---
summary: "adopt @cyanheads/mcp-ts-core ^0.10.9 — check-dependency-specifiers devcheck step, plugin-manifest packaging lint, fresh-scaffold devcheck guards, vendored skill re-sync"
breaking: false
security: false
---

# 0.2.4 — 2026-06-20

## Added

- **`scripts/check-dependency-specifiers.ts`** — new devcheck step (`Dependency Specifiers`, `--no-dep-specifiers`) rejecting floating specifiers (`latest`, `*`, pre-release dist-tags) in `package.json`'s dependency sections and `bun.lock`'s `workspaces` map, catching the case where `bun update --latest` writes a literal `latest` dist-tag into the lock and lets a later `bun install` re-resolve past an intentional version hold. ([cyanheads/mcp-ts-core#246](https://github.com/cyanheads/mcp-ts-core/issues/246))
- **Plugin marketplace manifest checks in `scripts/lint-packaging.ts`** — check 10 validates `.claude-plugin/plugin.json`, `.codex-plugin/plugin.json`, and `.codex-plugin/mcp.json`: non-empty descriptions, display fields carry the unscoped machine name, and the `npx -y` install arg carries the full scoped package name. Gated by the new `devcheck.config.json` `packaging.pluginManifests` flag (default on). ([cyanheads/mcp-ts-core#240](https://github.com/cyanheads/mcp-ts-core/issues/240))

## Changed

- **Fresh-scaffold devcheck guards** — `scripts/build-changelog.ts`, `scripts/devcheck.ts`, and `scripts/check-framework-antipatterns.ts` skip git-dependent checks when `.git` is absent; `scripts/check-skill-versions.ts` guards against a `SKILL.md` deleted from the worktree. ([cyanheads/mcp-ts-core#237](https://github.com/cyanheads/mcp-ts-core/issues/237), [#242](https://github.com/cyanheads/mcp-ts-core/issues/242), [#243](https://github.com/cyanheads/mcp-ts-core/issues/243))
- **Vendored skills re-synced** to mcp-ts-core 0.10.7–0.10.9 — `metadata.version` bumps across `api-auth`, `api-errors`, `api-services`, `api-telemetry`, `field-test`, `report-issue-local`, `tool-defs-analysis`, plus body updates to `git-wrapup`, `orchestrations`, `api-context`, and others. ([cyanheads/mcp-ts-core#238](https://github.com/cyanheads/mcp-ts-core/issues/238))

## Removed

- **`skills/references/{formatting,parsing,security}.md`** — stray framework reference docs vendored in error; removed.

## Dependencies

- `@cyanheads/mcp-ts-core` `^0.10.6 → ^0.10.9`
- `@types/node` `^25.9.3 → ^26.0.0`
- `vitest` `^4.1.8 → ^4.1.9`
