---
summary: "Reject fractional and blank/whitespace-only tool inputs; hn_search_content reports Algolia's own page count instead of a recomputation; hn_get_user's Firebase username segment is percent-encoded; hn_get_thread omits totalAvailable instead of rendering undefined. @cyanheads/mcp-ts-core ^0.10.9 → ^0.11.0."
breaking: false
security: false
---

# 0.5.12 — 2026-07-28

## Changed

- **`bunfig.toml`** — adds `[install.security] scanner = "@socketsecurity/bun-security-scanner"` and a `minimumReleaseAge` of 3 days (`259200`s) on installed package versions, excluding `@cyanheads/mcp-ts-core` via `minimumReleaseAgeExcludes` so framework releases still adopt same-day.
- **`Dockerfile`** — the production stage's OTEL `bun add` gains `--omit=dev --ignore-scripts`, and both stages gain a BuildKit cache mount (`--mount=type=cache,target=/root/.bun/install/cache`) for Bun's install cache.
- **`.gitignore`** — `data/` anchored to `/data/`; the unanchored pattern also matched nested paths such as `src/data/`.
- **`devcheck.config.json`** — `@socketsecurity/bun-security-scanner` added to the depcheck ignore list (install-time-only, never imported); `typescript` dropped from the `outdated` allowlist now that TypeScript 7 is adopted below.
- **Skill sync** — vendored `skills/` (15 directories) and framework `scripts/*.ts` (7 files) resynced to `@cyanheads/mcp-ts-core` 0.11.0.

## Fixed

- **Fractional numeric inputs are rejected** — `count`/`offset` (`hn_get_stories`), `itemId`/`depth`/`maxComments` (`hn_get_thread`), `submissionCount` (`hn_get_user`), `count`/`page`/`minPoints` (`hn_search_content`), and `HN_CONCURRENCY_LIMIT` now require `.int()`. Fractional values previously passed validation and either silently truncated results or produced confusing upstream errors. [#10](https://github.com/cyanheads/hn-mcp-server/issues/10)
- **Blank and whitespace-only strings are rejected** — `hn_search_content`'s `query` and `author`, and `hn_get_user`'s `username`, are now `.trim()`-aware. A whitespace-only `query` no longer returns HN's global leaderboard, and a whitespace-only `author` no longer silently zeroes out results. [#9](https://github.com/cyanheads/hn-mcp-server/issues/9)
- **`hn_search_content` reports Algolia's own page count** — `totalPages` now mirrors the Algolia response's `nbPages` instead of recomputing `Math.ceil(nbHits / count)`, which overstated reachable pages by orders of magnitude on broad queries. [#11](https://github.com/cyanheads/hn-mcp-server/issues/11)
- **`hn_get_user` percent-encodes the username path segment** — `HnService.fetchUser` calls `encodeURIComponent` before building the Firebase URL, so a value like `../item/8863` stays one opaque `/user/` segment instead of escaping to `/item/`. [#13](https://github.com/cyanheads/hn-mcp-server/issues/13)
- **`hn_get_thread` omits `totalAvailable` instead of rendering it as `undefined`** — comment and job roots don't report `descendants`; the enrichment call now only keys `totalAvailable` when HN provides a value. [#14](https://github.com/cyanheads/hn-mcp-server/issues/14)

## Dependencies

- `@cyanheads/mcp-ts-core` ^0.10.9 → ^0.11.0
- `typescript` ^6.0.3 → ^7.0.2
- `@biomejs/biome` ^2.5.0 → ^2.5.5
- `@types/node` ^26.0.0 → ^26.1.1
- `ignore` ^7.0.5 → ^7.0.6
- `tsc-alias` ^1.8.17 → ^1.9.1
- `vitest` ^4.1.9 → ^4.1.10
- new devDependency `@socketsecurity/bun-security-scanner` ^1.1.2 — the `bunfig.toml` install-time scanner
