---
summary: "Framework bump to ^0.7.4 — fail-closed Origin guard for HTTP, framework-antipattern devcheck step, literal-variant linter exemption, issue templates"
breaking: false
---

# 0.6.2 — 2026-04-25

Picks up `@cyanheads/mcp-ts-core` 0.7.1 → 0.7.4 (HTTP security hardening, format-parity numeric tightening, linter union-literal exemption) and the skill/script updates that ship with them. No behavior changes in this server's tools or prompts — maintenance release.

## Added

- **HTTP `MCP_ALLOWED_ORIGINS`** — documented in `.env.example` and the README env-var table. Framework 0.7.1 ships a fail-closed Origin allow-list for browser POSTs (loopback-only when unset, `*` to disable). Non-browser clients (no `Origin` header) are unaffected.
- **`scripts/check-framework-antipatterns.ts`** + **Framework Antipatterns devcheck step** — new check guards against three SDK-coupling shortcuts (inputSchema downgrade, post-register mutation, transport-layer error-text matching). Manually copied from the package as a workaround for [cyanheads/mcp-ts-core#69](https://github.com/cyanheads/mcp-ts-core/issues/69) and [#73](https://github.com/cyanheads/mcp-ts-core/issues/73), which prevent the script from being synced automatically by maintenance Phase C / `init`.
- **`.github/ISSUE_TEMPLATE/`** — bug, feature, and disabled blank-issue templates with a primary/secondary label split (`regression`/`performance`/`security`/`breaking-change`) matching the framework-side convention.

## Changed

- Bumped `@cyanheads/mcp-ts-core` `^0.7.0` → `^0.7.4` (no breaking changes). Spans:
  - **0.7.1** — HTTP transport security hardening (Origin guard, validated landing-page bearer check, raw-payload logging removed, opt-in LLM transcripts).
  - **0.7.2** — `vitest.config` subpath ships as `.mjs` (fixes Node 22.7+ type-strip failure under `node_modules`); new framework-antipattern devcheck step.
  - **0.7.3** — `format-parity` numeric normalization rejects lossy digit-shift transforms while preserving locale support; `fetchWithTimeout` SSRF guard documented as best-effort with DNS-rebinding caveat.
  - **0.7.4** — linter exempts `z.literal` union variants from `describe-on-fields`; landing connect snippets resist Cloudflare email rewriting and accept operator overrides; maintenance skill surfaces new/changed skills at end-of-run.
- Resynced framework skills:
  - **`api-linter`** 1.1 → 1.2 — adds the `z.literal` union-variant exemption row to the `describe-on-fields` table, with a worked form-client blank-tolerance example.
  - **`maintenance`** 1.5 → 1.6 — adds a "New/changed skills available" section to the end-of-run summary so users learn about new framework skills (e.g. `security-pass`) without forcing auto-invocation.
- Resynced framework script: `scripts/devcheck.ts` — adds the Framework Antipatterns step.
- `CLAUDE.md` / `AGENTS.md` checklist — clarifies that when regex/length constraints matter on form-client-tolerant optional fields, `z.union([z.literal(''), z.string().regex(...).describe(...)])` is the canonical shape (literal variants are exempt from `describe-on-fields`).
- Regenerated `docs/tree.md`.
