---
summary: "Truncation disclosure on socrata_query_dataset and socrata_dataframe_query, SQL system-catalog denial, explicit server identity; @cyanheads/mcp-ts-core ^0.9.21 → ^0.10.6"
breaking: false
security: false
---

# 0.1.8 — 2026-06-12

## Added

- **`socrata_query_dataset`** and **`socrata_dataframe_query`**: `truncated` / `shown` / `cap` enrichment fields. When a result fills the row limit, the tool now emits an agent-facing notice (paging, raising the limit, or — for `socrata_query_dataset` — the spilled canvas) instead of silently capping.
- **`socrata://` `createApp()` identity**: explicit `name` and `title` set to `socrata-mcp-server` so the served identity is the machine name rather than the scoped npm package name.
- **`Dockerfile`**: `HEALTHCHECK` (bun-native `fetch` against `/healthz`, no curl/wget in the slim image) and an `org.opencontainers.image.version` label driven by the `APP_VERSION` build arg.

## Changed

- **`socrata_dataframe_query`**: SQL execution now passes `denySystemCatalogs: true`. The `sql_rejected` contract and recovery text document that `information_schema`, `pg_catalog`, `sqlite_master`, and `duckdb_*` references are rejected — use `socrata_dataframe_describe` to list tables and schemas.
- **`lint:packaging`**: extended with bundle-content guards (root-anchored `.mcpbignore` evaluation, post-pack agent-doc strip verification) and an identity check that `name`/`title` and manifest `display_name` equal the unscoped package name.
- **`check-framework-antipatterns`**: new `coerce-boolean-env-flag` rule (`z.coerce.boolean()` can't be disabled via env — use `z.stringbool()`); comment lines are now skipped so a documented mention isn't flagged as a usage.
- **`.mcpbignore`**: dev-directory and tooling patterns root-anchored with a leading `/` so they no longer strip nested runtime paths under `node_modules/`.
- **`bundle`**: runs `scripts/clean-mcpb.ts` after `mcpb pack` to drop dependency-shipped agent docs (`skills/`, `.claude/`, `.agents/`, `SKILL.md`) that root-anchored ignore patterns cannot reach.
- **`.codex-plugin/plugin.json`**: `interface.displayName` set to the unscoped `socrata-mcp-server`.
- Vendored agent skills re-synced to the installed framework version.

Dependency bumps:

- `@cyanheads/mcp-ts-core` ^0.9.21 → ^0.10.6
- `@types/node` ^25.9.1 → ^25.9.3
- `vitest` ^4.1.7 → ^4.1.8
