---
summary: "Full content[] rendering (#19), bounded paginated canvas spillover (#20), and sql_rejected contract parity (#22); mcp-ts-core ^0.10.14, supply-chain hardening"
breaking: false
security: false
---

# 0.1.13 — 2026-07-10

## Added

- **`table_not_found`** error contract on `socrata_dataframe_query` — SQL referencing a dropped, expired, or mistyped canvas table now surfaces a dedicated `NotFound` reason with a recovery hint, instead of bubbling DuckDB's raw `missing_table` error as-is.
- **`canvas_row_count`** output field on `socrata_query_dataset` — reports how many rows were staged onto the DataCanvas when a query spills over.

## Changed

- **Canvas spillover** — `socrata_query_dataset` now drains a bounded copy of the matching set (up to 50,000 rows) across paginated SODA calls via a new `SocrataService.streamDatasetRows`, instead of staging only the single capped page already returned inline. Output and formatted-text guidance now describe the canvas honestly as a bounded copy, not "the full result set." ([#20](https://github.com/cyanheads/socrata-mcp-server/issues/20))
- **Supply-chain hardening** — `bunfig.toml` sets a 3-day `minimumReleaseAge` hold on new package versions (excluding same-day `@cyanheads/mcp-ts-core` adoption) and wires the Socket install scanner; new `.github/SECURITY.md` documents the vulnerability-reporting process.
- **Dockerfile** — build stage installs with `--ignore-scripts`, both install stages mount a BuildKit cache for Bun's package cache, and base images move to `oven/bun:1.3.14`.

## Fixed

- **`content[]` rendering** — `socrata_query_dataset`, `socrata_dataframe_query`, and `socrata_find_datasets` now render every row/column `structuredContent` carries, instead of silently capping at 50/20 rows or 8 columns in the Markdown/JSON view. ([#19](https://github.com/cyanheads/socrata-mcp-server/issues/19))
- **`socrata_dataframe_query`** — DataCanvas SQL-gate rejections (non-SELECT statements, multi-statement SQL, system-catalog access, denied functions/operators) now remap to the declared `sql_rejected` contract with a recovery hint, instead of bubbling the gate's raw `ValidationError` with no guidance. ([#22](https://github.com/cyanheads/socrata-mcp-server/issues/22))

Dependency bumps:

- `@cyanheads/mcp-ts-core` ^0.10.10 → ^0.10.14
- `@socketsecurity/bun-security-scanner` — new, ^1.1.2 (dev)
