# Changelog

All notable changes to this project will be documented in this file. See [standard-version](https://github.com/conventional-changelog/standard-version) for commit guidelines.

### [0.1.2](https://github.com/alejandrosaenz117/fetch-cwe-list/compare/v0.1.1...v0.1.2) (2026-08-29)


### Features

* **package.json:** add high-intent keywords ([469b67a](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/469b67aa34a3ce0f76033d5c607459bfb4370d6c))


### Bug Fixes

* **deps:** update dependencies to address security vulnerabilities ([d6b0b97](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/d6b0b9724be73d60cc7ff425f36af1a8efa60301))
* pin actions/checkout to immutable commit SHA (CWE-494) ([6a432b7](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/6a432b7b5de9edd137520b2f6c89e0e758d0463b)), closes [#24](https://github.com/alejandrosaenz117/fetch-cwe-list/issues/24)


### CI

* add guppy-agent security scanning workflow ([8eca674](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/8eca674eb18247d53000bb2b2aec16f1dbfd7bb8))


### Docs

* add MCP server section to root README ([34b0b68](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/34b0b6832752e8b9ff9e1c3ceea3760ccd51f9a6))
* add npm badge link to MCP package README ([6fd9c51](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/6fd9c51565669f06c63e911cc6871502b5ee06d0))
* add npm badge to root README ([9696b8e](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/9696b8e8ef0f188ab79d5069a65ef8581dbe00a2))


### Others

* **.gitignore:** ignore aider artifacts ([417bcda](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/417bcda3d6b4b05b365d63b86be56e98376af290))
* bump guppy-agent to v1.8.15 ([0b61072](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/0b61072d6a387206eebf8d3f0678b8887c3a3906))
* bump guppy-agent to v1.8.17 ([7f88cc1](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/7f88cc1e4880575a98c27b016dd559a6193ebdb6))
* clean up .gitignore ([9b17aba](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/9b17aba0f8d2f8f96c6dc0a23e967ed26f91d0e1))
* remove tracked coverage artifacts from git ([117c225](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/117c22595d7d0d5135948b6201beaa3e509b69e9))

### [0.1.1](https://github.com/alejandrosaenz117/fetch-cwe-list/compare/v0.1.0...v0.1.1) (2026-04-19)


### Features

* **mcp:** add fetch-cwe-list-mcp MCP server workspace package ([ade1497](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/ade14974eb94dc6cc5c9a709d0e80b641912b6fd))


### Bug Fixes

* **mcp:** pin dependency versions for supply chain security ([8d6e128](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/8d6e128d350cfaed6f5b8534388ab52130109fb6))
* replace __dirname with os.tmpdir() for ESM/ncc bundle compatibility ([87d5ce3](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/87d5ce3033d5baa96508bd0f08ddab31b6b1c3db))


### Others

* ignore cwe-sdk-javascript directory, remove demo.js ([86c3cbb](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/86c3cbbebe52c25a926160242bcf7df672e1ea41))


### Docs

* fix author GitHub link to alejandrosaenz117 ([7a43b66](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/7a43b669ffbdedb0cd08b756e8638851102c93e9))
* fix CAPEC-79 examples with actual MITRE mappings ([a3271b4](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/a3271b4d9ff1a0d01295e68febfc5d15f55e8668))
* fix CVE example in README with actual CWE-79 observed CVE ([4421922](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/442192282704de73287befb840309f812c187fa9))
* streamline README - remove fluff, consolidate examples ([53c245f](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/53c245f37e41152c2a8ce74aa8185804fa3b0627))


### Tests

* add 37 integration tests against live MITRE data ([a0db8da](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/a0db8da3bbd3c9f75b0a3b6773b342f07c2fe6b6))
* add verified CAPEC-to-CWE mapping integration tests ([da51056](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/da510564e3bccbfa117b1d0afa7b8ed6c5240f4d))
* **mcp:** expand test suite to 31 comprehensive tests ([4a2f586](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/4a2f5867a1812ca75b3c7cd850c999726688de77))

## [0.1.0](https://github.com/alejandrosaenz117/fetch-cwe-list/compare/v0.0.12...v0.1.0) (2026-04-19)


### Features

* add CAPEC_IDs enrichment from Related_Attack_Patterns ([bb93470](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/bb93470bedb11e243f2ce052baa54d22a932a7f0))
* add findById, findByName (string-only, ReDoS-safe), findByCapec named exports ([e2e2d37](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/e2e2d37db08f7b0f42fea9fee264692b8f12e2d9))
* add Hierarchy enrichment (parents array + full relationships) ([97925d2](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/97925d2cfda97ba1ea9a24c0a19da4ed3c075546))
* add Known_CVEs enrichment from Observed_Examples ([eb266e3](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/eb266e3acb09450d9ab3433057687b2a182ba512))
* add opt-in TTL cache with clone isolation, in-flight dedup, clearCache() API ([5e2103d](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/5e2103d9f25b9d53afd378dd8151d0bfedb9cead))
* add TypeScript definitions (index.d.ts) ([68843f1](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/68843f169aabaa070859ea1dfd274ffddf81c6da))


### Code Refactoring

* extract reference enrichment into lib/, normalize cwe.ID to string ([dbd4013](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/dbd4013462d88d526b975e01a0cb8302541f49a1))


### Docs

* add v0.1.0 feature documentation (CAPEC, Hierarchy, CVEs, query helpers, cache, TypeScript) ([d984b3a](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/d984b3a82a6a7869a2e6db226cc5522990cd00a0))

### [0.0.12](https://github.com/alejandrosaenz117/fetch-cwe-list/compare/v0.0.10...v0.0.12) (2026-04-11)


### Bug Fixes

* **deps:** resolve all critical and high severity vulnerabilities ([2d6342e](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/2d6342e3a1b954c9020981510c85888e09d86ad5))


### Others

* **release:** 0.0.11 ([b8037a8](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/b8037a8d517a48977c4d34a4e50eb6b219d32e60))
* update repository URL to point to fork ([5e313ce](https://github.com/alejandrosaenz117/fetch-cwe-list/commit/5e313ce626dbdeae3b22cdf25cf42da3045ff1db))

### [0.0.11](https://github.com/Whamo12/fetch-cwe-list/compare/v0.0.10...v0.0.11) (2026-04-11)


### Bug Fixes

* **deps:** resolve all critical and high severity vulnerabilities ([2d6342e](https://github.com/Whamo12/fetch-cwe-list/commit/2d6342e3a1b954c9020981510c85888e09d86ad5))

### [0.0.10](https://github.com/Whamo12/fetch-cwe-list/compare/v0.0.9...v0.0.10) (2026-04-11)

### [0.0.9](https://github.com/Whamo12/fetch-cwe-list/compare/v0.0.3...v0.0.9) (2026-04-11)


### Features

* merge upstream v0.0.7 with enhanced security hardening ([b6762d5](https://github.com/Whamo12/fetch-cwe-list/commit/b6762d522fb81a765c51066f9e7ca2bef204cfef))


### Bug Fixes

* **deps:** upgrade axios ^1.15.0, unzipper ^0.12.3, replace xml2json with fast-xml-parser ([67fd580](https://github.com/Whamo12/fetch-cwe-list/commit/67fd580ece4ff69ccfeb0dea2323ae31691b3cb5))
* eliminate async promise executor and handle single references correctly ([f62c634](https://github.com/Whamo12/fetch-cwe-list/commit/f62c63497c67af6561cff31cf128305b29229e70))
* **index.js:** add 30s timeout and 100MB response size limit to axios request ([b1bd7bc](https://github.com/Whamo12/fetch-cwe-list/commit/b1bd7bc94b02e37e2fdfee45ce5d71fca653a887))
* **index.js:** handle single vs array elements in XML parsing ([9cefa22](https://github.com/Whamo12/fetch-cwe-list/commit/9cefa227ac33aa309ce003db5a9ba4b882041db1))
* **index.js:** move externalReferenceAry to function scope to prevent concurrent call data leakage ([8c623f0](https://github.com/Whamo12/fetch-cwe-list/commit/8c623f0008864674755eee68da6a8a944ceea9e5))
* **index.js:** propagate fs.writeFile errors to the promise instead of silently hanging ([31cc35b](https://github.com/Whamo12/fetch-cwe-list/commit/31cc35b6f928fd33eef73645156e421002740242))
* **index.js:** replace xml2json with fast-xml-parser to eliminate XXE attack surface ([934db90](https://github.com/Whamo12/fetch-cwe-list/commit/934db909b92390e59293d97b81f1d4bcc0f32f18))
* **index.js:** use unzipper.Open for pre-extraction Zip Slip validation ([3c76c66](https://github.com/Whamo12/fetch-cwe-list/commit/3c76c665240459092e634a4e7e7e5757b2ce966c))


### Others

* **deps:** bump json5 from 1.0.1 to 1.0.2 ([8f049b6](https://github.com/Whamo12/fetch-cwe-list/commit/8f049b6011436fae84afd2993cee97692b7d628a))
* npm audit fix to resolve transitive dependency vulnerabilities ([66cacc8](https://github.com/Whamo12/fetch-cwe-list/commit/66cacc8f7dcf7e64bfe3cadda54acb5d4decbbf5))
* **release:** 0.0.8 ([394dd95](https://github.com/Whamo12/fetch-cwe-list/commit/394dd95ac2899f1c487c71a94dd65210a30d7a26))
* update package-lock.json for Jest devDependency ([3c8c92d](https://github.com/Whamo12/fetch-cwe-list/commit/3c8c92d6d83eade9efe71d0ac6abc03ec6f8b84c))


### Tests

* add security feature verification tests for v0.0.8 ([9eaff83](https://github.com/Whamo12/fetch-cwe-list/commit/9eaff83569c527f7806dfba256ac16afa8aed45e))
* **index.test.js:** add comprehensive unit tests with 92% coverage ([8bb7d01](https://github.com/Whamo12/fetch-cwe-list/commit/8bb7d012361a5849d210838223fbb5fa91cc722c))


### Docs

* add comprehensive testing report documenting 92.3% code coverage ([1097168](https://github.com/Whamo12/fetch-cwe-list/commit/10971687f1b6c7affe9c80246af90b63d54e6265))
* redesign README for better UX and scannability ([c13c6e8](https://github.com/Whamo12/fetch-cwe-list/commit/c13c6e8cf8d400da8200f9e41aecf4566fb608f2))

### [0.0.8](https://github.com/Whamo12/fetch-cwe-list/compare/v0.0.3...v0.0.8) (2026-04-11)


### Features

* merge upstream v0.0.7 with enhanced security hardening ([b6762d5](https://github.com/Whamo12/fetch-cwe-list/commit/b6762d522fb81a765c51066f9e7ca2bef204cfef))


### Bug Fixes

* **deps:** upgrade axios ^1.15.0, unzipper ^0.12.3, replace xml2json with fast-xml-parser ([67fd580](https://github.com/Whamo12/fetch-cwe-list/commit/67fd580ece4ff69ccfeb0dea2323ae31691b3cb5))
* eliminate async promise executor and handle single references correctly ([f62c634](https://github.com/Whamo12/fetch-cwe-list/commit/f62c63497c67af6561cff31cf128305b29229e70))
* **index.js:** add 30s timeout and 100MB response size limit to axios request ([b1bd7bc](https://github.com/Whamo12/fetch-cwe-list/commit/b1bd7bc94b02e37e2fdfee45ce5d71fca653a887))
* **index.js:** handle single vs array elements in XML parsing ([9cefa22](https://github.com/Whamo12/fetch-cwe-list/commit/9cefa227ac33aa309ce003db5a9ba4b882041db1))
* **index.js:** move externalReferenceAry to function scope to prevent concurrent call data leakage ([8c623f0](https://github.com/Whamo12/fetch-cwe-list/commit/8c623f0008864674755eee68da6a8a944ceea9e5))
* **index.js:** propagate fs.writeFile errors to the promise instead of silently hanging ([31cc35b](https://github.com/Whamo12/fetch-cwe-list/commit/31cc35b6f928fd33eef73645156e421002740242))
* **index.js:** replace xml2json with fast-xml-parser to eliminate XXE attack surface ([934db90](https://github.com/Whamo12/fetch-cwe-list/commit/934db909b92390e59293d97b81f1d4bcc0f32f18))
* **index.js:** use unzipper.Open for pre-extraction Zip Slip validation ([3c76c66](https://github.com/Whamo12/fetch-cwe-list/commit/3c76c665240459092e634a4e7e7e5757b2ce966c))


### Tests

* **index.test.js:** add comprehensive unit tests with 92% coverage ([8bb7d01](https://github.com/Whamo12/fetch-cwe-list/commit/8bb7d012361a5849d210838223fbb5fa91cc722c))


### Docs

* add comprehensive testing report documenting 92.3% code coverage ([1097168](https://github.com/Whamo12/fetch-cwe-list/commit/10971687f1b6c7affe9c80246af90b63d54e6265))


### Others

* **deps:** bump json5 from 1.0.1 to 1.0.2 ([8f049b6](https://github.com/Whamo12/fetch-cwe-list/commit/8f049b6011436fae84afd2993cee97692b7d628a))
* npm audit fix to resolve transitive dependency vulnerabilities ([66cacc8](https://github.com/Whamo12/fetch-cwe-list/commit/66cacc8f7dcf7e64bfe3cadda54acb5d4decbbf5))
* update package-lock.json for Jest devDependency ([3c8c92d](https://github.com/Whamo12/fetch-cwe-list/commit/3c8c92d6d83eade9efe71d0ac6abc03ec6f8b84c))

### [0.0.3](https://github.com/Whamo12/fetch-cwe-list/compare/v0.0.2...v0.0.3) (2022-12-06)


### Bug Fixes

* **index.js:** there was an issue with parsing the XML file due to the version number changes ([5be3592](https://github.com/Whamo12/fetch-cwe-list/commit/5be359256ead1173ed4497c5c7a8692cc203cf96))

### [0.0.2](https://github.com/Whamo12/fetch-cwe-list/compare/v0.0.2-alpha.2...v0.0.2) (2020-11-29)

### [0.0.2-alpha.2](https://github.com/Whamo12/fetch-cwe-list/compare/v0.0.2-alpha.1...v0.0.2-alpha.2) (2020-11-29)

### [0.0.2-alpha.1](https://github.com/Whamo12/fetch-cwe-list/compare/v0.0.2-alpha.0...v0.0.2-alpha.1) (2020-11-29)


### Docs

* **package.json readme.md:** update README to include example. Add git cz ([88222d2](https://github.com/Whamo12/fetch-cwe-list/commit/88222d2cc5b16b8a1907968c56ca5ac7e8d9e427))

### [0.0.2-alpha.0](https://github.com/Whamo12/fetch-cwe-list/compare/v0.0.2-0...v0.0.2-alpha.0) (2020-11-29)

### [0.0.2-0](https://github.com/Whamo12/fetch-cwe-list/compare/v0.0.1...v0.0.2-0) (2020-11-29)

### [0.0.1](https://github.com/Whamo12/fetch-cwe-list/compare/v0.0.1-alpha.2...v0.0.1) (2020-11-29)

### [0.0.1-alpha.2](https://github.com/Whamo12/cwe-list/compare/v0.0.1-alpha.1...v0.0.1-alpha.2) (2020-11-29)

### [0.0.1-alpha.1](https://github.com/Whamo12/cwe-list/compare/v0.0.1-alpha.0...v0.0.1-alpha.1) (2020-11-29)

### 0.0.1-alpha.0 (2020-11-29)
