---
summary: "Fix silent data loss in pubchem_get_compound_safety (precautionary statements) and pubchem_get_compound_details (FDA pharmacological classification), both parsing PubChem's real shapes; add a maxSynonyms cap; correct the server assay-routing instructions; adopt mcp-ts-core ^0.10.10; clear 8 transitive security advisories"
breaking: false
security: true
---

# 0.3.0 — 2026-06-30

## Added

- **`maxSynonyms`** — `pubchem_get_compound_details` gains an integer input (1–100, default 20) that caps the synonyms returned per compound, with a new optional **`synonymsTotal`** output reporting the full count before truncation. The structured surface was previously uncapped (697 synonyms for aspirin) and disagreed with `format()`'s 20-item view; both now share the head-of-list cap, preserving PubChem's relevance ordering. Mirrors the existing `maxDescriptions`/`descriptionsTotal` pattern. ([#24](https://github.com/cyanheads/pubchem-mcp-server/issues/24))

## Changed

- **Server `instructions`** — the target-centric routing hint pointed `pubchem_search_assays` (→ AIDs) into `pubchem_get_bioactivity`, which takes a compound `cid`, not AIDs. Reworded to the two real paths: assays-for-a-target chains `search_assays` → `pubchem_get_summary` (`entityType: assay`) per AID, and compound-active-against-a-target calls `get_bioactivity` with a `cid` plus `targetGeneId`/`targetAccession`. ([#25](https://github.com/cyanheads/pubchem-mcp-server/issues/25))

## Fixed

- **`pubchem_get_compound_safety` precautionary statements** — always returned `[]`. PubChem deposits precautionary statements as a single comma-separated P-code list (codes only, no descriptive text), which the `Pxxx: text` parser matched on neither shape. A dedicated `parsePrecautionaryCodes()` splits the list into code-only entries, preserving combined `Pxxx+Pyyy` (and triple) codes and stripping the terminal Oxford "and"; `format()` renders a bare code when no text is present. No standard P-statement text is fabricated. ([#22](https://github.com/cyanheads/pubchem-mcp-server/issues/22))
- **`pubchem_get_compound_details` FDA pharmacological classification** — `fdaClasses` and `fdaMechanisms` were always `[]` while MeSH classes and ATC codes in the same response parsed, because the parser gated every string on a `Pharmacological Classes:` prefix PubChem never emits. Now parses PubChem's two real shapes — individual (`<Type> [TAG] - <Name>`) and combined (`<Name> [TAG]; …`) — bucketing `EPC` → `fdaClasses` and `MoA` → `fdaMechanisms` (CS/PE have no output field). ([#23](https://github.com/cyanheads/pubchem-mcp-server/issues/23))

## Security

- Clears the 8 transitive advisories `bun audit` flagged on 0.2.4 (2 high, 6 moderate) — notably the high-severity `vite` `server.fs.deny` bypass and `hono` CORS reflecting any origin with credentials — via the lockfile re-resolve: `hono` `4.12.26 → 4.12.27`, `vite` `8.0.14 → 8.1.2`, and `js-yaml` `3.14.2 → 3.15.0` (merge-key quadratic DoS). All transitive — this server declares no direct dependency on them — and `bun audit` now reports no vulnerabilities.

## Dependencies

- `@cyanheads/mcp-ts-core` `^0.10.9 → ^0.10.10` — adopts the in-framework js-yaml v4 → v5 migration (preserves YAML 1.1 load semantics; not breaking for this server, which doesn't install js-yaml directly).
- `@biomejs/biome` `^2.5.0 → ^2.5.1`
- `@types/node` `^26.0.0 → ^26.0.1`
- Lockfile re-resolve also refreshed other transitive packages; the security-relevant bumps are listed under Security.
