---
summary: "Distinguish nonexistent CIDs from no-data compounds in pubchem_get_compound_safety; mark undecoded GHS P-codes explicitly; drop the dead severity field from pubchem_get_compound_interactions; fix two GHS-statement parsing bugs; adopt mcp-ts-core ^0.11.0"
breaking: false
security: false
---

# 0.4.2 — 2026-07-28

## Added

- **`bunfig.toml`** — `minimumReleaseAge` (3-day supply-chain guard against freshly published package versions, excluded for `@cyanheads/mcp-ts-core`) and the Socket install scanner (`@socketsecurity/bun-security-scanner`), scanning every package before install.
- **`scripts/clean-mcpb.ts` / `scripts/lint-packaging.ts`** — the `.mcpb` bundle strip now also removes platform-specific native binding entries (e.g. `@duckdb/node-bindings-*`), alongside the existing agent-doc strip, so a bundle built on one platform doesn't silently ship a binding that only runs there.
- **`.github/SECURITY.md`**, **`.github/FUNDING.yml`**, **`.gitattributes`** — repo governance and hygiene files vendored from the mcp-ts-core scaffold.

## Changed

- **`pubchem_get_compound_safety`** — CID lookups now report a `status` of `ok`, `no_ghs_data`, or `cid_not_found` instead of a single `hasData` boolean; the notice and rendered text lead with CID-verification guidance for unrecognized CIDs, separately from the no-classification case for compounds that exist. `pubchem://compound/{cid}/safety` carries the same discriminator. ([#42](https://github.com/cyanheads/pubchem-mcp-server/issues/42))
- **`pubchem_get_compound_safety`** — precautionary statement entries now carry a `decoded` boolean; a P-code absent from the static lookup table (free-fill placeholder or decoder-coverage gap) renders as `(not decoded)` instead of a bare or blank statement. ([#34](https://github.com/cyanheads/pubchem-mcp-server/issues/34))
- **`scripts/devcheck.ts`** outdated check — no longer flags peer-dependency rows or versions held back by `minimumReleaseAge`; only packages actually behind their declared range fail the gate.
- **`scripts/check-dependency-specifiers.ts`** — the floating-specifier check now also scans `package.json`'s `overrides` section.
- `package.json` `author` field and the `LICENSE` copyright line reformatted to match the current scaffold convention.

## Removed

- **`pubchem_get_compound_interactions`** — dropped the `severity` field from the output schema, type, and formatter. No fetch path (`getDrugDrugInteractions`, `getDrugFoodInteractions`, `getTargetInteractions`) ever populated it, and the underlying `drugbankddi` SDQ collection has no severity-bearing column to project. ([#43](https://github.com/cyanheads/pubchem-mcp-server/issues/43))

## Fixed

- **GHS hazard/precautionary parsing** — `parseCodedStatement` no longer drops statements carrying a depositor-agreement percentage (`H319 (100%): ...`) or asterisk marker (`H370 **: ...`) between the code and separator, and now accepts subcategory-suffixed codes (`H350i`, `H360D`, `H361fd`) as distinct entries instead of failing the match.
- **GHS precautionary code parsing** — `parsePrecautionaryCodes` now scans the list for P-code shapes instead of matching each comma-split token against an anchored pattern; the anchored form silently dropped whichever code PubChem's trailing prose ("click each P-code to see the statement") was glued to, most often the final code (P501, the disposal statement).

## Dependencies

- `@cyanheads/mcp-ts-core` `^0.10.10 → ^0.11.0`
- `typescript` `^6.0.3 → ^7.0.2`
- `@biomejs/biome` `^2.5.2 → 2.5.5` (pinned exact)
- `@types/node` `^26.1.0 → 26.1.1` (pinned exact)
- `tsc-alias` `^1.8.17 → ^1.9.1`
- `vitest` `^4.1.9 → ^4.1.10`
- `ignore` `^7.0.5 → ^7.0.6`
- `@socketsecurity/bun-security-scanner` added `^1.1.2`
