---
summary: "Framework bump to ^0.6.17, directory-based changelog, cleaner field rendering in search_entities (no comma-years, uppercased acronyms), security-pass skill surfaced"
breaking: false
---

# 0.6.0 — 2026-04-24

Picks up 7 patches of `@cyanheads/mcp-ts-core` (0.6.10 → 0.6.17), adopts the directory-based changelog convention, and resolves two visible render issues in `openalex_search_entities` that surfaced during field testing.

## Added

- **Directory-based changelog** under `changelog/<major.minor>.x/<version>.md` (18 migrated entries + `template.md` format reference). `CHANGELOG.md` is now a nav index regenerated by `bun run changelog:build`; `bun run changelog:check` runs in `devcheck`.
- `package.json` scripts `changelog:build` and `changelog:check`.
- **`security-pass` skill** (v1.1) — 8-axis MCP server audit — synced in from the framework and surfaced in the agent protocol `What's Next?` sequence (between `devcheck` and `polish-docs-meta`) and the skills table.
- Three new framework scripts: `scripts/build-changelog.ts`, `scripts/check-docs-sync.ts`, `scripts/check-skills-sync.ts`.

## Changed

- Bumped `@cyanheads/mcp-ts-core` `^0.6.10` → `^0.6.17` (no breaking changes across 7 patch releases).
- `openalex_search_entities` field rendering — dropped `.toLocaleString()` on integers (publication years no longer render as `2,007`; counts render as `23473` instead of `23,473`, consistent with CLAUDE.md's own anti-`toLocaleString` guidance on linted numbers).
- `openalex_search_entities` field labels — added an `ACRONYMS` set (`apc`, `doi`, `fwci`, `id`, `issn`, `oa`, `orcid`, `pmcid`, `pmid`, `ror`, `url`) so `toFieldLabel` renders `**DOI:**`, `**ORCID:**`, `**ID:**` instead of the title-cased `Doi`/`Orcid`/`Id`.
- All three tools now have `.describe()` on their array-element `z.object(...)` shapes — required by the `describe-on-fields` linter rule that became recursive in framework 0.6.16.
- Synced framework scripts (`devcheck.ts`, `lint-mcp.ts`, `tree.ts`) and skills (`field-test` 1.3 → 2.0, `report-issue-framework` and `report-issue-local` 1.1 → 1.2, `maintenance` 1.4 force-resync now includes Phase C for scripts sync).
- `CLAUDE.md` / `AGENTS.md` resynced, version field corrected, and security-pass surfaced.

## Fixed

- `describe-on-fields` lint warnings in `openalex_search_entities`, `openalex_analyze_trends`, and `openalex_resolve_name` — the recursive rule in framework 0.6.16 now flags array-element objects that lack `.describe()`.
