---
summary: "@cyanheads/mcp-ts-core ^0.10.6 → ^0.10.9 — check-dependency-specifiers + plugin-manifest devcheck guards, ctx.content collector, canvas SQL gate classification; dropped unused direct hono dependency; TypeScript 6 adopted"
breaking: false
security: false
---

# 0.5.11 — 2026-06-20

## Changed

- **`@cyanheads/mcp-ts-core` ^0.10.6 → ^0.10.9** — framework adoption. Brings the `check-dependency-specifiers` devcheck step (rejects floating `latest`/`*`/dist-tag specifiers in `package.json` and `bun.lock`'s `workspaces` map), `lint:packaging` check 10 (validates `.claude-plugin`/`.codex-plugin` manifest descriptions, unscoped display identity, and full-name `npx -y` install args), the `ctx.content` collector for image/audio blocks, sharper canvas SQL gate classification (`SELECT`-shaped prepare failures now throw `invalid_sql` with DuckDB binder detail), fresh-scaffold guards in `build-changelog`/`devcheck`, a `check-skill-versions` worktree-deletion guard, and the `DuckdbProvider.describe()` filter-qualification fix.
- **`devcheck.config.json`** — added `packaging.pluginManifests: true` to opt into the new plugin-manifest checks.
- **`.codex-plugin/plugin.json`** — populated the previously empty `interface.longDescription`.
- **Skill sync** — vendored `skills/` resynced to the framework version (14 updated); `add-export` and `add-provider` pruned (removed upstream); `scripts/` maintenance helpers re-synced, adding `scripts/check-dependency-specifiers.ts`.
- **`typescript` ^5.9.3 → ^6.0.3** — TypeScript 6 adopted (reverses the 0.5.10 hold).

## Removed

- **Unused direct `hono` dependency** — dropped from `package.json`. It was unused in source and escalated a transitive `hono` advisory into a false direct-dependency security-audit failure; `hono` remains available transitively via `@cyanheads/mcp-ts-core`.

### Dependency bumps

- `@cyanheads/mcp-ts-core` ^0.10.6 → ^0.10.9
- `@biomejs/biome` ^2.4.16 → ^2.5.0
- `@types/node` ^25.9.3 → ^26.0.0
- `typescript` ^5.9.3 → ^6.0.3
- `vitest` ^4.1.8 → ^4.1.9
