---
summary: "adopt @cyanheads/mcp-ts-core ^0.10.6 — truncation disclosure on capped searches, explicit createApp identity, MCPB bundle-content hardening"
breaking: false
security: false
---

# 0.2.3 — 2026-06-12

## Added

- **Truncation disclosure** — `pubchem_search_compounds`, `pubchem_search_assays`, and `pubchem_get_bioactivity` now emit `truncated`/`shown`/`cap` via `ctx.enrich.truncated()` when results are capped at `maxResults`, so callers know more matches exist beyond what was returned.
- **`scripts/clean-mcpb.ts`** — post-pack bundle cleaner wired into the `bundle` script: runs `mcpb clean`, then strips dependency-shipped agent-doc entries (`skills/`, `.claude/`, `.agents/`, `SKILL.md`) nested under `node_modules/` that root-anchored `.mcpbignore` patterns cannot reach.
- **Dockerfile `HEALTHCHECK`** — bun-native `fetch` against `/healthz` (slim image ships no curl/wget), plus an `org.opencontainers.image.version` OCI label sourced from the `APP_VERSION` build arg.

## Changed

- **`createApp()`** — sets explicit `name` and `title` to `pubchem-mcp-server`, pinning the served identity to the repo name on every surface instead of relying on the scoped-package fallback.
- **`scripts/lint-packaging.ts`** — adds bundle-content and identity guards: `.mcpbignore` dev-dir exclusion and anchoring (unanchored patterns also strip `node_modules/…/skills/`), critical-runtime-path protection, a post-bundle `node_modules` agent-doc scan, and a `createApp()`/manifest `display_name` identity check against the unscoped package name.
- **`scripts/check-framework-antipatterns.ts`** — adds rule 4 flagging `z.coerce.boolean()` on env flags (`Boolean("false")` is `true`, so the flag can't be disabled via env — use `z.stringbool()`); comment-line matches are now skipped so JSDoc naming an antipattern no longer false-positives.
- **`.mcpbignore`** — root dev-dir patterns anchored with a leading `/` so they no longer match nested runtime paths under `node_modules/`.

## Dependencies

- `@cyanheads/mcp-ts-core` `^0.9.21 → ^0.10.6`
- `@biomejs/biome` `^2.4.16 → ^2.5.0`
- `@types/node` `^25.9.1 → ^25.9.3`
- `packageManager` `bun@1.3.2 → bun@1.3.11`
