@hono/node-server` ^2.0.4 → ^2.0.5 (transitive, via framework)
- `hono` ^4.12.25 → ^4.12.26 (transitive, via framework)
