---
summary: "mcp-ts-core ^0.10.6 → ^0.10.9 maintenance: devcheck dependency-specifier guard + plugin-manifest packaging checks, fresh-scaffold devcheck guards, re-synced scripts and skills"
breaking: false
security: false
---

# 0.1.9 — 2026-06-20

Framework-maintenance release — no source or tool-behavior changes. Adopts `@cyanheads/mcp-ts-core` `^0.10.7`–`^0.10.9` via re-synced devcheck scripts and skills.

## Added

- **`scripts/check-dependency-specifiers.ts`** + **`Dependency Specifiers` devcheck step** (flag `--no-dep-specifiers`): hard-fails on floating specifiers (`latest`, `*`, the dist-tags `next`/`beta`/`canary`/`rc`) in `package.json`'s dependency sections and `bun.lock`'s `workspaces` map. `latest` fails everywhere; `*`/dist-tags fail in `dependencies`/`devDependencies` but are allowed in `peer`/`optional`. Static and local — runs in the default and `--fast` passes. ([#246](https://github.com/cyanheads/mcp-ts-core/issues/246))
- **Plugin-manifest packaging checks** (`scripts/lint-packaging.ts` check 10): validates `.claude-plugin/plugin.json` and `.codex-plugin/plugin.json` — non-empty descriptions, display fields carrying the unscoped machine name, and the `npx -y` install arg carrying the full `package.json` name. Gated by the new `devcheck.config.json` `packaging.pluginManifests` flag (default on); the `Packaging` gate now also runs when a plugin manifest is present. ([#240](https://github.com/cyanheads/mcp-ts-core/issues/240))

## Changed

- **Re-synced vendored agent skills** to the installed framework version — body-drift propagation across `add-tool`, `api-canvas`, `api-config`, `api-context`, `api-telemetry`, `git-wrapup`, `orchestrations`, `polish-docs-meta`. ([#238](https://github.com/cyanheads/mcp-ts-core/issues/238))

## Fixed

- **Fresh-scaffold devcheck guards** — `devcheck.ts`, `check-framework-antipatterns.ts`, and `build-changelog.ts` now skip cleanly outside a git repo (the TODOs/FIXMEs, Tracked Secrets, Framework Antipatterns, and Changelog Sync steps shell out to `git`/changelog files that don't exist before `git init`, which surfaced as a failure on a fresh `init`). ([#242](https://github.com/cyanheads/mcp-ts-core/issues/242), [#243](https://github.com/cyanheads/mcp-ts-core/issues/243))
- **`scripts/check-skill-versions.ts`** — skips a `SKILL.md` deleted from the worktree (`existsSync` guard) instead of crashing with ENOENT on a maintenance pass that prunes an upstream-removed skill. ([#237](https://github.com/cyanheads/mcp-ts-core/issues/237))

Dependency bumps:

- `@cyanheads/mcp-ts-core` ^0.10.6 → ^0.10.9
- `@biomejs/biome` ^2.4.16 → ^2.5.0
- `@types/node` ^25.9.3 → ^26.0.0
- `vitest` ^4.1.8 → ^4.1.9
