---
summary: "MCP SDK v2 compatibility, explicit stateless HTTP serving, and current framework-managed tooling"
breaking: false
security: false
---

# 0.5.14 — 2026-08-24

## Added

- **Community health files** — adds contribution and conduct guidance alongside the existing security policy.

## Changed

- **MCP SDK v2 compatibility** — HTTP serves both protocol revision 2026-07-28 and the 2025 era; undeclared top-level tool inputs are rejected by name, and tool failures advertise a structured error envelope.
- **HTTP session mode** — self-hosted configuration and the container explicitly use stateless serving; the schema's `auto` default remains documented as resolving to stateful.
- **Container build** — Bun `1.3.14` → `1.4.0`, native build stages use `BUILDPLATFORM`, and production installs omit the framework's optional peer tiers.
- **TypeScript and tests** — the typecheck covers `tests/`, build emission uses a dedicated config, and the Vitest suite uses typed error-contract contexts across all 274 tests.
- **Project tooling** — framework-managed scripts, skills, package metadata, plugin metadata, and bundle exclusions are synchronized with the current scaffold.
- **Security contact** — vulnerability reports use `security@caseyjhand.com`.

## Dependencies

- `@cyanheads/mcp-ts-core` `^0.11.0` → `^0.12.3`
- `@biomejs/biome` `^2.5.5` → `^2.5.10`
- `@types/node` `^26.1.1` → `^26.2.0`
- `tsc-alias` `^1.9.1` → `^1.9.2`
- `vitest` `^4.1.10` → `^4.1.11`
- `@vitest/coverage-istanbul` `^4.1.11` added; `pino-pretty` `^13.1.3` moved to runtime dependencies; direct `@hono/otel` `^1.1.2` removed in favor of the container's opt-in telemetry install.
