---
summary: "Adopted mcp-ts-core ^0.13.6: the server declares stateless session mode in source, argument rejections carry a reason and a schema-derived recovery hint, and tool errors close with their reason and retryable status."
breaking: false
security: false
---

# 0.5.17 — 2026-09-19

## Added

- **`.github/workflows/codeql.yml`** — the one GitHub Actions workflow this server carries; runs only while the repo's CodeQL default setup stays off.
- **`devcheck.config.json` gains a `lint` key** ([cyanheads/mcp-ts-core#388](https://github.com/cyanheads/mcp-ts-core/issues/388)), ready to carry a `truncationAllowlist` declaration read by `lint:mcp`.
- **The npm package now ships `AGENTS.md`** alongside `CLAUDE.md`.

## Changed

- **`createApp({ sessionMode: 'stateless' })` declares the HTTP session posture in source** ([cyanheads/mcp-ts-core#376](https://github.com/cyanheads/mcp-ts-core/issues/376)). With `MCP_SESSION_MODE` unset, the server now resolves `stateless` from its own `createApp({ sessionMode: 'stateless' })` declaration instead of the schema default `auto` (which resolves to `stateful`); an explicit `MCP_SESSION_MODE` value still overrides it. The Docker image and `.env.example` already set `stateless` — the README env row's default now matches.
- **`SIGTERM`/`SIGINT` now end the process explicitly** ([cyanheads/mcp-ts-core#435](https://github.com/cyanheads/mcp-ts-core/issues/435)) — exit `0` once shutdown settles, `1` if the 10s ceiling fires.
- **An argument rejection carries `data.reason: "invalid_arguments"` and a schema-derived `Recovery:` hint** naming the tool's accepted keys ([cyanheads/mcp-ts-core#445](https://github.com/cyanheads/mcp-ts-core/issues/445), [cyanheads/mcp-ts-core#378](https://github.com/cyanheads/mcp-ts-core/issues/378)); a required field omitted from an enum now renders as missing rather than as a wrong choice. An unknown key is still rejected — never dropped or ignored.
- **Tool arguments pass a pre-validation step before schema parsing** ([cyanheads/mcp-ts-core#452](https://github.com/cyanheads/mcp-ts-core/issues/452), [cyanheads/mcp-ts-core#453](https://github.com/cyanheads/mcp-ts-core/issues/453), [cyanheads/mcp-ts-core#234](https://github.com/cyanheads/mcp-ts-core/issues/234)) — a fixed list of client-added keys is dropped, a case-folded undeclared key matching exactly one declared key is rewritten to it, and a JSON-stringified array is repaired once after a failed parse. Advertised `inputSchema`/`outputSchema` are unchanged.
- **A tool error's text now closes with `(reason <reason>)`**, plus ` · retryable` / ` · not retryable` when the entry declares `retryable` ([cyanheads/mcp-ts-core#458](https://github.com/cyanheads/mcp-ts-core/issues/458)).
- **`hn_get_thread`'s `item_not_found` and `hn_get_user`'s `user_not_found` declare `severity: 'notice'`** ([cyanheads/mcp-ts-core#380](https://github.com/cyanheads/mcp-ts-core/issues/380)) — a lookup miss now logs at `notice` instead of `error`; the wire envelope is unchanged.
- `.env.example`'s `MCP_SESSION_MODE` comment explains the stateless/stateful tradeoff instead of stating only the default; the README row documents the new source default.
- CLAUDE.md's `## Publishing` section documents the full gated release-PR flow (`git-wrapup` → `release-pr-review` → `release-and-publish`), replacing the single-skill pointer.
- Minor/internal: all four tools' `upstream_*` service-thrown error reasons carry `thrownBy: 'service'` ([cyanheads/mcp-ts-core#462](https://github.com/cyanheads/mcp-ts-core/issues/462)); 22 `framework-skills/` files and 6 framework scripts (`build.ts`, `clean.ts`, `clean-mcpb.ts`, `devcheck.ts`, `lint-mcp.ts`, `lint-packaging.ts`) re-synced to their current mcp-ts-core versions.

## Dependencies

- `@cyanheads/mcp-ts-core` ^0.13.0 → ^0.13.6
- `zod` ^4.6.1 → ^4.6.5
- `@biomejs/biome` ^2.5.13 → ^2.5.14
- `@types/node` ^26.5.1 → ^26.6.1
- `vitest` / `@vitest/coverage-istanbul` ^5.0.0 → ^5.0.1
- `tsc-alias` ^1.9.4 → ^1.9.5
