---
summary: "Five bug fixes (SoQL error classification, invalid app-token detection, grouped total_count, DataCanvas reachability, computed-region spillover); mcp-ts-core ^0.10.9 → ^0.10.10; vite/hono/js-yaml security advisories cleared"
breaking: false
security: true
---

# 0.1.10 — 2026-07-04

## Changed

- Vendored agent skills re-synced to the installed framework version (`api-utils`/parsing, `polish-docs-meta`/readme); this server's own `README.md` drops the `## Contributing` section to match the updated template.

## Fixed

- **`socrata_query_dataset`** — SODA 400 bodies keyed `errorCode` (query-coordinator errors, e.g. `no-such-column`) fell through to a generic HTTP error and lost the upstream message. `fetchJson` now accepts either `code` or `errorCode` and always throws `soql_error` with the SODA message; the tool's catch block re-throws `soql_error` (and `rate_limited`) through `ctx.fail` so the declared recovery hint reaches the wire — previously only `not_found` got that treatment. ([#2](https://github.com/cyanheads/socrata-mcp-server/issues/2))
- **`socrata_get_dataset`**, **`socrata_query_dataset`**, **`socrata_find_datasets`** — an invalid `SOCRATA_APP_TOKEN` surfaced as a generic `Forbidden`. `fetchJson` now recognizes a 403 `permission_denied` body whose message mentions the app token and throws a new `invalid_app_token` (`ConfigurationError`) instead, without the token value ever entering the error payload; a private-dataset denial (no app-token mention) keeps the existing generic path. `find-datasets.tool.ts` had no try/catch around its service call at all — one was added. ([#10](https://github.com/cyanheads/socrata-mcp-server/issues/10))
- **`socrata_query_dataset`** — grouped/aggregate queries (`group` set) reported `total_count` as the raw matching source-row count rather than a count of the returned groups. The best-effort recount now skips whenever `group` is set, and the truncation guidance only claims "(exact count in total_count)" when a count actually ran. ([#11](https://github.com/cyanheads/socrata-mcp-server/issues/11))
- **`socrata_dataframe_describe`** — omitting `canvas_id` silently minted a fresh empty canvas and described it as empty rather than the documented "list all tables" behavior; `DataCanvas.acquire(undefined, ctx)` has no such listing mode. The handler now throws a new `canvas_id_required` (`ValidationError`) when canvas is enabled and `canvas_id` is omitted or blank. Every surface repeating the false "omit to list tables/canvases" promise — this tool's input description and `canvas_not_found` recovery, `socrata_dataframe_query`'s `canvas_not_found` recovery, and two call-outs in `docs/design.md` — was corrected. ([#15](https://github.com/cyanheads/socrata-mcp-server/issues/15))
- **DataCanvas was unreachable on every transport** — all three canvas touchpoints read `ctx.core?.canvas`, but the framework only exposes `canvas` on `CoreServices` inside `setup()`, never on the per-request `Context`; `CANVAS_PROVIDER_TYPE=duckdb` always reported canvas as disabled, so spillover never ran and `canvas_id_required` above could never fire. New `src/services/canvas-accessor.ts` (`setCanvas`/`getCanvas`), wired from `setup(core)` in `src/index.ts`, fixes all three call sites. ([#15](https://github.com/cyanheads/socrata-mcp-server/issues/15))
- **`socrata_query_dataset`** — canvas spillover silently failed on any default-projection query against a dataset carrying `:@computed_region_*` columns, since `registerTable` rejects `:`-prefixed keys as invalid canvas identifiers and the failure only logged a warning. Socrata system columns are now stripped from the canvas projection before `registerTable`; the inline `rows` in the response keep every column. ([#16](https://github.com/cyanheads/socrata-mcp-server/issues/16))

## Security

- **`vite`** `≤8.0.15` → `8.1.3` — high [GHSA-fx2h-pf6j-xcff](https://github.com/advisories/GHSA-fx2h-pf6j-xcff) (`server.fs.deny` bypass); moderate [GHSA-v6wh-96g9-6wx3](https://github.com/advisories/GHSA-v6wh-96g9-6wx3) (launch-editor NTLMv2 hash disclosure, dev-time chain via `vitest`).
- **`hono`** `<4.12.25` → `4.12.27` — high [GHSA-88fw-hqm2-52qc](https://github.com/advisories/GHSA-88fw-hqm2-52qc) (CORS wildcard-credential reflection); moderate [GHSA-wwfh-h76j-fc44](https://github.com/advisories/GHSA-wwfh-h76j-fc44), [GHSA-j6c9-x7qj-28xf](https://github.com/advisories/GHSA-j6c9-x7qj-28xf), [GHSA-rv63-4mwf-qqc2](https://github.com/advisories/GHSA-rv63-4mwf-qqc2), [GHSA-wgpf-jwqj-8h8p](https://github.com/advisories/GHSA-wgpf-jwqj-8h8p).
- **`js-yaml`** (transitive, via `depcheck`) `3.14.2` → `3.15.0` — moderate merge-key denial-of-service.

Lockfile refresh from the `@cyanheads/mcp-ts-core` ^0.10.10 adoption cleared all 8 flagged advisories (2 high, 6 moderate); `bun audit` now reports 0.

Dependency bumps:

- `@cyanheads/mcp-ts-core` ^0.10.9 → ^0.10.10
- `@biomejs/biome` ^2.5.0 → ^2.5.2
- `@types/node` ^26.0.0 → ^26.1.0
- `tsc-alias` ^1.8.17 → ^1.9.0
