Raw JSON report machine-readable
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 38082,
"has_wiki": true,
"homepage": "https://klarlabs-studio.github.io/mcp-go/",
"languages": {
"Go": 1047796,
"CSS": 5746,
"Astro": 80422,
"Makefile": 2628,
"JavaScript": 181
},
"pushed_at": "2026-07-25T19:54:47Z",
"created_at": "2025-12-25T20:36:01Z",
"owner_type": "Organization",
"updated_at": "2026-07-25T19:53:52Z",
"description": "A Go framework for building MCP (Model Context Protocol) servers",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": "https://klarlabs.de",
"name": "Klarlabs",
"type": "Organization",
"login": "klarlabs-studio",
"company": null,
"location": "Munich, Germany",
"followers": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/291279584?v=4",
"created_at": "2026-06-06T11:23:11Z",
"is_verified": null,
"public_repos": 32,
"account_age_days": 49
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v1.24.0",
"kind": "minor",
"published_at": "2026-07-11T11:02:38Z"
},
{
"tag": "v1.23.0",
"kind": "minor",
"published_at": "2026-07-11T10:38:20Z"
},
{
"tag": "v1.22.0",
"kind": "minor",
"published_at": "2026-07-10T15:10:46Z"
},
{
"tag": "v1.21.0",
"kind": "minor",
"published_at": "2026-07-06T07:34:11Z"
},
{
"tag": "v1.20.1",
"kind": "patch",
"published_at": "2026-07-03T07:35:37Z"
},
{
"tag": "v1.20.0",
"kind": "minor",
"published_at": "2026-06-23T10:26:33Z"
},
{
"tag": "v1.19.0",
"kind": "minor",
"published_at": "2026-06-20T20:46:25Z"
},
{
"tag": "v1.18.0",
"kind": "minor",
"published_at": "2026-06-20T15:15:21Z"
},
{
"tag": "v1.17.1",
"kind": "patch",
"published_at": "2026-06-13T21:02:30Z"
},
{
"tag": "v1.17.0",
"kind": "minor",
"published_at": "2026-06-08T22:05:01Z"
},
{
"tag": "v1.16.0",
"kind": "minor",
"published_at": "2026-06-08T20:53:11Z"
},
{
"tag": "v1.15.0",
"kind": "minor",
"published_at": "2026-06-06T20:02:02Z"
},
{
"tag": "v1.14.0",
"kind": "minor",
"published_at": "2026-06-02T14:44:30Z"
},
{
"tag": "v1.13.0",
"kind": "minor",
"published_at": "2026-05-18T05:52:24Z"
},
{
"tag": "v1.12.0",
"kind": "minor",
"published_at": "2026-05-17T19:22:40Z"
},
{
"tag": "v1.11.2",
"kind": "patch",
"published_at": "2026-05-12T07:19:40Z"
},
{
"tag": "v1.11.0",
"kind": "minor",
"published_at": "2026-05-10T18:31:57Z"
},
{
"tag": "v1.10.1",
"kind": "patch",
"published_at": "2026-05-10T09:35:39Z"
},
{
"tag": "v1.10.0",
"kind": "minor",
"published_at": "2026-05-02T11:27:24Z"
},
{
"tag": "v1.9.0",
"kind": "minor",
"published_at": "2026-03-21T18:11:34Z"
},
{
"tag": "v1.8.0",
"kind": "minor",
"published_at": "2026-03-21T10:33:28Z"
},
{
"tag": "v1.7.0",
"kind": "minor",
"published_at": "2026-02-24T20:39:22Z"
},
{
"tag": "v1.6.4",
"kind": "patch",
"published_at": "2026-02-01T16:19:21Z"
},
{
"tag": "v1.6.3",
"kind": "patch",
"published_at": "2026-02-01T15:12:22Z"
},
{
"tag": "v1.6.2",
"kind": "patch",
"published_at": "2026-01-28T20:41:34Z"
},
{
"tag": "v1.6.1",
"kind": "patch",
"published_at": "2026-01-28T16:54:31Z"
},
{
"tag": "v1.2.1",
"kind": "patch",
"published_at": "2026-01-28T17:12:04Z"
},
{
"tag": "v1.6.0",
"kind": "minor",
"published_at": "2026-01-28T09:52:06Z"
},
{
"tag": "v1.5.0",
"kind": "minor",
"published_at": "2026-01-15T10:10:43Z"
},
{
"tag": "v1.4.0",
"kind": "minor",
"published_at": "2026-01-03T13:04:54Z"
},
{
"tag": "v1.3.4",
"kind": "patch",
"published_at": "2026-01-02T18:42:23Z"
},
{
"tag": "v1.3.3",
"kind": "patch",
"published_at": "2026-01-02T18:31:47Z"
},
{
"tag": "v1.3.2",
"kind": "patch",
"published_at": "2025-12-31T18:16:00Z"
},
{
"tag": "v1.3.1",
"kind": "patch",
"published_at": "2025-12-30T08:14:18Z"
},
{
"tag": "v1.3.0",
"kind": "minor",
"published_at": "2025-12-27T13:13:24Z"
},
{
"tag": "v1.2.0",
"kind": "minor",
"published_at": "2025-12-26T10:14:53Z"
},
{
"tag": "v1.1.0",
"kind": "minor",
"published_at": "2025-12-25T22:53:33Z"
},
{
"tag": "v1.0.0",
"kind": "major",
"published_at": "2025-12-25T22:03:15Z"
}
],
"recent_commits": [
{
"oid": "45223e3fe3c460b0a78b211139a9c675ff6c2ebb",
"body": "Clear the residual medium-severity dependency advisory reported by\nnox 1.16.1:\n - golang.org/x/text v0.38.0 -> v0.40.0 (GO-2026-5970: infinite loop on\n invalid input)\n\nNot gating (the CI gate fails only on net-new critical/high), but it is a\nreal known advisory with a patched release available.\n\ngo build and go vet pass.\n\nClaude-Session: https://claude.ai/code/session_01Cr6YdzphmFF3NJqm7kSJom",
"is_bot": false,
"headline": "fix(security): bump x/text to a patched version (#136)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-25T19:53:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1cadfe40ccc0413471b94d683da835a9fab292ba",
"body": "Branch protection requires `ci / Lint`, `ci / Test (ubuntu-latest)`,\n`ci / Build` and `ci / Security (nox)`, but the pull_request trigger had\npaths-ignore for **.md, docs/** and LICENSE. A docs-only PR therefore\nskipped the whole workflow, the required checks never reported, and the\nPR was BLOCKED f\n[…]\nps its paths-ignore, so merging docs changes still skips CI.\n\nMirrors the same fix already applied in warden, nox and statekit.\n\nClaude-Session: https://claude.ai/code/session_01Cr6YdzphmFF3NJqm7kSJom",
"is_bot": false,
"headline": "fix(ci): run CI on docs-only PRs so required checks can report (#135)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-25T19:20:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "85f74f962aec78af02df72eed02011c2b572d81b",
"body": "Remediate net-new CVE surfaced by nox 1.16.1:\n - google.golang.org/grpc v1.82.0 -> v1.82.1 (GHSA-hrxh-6v49-42gf, high:\n gRPC-Go xDS RBAC / HTTP/2)\n\ngo build and go vet pass. nox scan reports 0 net-new critical/high.\n\nClaude-Session: https://claude.ai/code/session_01Cr6YdzphmFF3NJqm7kSJom",
"is_bot": false,
"headline": "fix(security): bump grpc to patched version (#134)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-25T17:31:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b0ecc3b4e6d54b826bfc838b8d9ce117172e6f5a",
"body": "ai.inventory.json was committed into this repository and, because the\nnox-remediate workflow stages tracked modifications, it was refreshed and\nre-committed by every weekly run — inside a PR that auto-merges. Scan output is\na build artifact, not source.\n\nThe workflow now writes its output to RUNNER_\n[…]\n(klarlabs-studio/.github#40), so nothing new leaks. This removes what is already\ntracked and ignores it so it cannot come back.\n\nClaude-Session: https://claude.ai/code/session_01UCLAAksd3a1cmQz2LVs3ts",
"is_bot": false,
"headline": "chore: untrack nox scan artifacts (#133)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-21T19:14:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "488e6de97d6dfd7543b5c9b9ad753626590280b2",
"body": "Co-authored-by: nox-remediate <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(security): nox remediation (deps + actions) (#132)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T09:39:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "680a881f6deb0157adcbf8a92abbbc8100780676",
"body": "Co-authored-by: nox-remediate <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(security): nox remediation (deps + actions) (#131)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-13T09:51:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7a82d0444327d9d46e2320969a783a3b021d71f8",
"body": "…-fleet-ops\n\ndocs(claude): add fleet-ops failure modes",
"is_bot": false,
"headline": "Merge pull request #130 from klarlabs-studio/docs/known-failure-modes…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-11T20:28:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1257c5ea667a5b1e3f5b1d2964a86ed812dc95bd",
"body": "The prior note said setup-node's registry-url conflicts with OIDC and must be\nomitted — that WRONG belief cost the entire warden npm saga. Truth (warden\nv0.18.16 resolved): registry-url IS required; ENEEDAUTH = npm never tried OIDC\n(workflow bug), 404 = OIDC worked but trusted-publisher account config mismatch.\n\nClaude-Session: https://claude.ai/code/session_01T68jn2UbNWLE178iorAKtC",
"is_bot": false,
"headline": "docs(claude): correct npm-OIDC failure mode (registry-url IS required)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-11T19:47:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2de048d18677f85f4499dad205e609c285ded547",
"body": "…, force-push)\n\nRecords three lessons from the v1.24 fleet upgrade: local go.mod is not\nauthoritative for fleet-version work (branch subagents from origin/main);\nuse isolated git worktrees when a concurrent process may manipulate the\ncheckout; git push --force-with-lease is classifier-blocked, so replace a\nstale PR branch via close --delete-branch + fresh branch.\n\nClaude-Session: https://claude.ai/code/session_01T68jn2UbNWLE178iorAKtC",
"is_bot": false,
"headline": "docs(claude): add fleet-ops failure modes (stale checkouts, worktrees…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-11T12:17:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7ee3bd6a4bd3d49c21b6bb8c6ca92ea2fc4fbff3",
"body": "feat(transport)!: stateless-by-default for Streamable HTTP (v1.24.0)",
"is_bot": false,
"headline": "Merge pull request #129 from klarlabs-studio/feat/stateless-default",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-11T11:01:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d225deb3a196c859a65e1d2ac47500521d54718d",
"body": "…24.0)\n\nWithStreamable() now enables the stateless (MCP 2026-07-28) model by default:\nit drops the Mcp-Session-Id lifecycle and hard-requires the Mcp-Method routing\nheader (absent -> -32020). WithStreamableStateful() is the new opt-out into the\nlegacy session-negotiated (2025-03-26) path (mints/requ\n[…]\non-lifecycle test helper is pinned to WithStreamableStateful(); new\ntests cover the stateless default and the stateful opt-out.\n\nClaude-Session: https://claude.ai/code/session_01T68jn2UbNWLE178iorAKtC",
"is_bot": false,
"headline": "feat(transport)!: make stateless the default for Streamable HTTP (v1.…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-11T10:56:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3c7241b159d8bed06010174b6df16644cdbe9865",
"body": "chore(release): v1.23.0",
"is_bot": false,
"headline": "Merge pull request #128 from klarlabs-studio/chore/release-v1.23.0",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-11T10:36:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "277e5f3e1e5860572ac3776968986b482cc433c5",
"body": "Cut the v1.23.0 changelog: completes the 2026-07-28 stateless surface\n(Phase 4) on the v1 line — additive and backward-compatible, gated behind\nthe WithStreamableStateless opt-in. Retired lifecycle methods on the modern\npath and formalized the sampling/roots/logging deprecations with Go\n// Deprecate\n[…]\n2.0.0 is deferred.\n\nAlso retroactively documents the v1.22.0 stateless foundation, which was\ntagged without a changelog header.\n\nClaude-Session: https://claude.ai/code/session_01T68jn2UbNWLE178iorAKtC",
"is_bot": false,
"headline": "chore(release): v1.23.0",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-11T10:28:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "97161900b19a1f4e95f8f93275c33a5d03525275",
"body": "…y-methods\n\nfeat(mcp): complete Phase 4 (stateless surface) — stay on v1",
"is_bot": false,
"headline": "Merge pull request #127 from klarlabs-studio/feat/phase4-retire-legac…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-11T10:18:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "131352f8947decae152e24b2fecca53305cbd7ae",
"body": "…tay v1)\n\nMark the remaining Phase 4 checklist items against reality: deprecations\ndone (see prior commit), error renumbering done and already covered by\nTestModern_ResourceNotFoundRenumbered (the modern codes live in the\nreserved -32020..-32099 range; mcp-go emits no other legacy -3200x from a\nhand\n[…]\n1 by decision. All Phase 4 behavior ships behind the\nWithStreamableStateless opt-in, so it is additive and backward-compatible.\n\nClaude-Session: https://claude.ai/code/session_01T68jn2UbNWLE178iorAKtC",
"is_bot": false,
"headline": "docs(phase4): close deprecations + error-renumbering; defer v2.0.0 (s…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-11T10:14:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d5b31a76f6e7f5abf8b4879f6db2274b91e07427",
"body": "…ase 4)\n\nThe 2026-07-28 stateless revision retires the three server-initiated\nfeatures. Mark them with Go `// Deprecated:` markers so gopls/staticcheck/\npkg.go.dev flag usage, while keeping them fully functional for the 12-month\nwindow — nothing is removed, v1 servers are unaffected:\n\n- Sampling: Se\n[…]\nercise the still-functional API carry justified\n//nolint:staticcheck directives. No new lint issues; build/vet/test/race\ngreen.\n\nClaude-Session: https://claude.ai/code/session_01T68jn2UbNWLE178iorAKtC",
"is_bot": false,
"headline": "feat(server): deprecate server-initiated Roots, Sampling, Logging (Ph…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-11T10:14:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9bd503b879b31ca17db9338c075466f544f7efc8",
"body": "Record the Known Failure Modes accumulated during the Phase 4 push\n(worktree base drift, protected-main PR-only CI, stale LSP/Dependabot\ntraps, npm OIDC publishing, per-batch admin-merge auth) in CLAUDE.md, and\npersist the roady rev4 task's in-progress transition.\n\nClaude-Session: https://claude.ai/code/session_01T68jn2UbNWLE178iorAKtC",
"is_bot": false,
"headline": "chore(mcp): capture Phase 4 lessons and roady task state",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-11T09:55:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "392747653ff519b40e2261c1ddd1858eb0f3b313",
"body": "The stateless 2026-07-28 redesign replaces the initialize/ping handshake\nwith server/discover + per-request _meta, moves the log level into _meta,\nand swaps resources/subscribe+unsubscribe and the roots list-changed\nnotification for subscriptions/listen + MRTR. Generalize the existing\ntasks/list gat\n[…]\ng Phase 4 work: deprecate Roots/Sampling/Logging (12mo) and flip\nStateless to default for the v2.0.0 tag (gated on spec-final).\n\nClaude-Session: https://claude.ai/code/session_01T68jn2UbNWLE178iorAKtC",
"is_bot": false,
"headline": "feat(mcp): retire legacy lifecycle methods on the modern path (Phase 4)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-11T09:55:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ded0742f923ac341a9cdd14602d52de25b515178",
"body": "Phase 4 (foundation): 2026-07-28 stateless — server/discover + per-request _meta",
"is_bot": false,
"headline": "Merge pull request #126 from klarlabs-studio/feat/spec-phase4-2026-07-28",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T15:01:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e20d494f1359dbad90651dfdc6379af5cfeb2b66",
"body": "Phase 3: certify 2025-11-25 (tasks, URL elicitation, SEP-1303, icons, sampling-tools, JSON Schema 2020-12)",
"is_bot": false,
"headline": "Merge pull request #125 from klarlabs-studio/feat/spec-phase3-2025-11-25",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T15:00:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c0fda5daf0611d0a97290d62c36c8156511bf93e",
"body": "Spec revisions: certify 2024-11-05 → 2025-06-18, land 2025-11-25 features + shift-left CI",
"is_bot": false,
"headline": "Merge pull request #124 from klarlabs-studio/feat/spec-revisions-roadmap",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T14:57:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bb02c63416da427225fe57ade788cd803f29edbb",
"body": "Two open Phase 4 questions resolved by research, not code churn:\n\n- MCP Apps: the extension identifier is io.modelcontextprotocol/ui (NOT /apps —\n the feature is named \"MCP Apps\" but the negotiated id is /ui, per the ext-apps\n spec 2026-01-26). mcp-go already advertises ExtensionUI and associates \n[…]\nonfirmed OUT OF SCOPE — in-library auth was deliberately\n removed; enforcement belongs at the gateway (advertise-only stance).\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "docs(phase4): resolve MCP Apps extension id + auth scope open questions",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T14:46:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2fd45b633b28d902f2832d894fd2129360ce5666",
"body": "Record the five prerequisite increments landed toward v2 graduation: W3C Trace\nContext propagation (7020967), tasks/update + modern tasks/list retirement\n(cfc41f3), deterministic tools/list ordering (0e08182), full JSON Schema 2020-12\n$ref/$defs/composition (ce836c4), and the earlier modern Icon fields. Check off\nthe corresponding roadmap items.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "docs(phase4): changelog + roadmap for prerequisite batch",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T14:36:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ce836c48098d98d9a9d5f044bf677a1c482db9a6",
"body": "…ase 4)\n\nLoosen inputSchema/outputSchema to the full JSON Schema 2020-12 vocabulary\nrather than the flat object/array subset.\n\n- Extend Schema with $ref, $defs, oneOf/anyOf/allOf, and if/then/else\n (all omitempty). Rewrite MarshalJSON to encode via struct tags and only\n patch the two keys tags can\n[…]\n), and\n if/then/else. Unresolvable references are lenient and never reject valid\n input; recursion terminates on finite data.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(schema): full JSON Schema 2020-12 $ref/$defs and composition (Ph…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T14:34:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7020967d72533a2f55e6c43805c1ba1f91837a6e",
"body": "A modern (stateless) request carries the caller's distributed-trace\nposition in _meta (traceparent/tracestate/baggage) so the server span\njoins the client's trace. Wire it end to end:\n\n- protocol/constants.go: reserve MetaKeyTraceparent/Tracestate/Baggage\n in the existing MetaKey* block (reverse-DN\n[…]\ne trace id matches the incoming one and whose parent is the\nremote span; absent trace context still yields a working root span.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(otel): propagate W3C Trace Context from modern _meta (Phase 4)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T14:34:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0e08182a5723a3819069803cd22525e9261d86bd",
"body": "Server.Tools() is backed by a Go map whose iteration order is\nrandomized, so tools/list previously returned tools in a nondeterministic\norder across calls. Sort the slice by tool name (ascending) inside\nhandleToolsList before building the response, giving a stable order on\nevery call as required by MCP 2026-07-28.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(mcp): deterministic tools/list ordering (Phase 4, 2026-07-28)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T14:33:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cfc41f3818d66693e7dfc7c9c3fe68d3a979f868",
"body": "…ks extension)\n\nMove Tasks toward the io.modelcontextprotocol/tasks extension model (MCP\n2026-07-28):\n- Add tasks/update — refresh a non-terminal task's ttl (null clears the\n deadline) so a slow task is not evicted before it finishes; unknown/terminal\n tasks map to -32602. Backed by Server.UpdateA\n[…]\nefresh, unknown-task rejection, and the legacy-served /\nmodern-not-found split for tasks/list. Full -race suite and lint green.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(mcp): tasks/update + gate tasks/list off for modern (Phase 4 tas…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T14:32:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9a5e15ed901ad299448e1f1054434191c354659f",
"body": "…less mode\n\nUpdate CHANGELOG and roadmap to reflect the two transport increments now landed:\nthe subscriptions/listen long-lived POST-response SSE stream (7579ccc) and\nWithStreamableStateless (ccece72) — hard-required Mcp-Method + dropped\nMcp-Session-Id. Check off the corresponding roadmap items.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "docs(phase4): transport realizations for subscriptions/listen + state…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T14:21:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7579cccc9c34f50aaa95eda9b612669a084db8fd",
"body": "…se 4)\n\nRealize the transport half of subscriptions/listen (MCP 2026-07-28): a single\nlong-lived POST-response SSE stream that replaces the GET stream +\nresources/subscribe/unsubscribe. On a subscriptions/listen POST the handler runs\nonce to register the subscription and return a subscriptionId; the\n[…]\nsubscription ack frame carries the subscriptionId and a pushed resource-updated\nnotification arrives tagged on the same stream.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(transport): subscriptions/listen long-lived POST SSE stream (Pha…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T14:18:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ccece729c84177678df5a480eee9d602a83e38a8",
"body": "…cp-Method (Phase 4)\n\nThe stateless (MCP 2026-07-28) streamable HTTP mode. WithStreamableStateless()\nimplies WithStreamable and switches the POST path to the modern model:\n- the Mcp-Session-Id lifecycle is dropped (no minting on initialize, no\n per-request header requirement) — every request self-d\n[…]\nired, required-header rejection, no session-id\nminting, and a guard that the default path still enforces the session lifecycle.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(transport): WithStreamableStateless — drop session id, require M…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T14:13:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7372a3a84ce55a4d93e92d1ee9e80d6f84822bbe",
"body": "…eaders, icons\n\nRecord the three parallel Phase 4 increments (each landed as its own commit):\nsubscriptions/listen (42fe28e), Streamable HTTP Mcp-Method/Mcp-Name routing\nheader validation (8a27d31), and additive modern Icon src/sizes/theme (a47decb).\nRoadmap items marked partial where a transport follow-up remains.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "docs(phase4): changelog + roadmap for subscriptions/listen, routing h…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T13:58:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "42fe28e4848159325dc1d14b80d7380e1b724525",
"body": "Add the modern (MCP 2026-07-28, stateless) subscriptions/listen method that\nreplaces the GET SSE stream plus resources/subscribe and resources/unsubscribe.\nA modern client opts into the notification types it wants and, optionally, the\nresource URIs it cares about; the requested URIs are registered o\n[…]\nd notifications is a\ndeferred transport follow-up (documented in the handler doc comment); nothing\nunder transport/ is touched.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(mcp): subscriptions/listen stateless subscription method (Phase 4)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T13:56:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a47decbeec31e2ed0f29cfa16dee4e67120a34e3",
"body": "Extend the Icon type so a single value serializes for both the legacy\n(2025-11-25, SEP-973) uri/mimeType/size shape and the modern (2026-07-28)\nsrc/sizes/theme shape. Add src/sizes/theme as omitempty fields, a NewIcon\nconstructor with WithMimeType/WithSizes/WithTheme builders, and a Normalize\nmethod that maps legacy<->modern fields without overwriting set values.\nLegacy struct literals and their JSON output are unchanged.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(server): additive modern icon fields (src/sizes/theme) (Phase 4)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T13:56:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8a27d3169e3e5f6cf432796a70252e7a8fdbdf6b",
"body": "Modern Streamable HTTP POSTs (MCP 2026-07-28) may carry routing headers so\nintermediaries route without parsing the body. Validate them when present:\nMcp-Method must equal the JSON-RPC method, and Mcp-Name must equal the body's\nprimary named target for name-bearing methods (tools/call -> name,\nresou\n[…]\ns\n\"required\", but enforcing their presence is deferred to a future Stateless\noption since the modern transport is still opt-in.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(transport): validate Mcp-Method/Mcp-Name routing headers (Phase 4)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T13:54:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bafe8dde2c60c28724bf378c52fa202164d57ac0",
"body": "Implement Multi Round-Trip Requests (SEP-2575), the stateless replacement for\nevery server-initiated request (sampling, elicitation, roots/list) in the\n2026-07-28 model. Fixes the ErrNoRequestSender dead-end those calls hit under\nmodern semantics (no connection to call back over).\n\nReplay/continuati\n[…]\ngration tests\ndrive the full sampling and elicitation round-trips through the real dispatcher.\nFull -race suite and lint green.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(mcp): MRTR / InputRequiredResult stateless input requests (Phase 4)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T13:45:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fb7dcf868eb1839abf4ed2bd2989b98bcfcdc80d",
"body": "Document sampling, roots, and logging as deprecated in MCP 2026-07-28 (SEP-2577,\n12-month window; still fully functional), with migration guidance (call provider\nAPIs directly / receive dirs via tool params or config / log to stderr+OTel).\nNo machine-readable Deprecated: marker, to avoid SA1019 churn on the module's\nown re-exports.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "docs(server): deprecation posture for roots/sampling/logging (Phase 4)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T12:54:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "137c11a88c49ad876d3f0d3455d3f2df37a1abb8",
"body": "Modern (2026-07-28) response shaping, dual-era:\n- WithResultCache(ttlMs, scope) stamps ttlMs/cacheScope on cacheable results\n (tools/list, prompts/list, resources/list, resources/read,\n resources/templates/list) for modern clients (SEP-2549). Legacy responses\n are untouched.\n- Resource-not-found \n[…]\nh step. Tests cover the cache\nhint (modern-only) and the error renumbering (modern vs legacy). Full -race\nsuite and lint green.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(mcp): CacheableResult + modern error renumbering (Phase 4)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T12:52:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ea02d8274282df965029cf88d905deabd3fb0020",
"body": "Serve modern (stateless) requests dual-era alongside legacy. A request carrying\nio.modelcontextprotocol/protocolVersion in _meta is:\n- validated for the required per-request fields (protocolVersion, clientInfo,\n clientCapabilities) → -32602 if missing;\n- version-checked → -32022 UnsupportedProtocol\n[…]\ntType stamping, unsupported-version rejection, missing-meta rejection, and\nlegacy passthrough. Full -race suite and lint green.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(mcp): stateless per-request _meta handling (Phase 4, 2026-07-28)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T12:45:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7c2f56489e0a892278344f71cccb8d19c6dfc840",
"body": "…-28)\n\nFirst increment of the stateless 2026-07-28 revision (SEP-2575), building the\nfoundation dual-era (initialize stays for legacy clients).\n\n- server/discover: stateless replacement for the initialize handshake — returns\n resultType/supportedVersions/capabilities(+extensions)/serverInfo/instruc\n[…]\nth (per-request _meta, MRTR, subscriptions/listen, routing headers)\nlands in later increments. Full -race suite and lint green.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(protocol): server/discover + modern foundation (Phase 4, 2026-07…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T12:41:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dea1ae3d228abe71f5ea024f4e4e6114373df673",
"body": "Add 2025-11-25 to SupportedVersions and advance the default MCPVersion to it;\nthe server now negotiates and honors all four revisions, conformance-gated.\n\nCompleting the revision:\n- SEP-1303: invalid tool input is a tool execution error (isError result) via\n the new ToolInputError, not a -32602 pro\n[…]\nthe SEP-1303\nbehavior. Full -race suite and lint green across all 11 packages; conformance\nruns against every SupportedVersion.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(protocol): certify 2025-11-25 (Phase 3 complete)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T12:32:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4257d3e8c15faf0c6d73eab8cd77b6e408155cd5",
"body": "Spec-conformant MCP 2025-11-25 Tasks. A tools/call carrying `task: {ttl}` is\naccepted immediately with a CreateTaskResult and runs in the background; the\nrequestor polls tasks/get and fetches the outcome via tasks/result.\n\n- New augmented-task registry (server/tasks_augment.go): cryptographically\n \n[…]\n, rejections, cancel-terminal, and capability/\nexecution advertisement; full -race suite (3x on the async path) and lint green.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(server): task-augmented requests / tasks/* (Phase 3, SEP-1686)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T12:10:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f839cf9cdb71efa5788751ffee9769b5077ff025",
"body": "Negotiate and honor 2025-03-26 and 2025-06-18 in addition to 2024-11-05;\nprotocol.MCPVersion (the default when a client requests an unknown/empty\nversion) advances to 2025-06-18.\n\n- Top-level `title` (2025-06-18) on tools/resources/resource-templates/prompts,\n advertised beside `name` in every list\n[…]\nns with a version-aware initialize echo, plus 2025-06-18 title\ncases. 39 conformance subtests, full -race suite and lint green.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(protocol): certify 2025-03-26 and 2025-06-18 (Phases 1-2)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T11:42:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "384f4a6ffdbd9234962b77087ca6a203934cc96a",
"body": "Integration of the parallel feature batch:\n- Advertise icons in tools/list, resources/list, resources/templates/list,\n prompts/list.\n- Re-export WithStreamable and the SamplingTool/ToolChoice/ToolCall types.\n- Tests: icons advertised in tools/list; audio + resource_link content blocks\n flow throug\n[…]\nsion certification (batching gating, MCP-Protocol-\nVersion enforcement, tasks/*, URL elicitation remain before a version bump).\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(mcp): wire Phase 1-3 features into the facade + dispatcher",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T11:33:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4da946b3d9b54bdaf31be7927de415e56f3854ee",
"body": "…-973)\n\nAdd an .Icons(...) builder to ToolBuilder/ResourceBuilder/PromptBuilder and\nexpose icons via ToolInfo/ResourceInfo/ResourceTemplateInfo/PromptInfo so the\ndispatcher can advertise them. Additive; empty by default.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(server): icons metadata on tools/resources/prompts (Phase 3, SEP…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T11:33:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "78d77c98c0f5facd4eb20945750877c486a10ad5",
"body": "sampling/createMessage can now offer tools to the model: CreateMessageRequest\ngains Tools/ToolChoice, CreateMessageResult gains ToolCalls, and a new\nSession.CreateMessageWithTools delegates through the shared request path (so the\nsampling gate and ErrNoRequestSender guard are identical). New types\nSamplingTool/SamplingToolChoice/SamplingToolCall.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(server): sampling with tools (Phase 3, SEP-1577)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T11:33:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "794bd9c8c2c910f50bda008747bce9be5946e357",
"body": "Generated root schemas now carry the 2020-12 dialect marker\n($schema: https://json-schema.org/draft/2020-12/schema); add the\nschema.Dialect2020_12 constant. Additive — existing type/properties/required/\nenum output is unchanged; arrays already use single-schema items (correct\n2020-12 list-validation semantics).\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(schema): JSON Schema 2020-12 dialect (Phase 3, SEP-1613)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T11:33:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c126edbce97702f0c14c62deb897a55f85fa4750",
"body": "…only)\n\nExtend the /.well-known/mcp document with RFC 9728 protected-resource metadata\n(authorizationServers, protectedResourceMetadata, resourceIndicator,\nscopesSupported) and an oidcConfiguration pointer, via WithDiscoveryOAuthMetadata.\nAdditive and advertise-only — the library still performs no token handling or\nOAuth flows; this just lets spec-compliant clients discover the auth server.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(transport): OAuth/OIDC discovery metadata (Phase 1-2, advertise-…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T11:32:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b278a6fc9cbe69be5e0b72327cbda4e38e75c8b2",
"body": "Add modern Streamable HTTP support behind WithStreamable(): a single /mcp\nendpoint accepting POST (JSON or SSE reply negotiated via Accept), GET (a\nstanding server→client SSE stream keyed by Mcp-Session-Id), and DELETE\n(session teardown). Mcp-Session-Id is minted on initialize and required/echoed\nth\n[…]\nter; origin/authorize/size limits apply on every path. The legacy\nHTTP+SSE endpoints stay the default, byte-for-byte unchanged.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(transport): Streamable HTTP server (Phase 1, 2025-03-26)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T11:32:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "12ab748377579afe50743d0d2452c4d0561c88f9",
"body": "Collapse the loosely-duplicated content representations onto a single canonical\nunion. Content gains uri/name/description/resource/annotations fields (all\nomitempty, so text and image blocks serialize byte-identically) and is aliased\nas ContentBlock. New constructors: NewAudioContent (2025-03-26),\nN\n[…]\nhase 2) content\ntypes build on.\n\nTests: wire-shape of every content constructor; Content/ContentBlock alias\ninterchangeability.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(server): unify content into ContentBlock union (Phase 0)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T11:03:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dcaa186130d2ab54c86b252d369ed5e3c05cc98b",
"body": "Add mcp_conformance_test.go: a table-driven harness that drives a fully\nfeatured reference server (tool, static + templated resource, prompt,\ncompletion) through every method the 2024-11-05 revision defines and asserts\nthe response shape. Cases carry a minVersion so later phases append their new\nmet\n[…]\npromote the \"type\"/\"uri\" map keys in mcp.go to fieldType/fieldURI\nconstants (goconst) now that the harness references them too.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "test(conformance): per-revision method harness (Phase 0 gate)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T10:59:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "af47cf156a7db316fef7d850ab9eae170ac3f8e1",
"body": "Phase 0: make session-dependent features reachable. stdio and websocket now\nattach a per-connection server.Session to every request context, so logging\nnotifications, channels, and resource-updated — previously dead because\nSessionFromContext(ctx) was always nil — work end to end. Client capabilitie\n[…]\nTests: stdio session injection; ErrNoRequestSender for sampling/roots/\nelicitation; channels work with a notifier-only session.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(transport): inject per-connection session (stdio, websocket)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T10:56:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fc177c819ed231f80a082defef9e156c4adcbfb1",
"body": "Backbone for the spec-revisions roadmap plus the wiring fixes that make\nalready-implemented features reachable.\n\n- protocol.SupportedVersions / IsSupportedVersion / NegotiateVersion. initialize\n now parses and negotiates the client's protocolVersion instead of hard-\n returning the server's own; ne\n[…]\non negotiation, capability advertisement, wired-method dispatch,\nsetLevel validation, templates/list, client-capability decode.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "feat(protocol): version negotiation + wire dead methods (Phase 0)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T10:42:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ae32de842a7c07e9ac29ae48b2225bb935b48280",
"body": "Complete the migration from the hand-rolled .githooks/ to warden as the\nsingle shift-left gate, and load the spec-revisions plan into Roady.\n\n- Arm warden pre-commit (fmt ∥ vet ∥ lint) and pre-push (build ∥ test),\n mirroring the shared go-ci.yml bar. Remove the legacy .githooks/pre-commit\n and the\n[…]\ngo current across every MCP spec revision.\n- Load the 5-phase plan into Roady under a new \"Spec Revisions Alignment\"\n feature.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "chore(ci): warden shift-left gate + spec-revisions roadmap",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T10:41:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "15d7e24fc785e489d07b9b5e793b3c223840793d",
"body": "Co-authored-by: nox-remediate <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(security): nox remediation (deps + actions) (#123)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T11:09:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c34052d459591c056ca1dd143c7b9ea2bcd38762",
"body": "nox 1.7.0 uses fingerprint v2; the committed v1 baseline no longer matched.\nMigrated v1->v2 + refreshed so pre-accepted findings are recognized again.\nNo real finding suppressed. Claude-Session: https://claude.ai/code/session_01QKTcmXFTKoTQr7mB3HCuHZ",
"is_bot": false,
"headline": "chore(nox): refresh baseline to fingerprint v2 (nox 1.7.0) (#122)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T11:06:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "01c160ef846809cf3517b941d20bcb95a2e7250d",
"body": "Adds the 1.21.0 section covering the deep-review remediation (#115–#120):\nmiddleware defaults (Use() fix, Recover on by default), protocol correctness,\ndeterministic dispatch, transport origin/session/limit hardening, framing\nresilience, client bounds, and task/cancellation lifecycle. Minor bump — no\npending breaking changes (the stale [Unreleased] auth-removal shipped in\nv1.19.0/v1.20.0 and is pre-existing CHANGELOG debt).\n\nClaude-Session: https://claude.ai/code/session_01QKTcmXFTKoTQr7mB3HCuHZ",
"is_bot": false,
"headline": "docs(changelog): v1.21.0 — secure-by-default hardening (#121)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T07:32:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a6e55df13d20024b2cdb0d6e30aec3edf834cbf1",
"body": "…l leak (#120)\n\nLifecycle hardening for the tasks, cancellation, and subscription subsystems:\n\n- Task registry is now bounded. Each task stores its context-cancel func so\n CancelTask actually stops the running goroutine (previously a no-op that only\n flipped a status flag). Task goroutines derive \n[…]\nns deliberate protocol errors verbatim but logs and replaces any\n other error with a generic -32603, covering every transport.\n\nClaude-Session: https://claude.ai/code/session_01QKTcmXFTKoTQr7mB3HCuHZ",
"is_bot": false,
"headline": "fix(server): bound task registry, wire cancellation, stop error-detai…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T07:24:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0a0409bad2722b8d5d8dff08af09d6c5f937b4b9",
"body": "…ts (#119)\n\nHarden the stdio framing, session store, HTTP client, and observability\nmiddleware against a range of correctness and abuse issues surfaced in\ndeep review:\n\n- transport/framer: an over-cap (>16MB) frame no longer wedges the\n transport. ReadMessage drains the oversized line and returns a\n[…]\n per-client when a\n client id is on the context (ContextWithClientID), falling back to a\n documented global bucket otherwise.\n\nClaude-Session: https://claude.ai/code/session_01QKTcmXFTKoTQr7mB3HCuHZ",
"is_bot": false,
"headline": "fix(transport,client): resilient framing, bounded reads, safe redirec…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T07:24:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1fb7fa9b38c8eecfc880c23a7744c228568c6856",
"body": "The HTTP, SSE, and WebSocket transports were insecure by default. This\nmakes them secure-by-default with explicit, named opt-outs.\n\n- SSE session hijack: honor the caller's crypto-random correlation id but\n refuse to overwrite a live map entry, mint server-side with crypto/rand\n when none is suppl\n[…]\nor JSON-RPC notifications instead of a body.\n- CORS: reject the \"*\" origin + credentials combination by dropping\n credentials.\n\nClaude-Session: https://claude.ai/code/session_01QKTcmXFTKoTQr7mB3HCuHZ",
"is_bot": false,
"headline": "fix(transport): secure HTTP/SSE/WebSocket defaults (#118)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T07:24:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f050f1cc41f6584721f2eee04c43746adc87fb55",
"body": "…tration (#117)\n\nOverlapping resource URI templates dispatched to a non-deterministic\nhandler because matching ranged over the randomized resources map and\nreturned the first hit. Registering config://database alongside\nconfig://{key} meant a read of config://database could resolve to either,\nso aut\n[…]\n absolute paths, .. traversal, and symlink escape via\n Clean + Rel containment + EvalSymlinks. Params are untrusted/undecoded.\n\nClaude-Session: https://claude.ai/code/session_01QKTcmXFTKoTQr7mB3HCuHZ",
"is_bot": false,
"headline": "fix(server): deterministic resource matching + reject duplicate regis…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T07:23:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "471f686cec47220ef640c274d33fe4c176e60b2e",
"body": "…RPC ids (#116)\n\n- schema: reject JSON nested beyond maxJSONDepth (100) before encoding/json's\n recursive decoder can exhaust the stack (uncatchable fatal DoS).\n- protocol: Response.MarshalJSON always emits \"id\" (null when unset, per\n JSON-RPC 2.0 §5) and always carries \"result\" on success / never\n[…]\ner: ExtractProgressToken accepts string OR integer progressToken\n (MCP-compliant) instead of silently dropping numeric tokens.\n\nClaude-Session: https://claude.ai/code/session_01QKTcmXFTKoTQr7mB3HCuHZ",
"is_bot": false,
"headline": "fix(protocol): depth-limit untrusted JSON, spec-correct ids, escape g…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T07:23:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bd1b475b6bc2ddb7e4f422b61dc52b28b4a4427a",
"body": "…default (#115)\n\nDeep-review hardening of the core dispatch. Four fleet-wide defaults were unsafe:\n\n- Server.Use() was a dead no-op. newRequestHandler only read the WithMiddleware\n serve option; s.middleware (populated by Use) was never consulted, so every\n middleware added via the documented flue\n[…]\nanic-detail leak),\nand Timeout bounds a non-cooperative handler. Full suite green under -race,\ngofmt, golangci-lint (0 issues).\n\nClaude-Session: https://claude.ai/code/session_01QKTcmXFTKoTQr7mB3HCuHZ",
"is_bot": false,
"headline": "fix(server): secure middleware defaults — apply Use(), Recover on by …",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T06:56:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d2481b63c13d7afc8fbfa385919948144468229c",
"body": null,
"is_bot": false,
"headline": "chore(ci): use reusable nox-remediate workflow (#114)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-03T13:53:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7aa20c3c055fd51475cd45e79d4a2c1166385ce7",
"body": null,
"is_bot": false,
"headline": "ci: remove dependabot (superseded by nox-remediate)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-03T12:19:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0249ed92b2dacf62ee3ca6e400f666188ed3abcd",
"body": null,
"is_bot": false,
"headline": "ci: remove dependabot (superseded by nox-remediate)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-03T12:19:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "05f84b7d990cd99b7c77b65cc9aed48d67893a75",
"body": null,
"is_bot": false,
"headline": "ci: nox-remediate (replaces dependabot)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-03T12:19:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2415494a31f7065eae545611285fc953f49b50b6",
"body": "Local gate config (pre-commit/pre-push: lint + race tests, parallel) plus an\ninformational warden-verify PR check. Aligns with the klarlabs-studio convention.",
"is_bot": false,
"headline": "chore: adopt warden — .warden.yaml + provenance-skip CI",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-03T08:56:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4f1d66c9de9c8297ecc247b56edb53425cd4505a",
"body": "- go.klarlabs.de/fortify v1.6.0 → v1.8.1\n- go get -u ./...: redis/go-redis, grpc, genproto and transitive graph\nBuild + tests green.",
"is_bot": false,
"headline": "chore(deps): update dependencies to latest",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-03T07:34:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "688f5d602b831d84e65710f1483dd13501da41c0",
"body": "The HTTP client transport now interoperates with streamable-HTTP MCP servers\n(e.g. GitHub's api.githubcopilot.com/mcp), not just plain JSON-over-HTTP:\n\n- Advertise Accept: \"application/json, text/event-stream\" so a server may\n reply with either a single JSON object or an SSE stream.\n- Parse SSE res\n[…]\nequests.\n\nPlain JSON-over-HTTP responses keep working (back-compat test added). Also\nextracts a jsonrpcVersion const (goconst).\n\nClaude-Session: https://claude.ai/code/session_01V4xnsDxEEPFRaYvL2AGmpP",
"is_bot": false,
"headline": "feat(client): streamable-HTTP support (MCP 2025-03-26)",
"author_name": "Felix Geelhaar",
"author_login": null,
"committed_at": "2026-06-23T10:24:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5af5f40970127f22a06167d23cbe196de63d013b",
"body": "spec compliance: remove in-lib auth, shared transport, fallback-framer race fix",
"is_bot": false,
"headline": "Merge pull request #113 from klarlabs-studio/feat/spec-compliance",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T20:40:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6f5dea2b8bd929e7ff5da21568a25e0a9318571f",
"body": "…-of-Serve writes\n\ncurrentFramer() previously constructed a fresh NewNewlineFramer (with a fresh\nwrite mutex) on every call when s.framer == nil — i.e. for SendNotification and\nwriteResponse fired before Serve starts or after it returns. Two concurrent\nout-of-Serve writers then locked different mute\n[…]\ndynamic escape-hatch interface and the metadata\nstruct is client.ToolInfo, so t.Name on a client.Tool value no longer compiles.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "fix(transport): reuse a single fallback stdio framer to serialize out…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T20:06:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "43cd81eed2e81e6faeb9d25e8f171f281771c178",
"body": "The client previously shipped its own stdio and SSE framers,\nindependent of the transport/ package. Per the non-negotiable\n\"client and server share transport implementations, no duplication\",\nextract the framing primitives into transport/ and use them on both\nsides:\n\n- Add transport.NewlineFramer: n\n[…]\ndata: \" framing.\n\nThe end-to-end resource-subscription push test exercises the unified\nserver-writer -> client-reader SSE path.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "refactor: unify client/server transport framing",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T19:50:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e3c58f02b0a29816b082feacfab1b8547cb6fc95",
"body": "mcp-go never handles auth — tokens, OAuth flows, and credentials live\nentirely in the caller-supplied http.Client transport (client) or at\nthe transport/proxy layer (server). Per the non-negotiable, all\nin-library auth is removed:\n\n- Delete middleware/auth.go and all its symbols (Auth, Authenticator\n[…]\nth must be terminated at the\ntransport/proxy layer or in caller-provided middleware. See CHANGELOG\nfor the full migration note.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "refactor!: remove in-library auth (callers inject http.Client)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T19:45:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e4857c516812ed184bfdd873408f1757ae67eef3",
"body": "Add the spec's top-level CLIENT API so callers use the mcp package\ndirectly without reaching into the client sub-package:\n\n- mcp.NewClient(url, mcp.WithHTTPClient(...)) and mcp.NewStdioClient\n- mcp.Call[In,Out] and mcp.NewClientTool[In,Out] (typed, primary path)\n- mcp.Client / mcp.ToolInfo / mcp.Too\n[…]\nhatch (not recommended)\n\nWithHTTPClient is the only auth hook — auth is injected via the\ncaller-supplied http.Client transport.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "feat(client): top-level mcp.NewClient/Call surface",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T19:38:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b31a9278dcc7e2dc7f6e6516a6517e77a44f1775",
"body": "The spec's dynamic escape hatch is an interface named Tool (Name +\nCall(ctx, RawMessage)->RawMessage). A client.Tool struct already\nexisted, so:\n\n- Rename the struct Tool -> ToolInfo (returned by ListTools).\n- Rename the interface DynamicTool -> Tool; keep DynamicTool as a\n deprecated type alias.\n-\n[…]\ndelegates.\n- Add NewClientTool as an alias of NewTypedTool.\n\nTyped Call / NewTypedTool / NewClientTool remain the primary path.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "refactor(client): resolve Tool naming, add CallRaw/NewClientTool",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T19:35:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a605f82d717714ad7a8ec3d1eb5b51af5ef1c38c",
"body": "Add (*Server).ListTools() as an alias of Tools() to match the spec's\nintrospection naming (ListTools/GetTool). Since mcp.Server is a type\nalias, the method is available at the top level too.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "feat(server): add ListTools introspection alias",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T19:33:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "798bcfa57668f0e7ae16efa9e56e08ca532ebfa3",
"body": "JSON Schema constraint validation (required/min/max/enum) now runs\nbefore every tool handler, so invalid-per-schema input is rejected\nwith InvalidParams and never reaches business logic — satisfying the\n\"invalid input never reaches business logic\" non-negotiable.\n\n- Flip the gate from opt-in validat\n[…]\n ValidateInput() becomes a no-op compatibility alias (deprecated);\n existing calls keep compiling and keep validation enabled.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "feat(server): validate tool input against schema by default",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T19:32:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d3a0d158e7ca411f582352fdb55d3912ee411f01",
"body": "ci: bump nox pin 0.10.0 -> 1.2.0 (fix plugin verification)",
"is_bot": false,
"headline": "Merge pull request #112 from klarlabs-studio/fix/nox-pin-cosign-verify",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T13:37:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ae986151a1782a257f6432f86cbd3d1643267e41",
"body": "The 0.10.0 pin predates nox's deriveChecksumsURL fix (first in v1.1.2).\nWith 0.10.0, `nox plugin install nox/taint-analysis` resolves the latest\nplugin (v0.6.6) whose cosign bundle is named \"checksums.txt.sigstore.json\".\nnox 0.10.0 only stripped \".sig.bundle\", so it downloaded the bundle and\nhanded \n[…]\n CI. Bumping to 1.2.0 (>= 1.1.2) picks\nup the deriveChecksumsURL fix that strips \".sigstore.json\". No trust\npolicy was lowered.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "ci: bump pinned nox to 1.2.0 to fix cosign plugin-verify failure",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T13:25:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "58cc8a0897fd79c5bb566f5ee662a7714d83bb9f",
"body": "feat(client): typed call API + correctness hardening",
"is_bot": false,
"headline": "Merge pull request #111 from klarlabs-studio/feat/typed-client-api",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T12:56:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cd70a945afaf89b332eb128040aaad0278ddcdbb",
"body": "…e-encoding\n\ndynamicTool.Call unmarshaled its json.RawMessage argument into\nmap[string]any and handed that to CallTool, which re-marshaled it. The\nround-trip through map[string]any silently lost int64 precision (JSON\nnumbers decode to float64, so values above 2^53 were rounded) and object\nfield orde\n[…]\n as float64) reaches the transport intact and that\nfield ordering survives, by inspecting the captured outgoing request\nparams.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "fix(client): pass raw JSON through dynamic tool calls without lossy r…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T12:41:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e8b4019fbcb13f55cba305cd84d08584767fa100",
"body": "Call now adds its own \"typed call tool\" error frame on the CallTool\nfailure path (using %w so *protocol.Error stays inspectable), matching the\ndecode path which already wrapped. The Out=string branch carries a godoc\nwarning that a JSON-encoded string block is returned raw (quotes included)\nrather th\n[…]\nt\nasserts a cancelled context surfaces through to the transport. The mock\ntransport now records and honors the request context.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "fix(client): frame CallTool errors and harden typed-call tests",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T12:37:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "139b6ff4ab7035c7ad8c1f56cfc0bfae013f3a87",
"body": "The critic suggested ClientTool -> Tool, but client.Tool already exists as\na struct, so that would collide. Renamed ClientTool[In,Out] -> TypedTool\nand NewClientTool -> NewTypedTool instead: no stutter, no collision, and a\nclearer name for the reusable typed handle.\n\nUpdated the typed-client example, examples README, and tests.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "refactor(client): rename ClientTool to TypedTool",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T12:34:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b27e665f18c40af0fb141ba5b499e39f1d15810c",
"body": "Call and dynamicTool.Call took Content[0] unconditionally, so an\nimage-first or otherwise non-text-first result fed an empty/garbage string\ninto json.Unmarshal. They now scan for the first block whose type is\n\"text\" via firstTextContent.\n\nWhen no text block exists and there is no structuredContent, \n[…]\nmage-first selection, multi-content first-text selection,\nand the non-text no-content error path for both Call and DynamicTool.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "fix(client): select first text content block",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T12:33:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f9d85d378d9d2a5860a7a62d8c983118a304c1a8",
"body": "Typed output was decoded from the display Content[0].Text, ignoring the\ncanonical structuredContent channel the server emits for typed handlers.\n\nToolResult now carries StructuredContent (parsed from the tools/call\nresponse in CallTool), and Call unmarshals that into Out when present,\nfalling back t\n[…]\n returning ErrNoContent.\n\nAdds table-driven tests for structuredContent-only and\nstructuredContent-preferred-over-display-text.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "fix(client): prefer structuredContent in typed Call",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T12:31:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b2822e7a9ba6910c50eb1ad80d14cad62535780c",
"body": "Call and dynamicTool.Call previously decoded an isError:true tool result\nas a successful Out, silently masking server-side tool failures. They now\ninspect ToolResult.IsError and return the zero value plus an error wrapping\nthe new exported sentinel ErrToolError, carrying the first text content\nblock as the error detail.\n\nAdds the isError path to both the typed Call and DynamicTool test suites\n(previously zero coverage).\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "fix(client): surface tool isError as an error",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T12:30:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ff60dc7bae80caaeb2137d3fcfb42f2d797f057b",
"body": "Demonstrate the typed client API against an in-process HTTP MCP server:\nclient.Call for one-shot calls, NewClientTool for a reusable handle, and\nNewDynamicTool for the raw-JSON escape hatch. Wire it into the examples\nREADME alongside the other runnable examples.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "docs(examples): add runnable typed-client example",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T11:57:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "34a76d4178fc3b2227248dd9576cf56594ba3425",
"body": "Add the typed primary client API on top of the existing untyped CallTool:\n\n- Call[In, Out](ctx, c, name, in): marshals the typed input to tool\n arguments, invokes CallTool, and decodes the first content block into\n Out. A string Out receives the raw text; otherwise it is JSON-decoded,\n mirroring \n[…]\nhaling, reusable handle reuse, and the raw escape hatch. typed.go is\n100% covered; the client domain rises to 85.3% (gate 80%).\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "feat(client): add typed tool call API (Call, NewClientTool, DynamicTool)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T11:56:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1b8c83f0053c9e51e5ce53de61f5d6e20e713548",
"body": "bufio.Scanner defaults to a 64KB max token, so a single JSON-RPC line larger\nthan that (e.g. a browser-automation annotated_screenshot response, ~66KB+) is\nrejected with ErrTooLong and the message is never delivered — the call stalls\nuntil the caller's context deadline. Raise the read buffer to 16MB on both the\nclient stdout reader and the server stdin reader (the HTTP+SSE notification\nreader already does this).",
"is_bot": false,
"headline": "fix(stdio): raise scanner buffer above 64KB default",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-13T20:48:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "84f84acc650fdac2f6ad430e8e47e767086c6c9f",
"body": "The client can now receive server-initiated resource-updated notifications,\ncompleting the subscription round-trip added server-side in v1.16.0:\n\n- HTTPTransport mints a clientId, echoes it on every POST, and exposes\n Stream(ctx, handler): it opens the /mcp/sse channel and dispatches inbound\n JSON\n[…]\ndated to them\n (ErrNotificationsUnsupported for non-streaming transports).\n\nEnd-to-end test: a real HTTP server pushes NotifyResourceUpdated and the\nclient's OnResourceUpdated handler fires over SSE.",
"is_bot": false,
"headline": "feat(client): resource subscriptions over HTTP+SSE (#110)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-08T22:03:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "70f13faa5c9f6c02dfd2d759c8d754bb96d7145e",
"body": "ci(security): enable nox taint-analysis SAST",
"is_bot": false,
"headline": "Merge pull request #109 from klarlabs-studio/ci/enable-taint-sast",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-08T21:10:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f89d13d8fbb54ab554ec460e64c4ebd014c892c6",
"body": "Declares nox/taint-analysis in plugins.required so nox scan runs\nsource-to-sink taint analysis (SSRF, injection, path traversal) and\nmerges findings into the security gate. Step toward nox owning all\ncode-level security (then gosec is dropped).",
"is_bot": false,
"headline": "ci(security): enable nox taint-analysis SAST",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-08T21:03:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7ccbea42a2a094fb6468aa490ecae3048e819b7e",
"body": "Wire the existing per-session subscription primitives into the high-level\nserver so clients can subscribe to a resource URI and receive\nnotifications/resources/updated when it changes:\n\n- Capabilities.ResourceSubscribe advertises resources.subscribe in the\n initialize response.\n- resources/subscrib\n[…]\ntions. ServeHTTP wires both automatically when the\n capability is enabled.\n\nTargeted delivery, per-client error isolation, and lifecycle cleanup are\ncovered by unit + handler-level integration tests.",
"is_bot": false,
"headline": "feat(server): resource subscriptions (resources/subscribe + push) (#108)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-08T20:51:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ee7962efd0fde509df5bafb6bc6a5b804a51ea1e",
"body": "ci: adopt shared reusable Go CI workflow",
"is_bot": false,
"headline": "Merge pull request #106 from klarlabs-studio/ci/adopt-shared-workflow",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-08T11:10:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "240eb8425e3223e16fc96aaf6fdd1e1a72a54646",
"body": "Extend the documentation excludes to the remaining paths that produce\nonly secret-scanner false positives, mirroring the upstream nox project's\nown .nox.yaml convention:\n- *_test.go: long CamelCase test identifiers match the Split API Key\n regex (consistent with the gosec _test.go exclusion in .gol\n[…]\nile, whose stored fingerprints\n and dependency hashes are high-entropy by design.\n\nNo security rules are disabled; application source, config, and\ndependency manifests remain fully scanned and gated.",
"is_bot": false,
"headline": "ci: broaden nox scan-scope exclusions to false-positive paths",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-08T11:05:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "02a5f26ef74f80be8207c5e1ff58455bcb4812cb",
"body": "nox's secret-detection regexes match Go code examples in README.md\n(struct field names, example tool names) as API keys (Braintree,\nSendGrid, Datadog, Grafana, etc.) — false positives. Add a .nox.yaml\nthat excludes documentation files from scanning, mirroring the upstream\nnox project's own .nox.yaml convention. Source, IaC, workflows, and\ndependencies remain fully scanned and gated by the shared CI workflow.",
"is_bot": false,
"headline": "ci: exclude documentation from nox secret scanning",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-08T10:56:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eab3238531e2682d623e9fa87e1aacff0fbf9ff2",
"body": "The shared workflow's default nox (0.8.1) is older than the version this\nrepo's reviewed .nox/baseline.json was generated with (0.10.0, per the\nprior CI). 0.8.1's secret scanner produces false positives on Go struct\nfields, long test-function names, and the baseline file itself, none of\nwhich are re\n[…]\nusing the credentials persisted by actions/checkout instead\nof embedding GITHUB_TOKEN in the remote URL, so the nox secret scanner\nstays clean (the old inline pattern was a baselined SEC-085 finding).",
"is_bot": false,
"headline": "ci: pin nox to repo baseline version and harden badge push",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-08T10:50:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "922e33ea9e455e92031799dac3e399b2b357903d",
"body": "Replace the bespoke ci.yml with a thin caller of the org-shared\nreusable workflow (klarlabs-studio/.github go-ci.yml@main):\n\n- ci.yml is now a thin caller (coverage: true, cross-platform: false).\n Repo ships .coverctl.yaml with per-domain thresholds, so the\n coverctl coverage gate is enabled; the \n[…]\no-specific opt-ins, settings,\n and exclusions (incl. gosec test exclusion).\n\nrelease.yml, pages.yml, dependabot-auto-merge.yml untouched.\ngolangci-lint v2.7.2 clean (0 issues); coverctl check passes.",
"is_bot": false,
"headline": "ci: adopt shared reusable Go CI workflow",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-08T10:37:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "37858c67f543270872d1bd75c9e501244e7543b7",
"body": null,
"is_bot": false,
"headline": "ci: install coverctl from go.klarlabs.de vanity path",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-07T18:22:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d0803f86bf114ff967666c759bb30248aedbb664",
"body": "36x SEC-616 (FCM-key regex matching go.sum base64 checksums from the\ngo.klarlabs.de dependency churn) and 1x DATA-001 (intentional\nsecurity@klarlabs.de contact in SECURITY.md).",
"is_bot": false,
"headline": "chore: baseline nox false positives after module path migration",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-07T18:21:09Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 38,
"commits_last_year": 213,
"latest_release_at": "2026-07-11T11:02:38Z",
"latest_release_tag": "v1.24.0",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 18,
"days_since_latest_release": 14,
"mean_days_between_releases": 3.6
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 75,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "go.klarlabs.de/mcp",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": null,
"registry_url": "https://pkg.go.dev/go.klarlabs.de/mcp",
"is_deprecated": false,
"latest_version": "v1.24.0",
"repository_url": null,
"versions_count": 38,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-11T11:01:24Z",
"latest_version_yanked": null,
"days_since_latest_publish": 14
}
]
},
"popularity": {
"forks": 0,
"stars": 2,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": null,
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile"
],
"api_schema_files": [
"transport/grpc/mcp.proto"
],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"go.mod"
],
"largest_source_bytes": 63600,
"source_files_sampled": 168,
"oversized_source_files": 1,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 14404
},
"dependencies": {
"manifests": [
"go.mod",
"website/package.json"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go",
"npm"
],
"dependencies": [
{
"name": "github.com/alicebob/miniredis/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.38.0"
},
{
"name": "github.com/gorilla/websocket",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.5.3"
},
{
"name": "github.com/redis/go-redis/v9",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v9.21.0"
},
{
"name": "go.klarlabs.de/fortify",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.8.1"
},
{
"name": "go.opentelemetry.io/otel",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/metric",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/sdk",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/sdk/metric",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/trace",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "google.golang.org/grpc",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.82.1"
},
{
"name": "google.golang.org/protobuf",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.36.11"
},
{
"name": "astro",
"manifest": "website/package.json",
"ecosystem": "npm",
"version_constraint": "^6.3.1"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 76,
"open_issues": 0,
"closed_ratio": 1,
"closed_issues": 18,
"closed_unmerged_prs": 42
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "felixgeelhaar",
"commits": 189,
"avatar_url": "https://avatars.githubusercontent.com/u/6020564?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"badge.yml",
"ci.yml",
"nox-remediate.yml",
"pages.yml",
"provenance.yml",
"release.yml"
],
"has_docs_dir": true,
"linter_configs": [
".golangci.yml"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": null,
"reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 8,
"reason": "11 out of 13 merged PRs checked by a CI test -- score normalized to 8",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/13 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 3,
"reason": "project has 1 contributing companies or organizations -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 5,
"reason": "dependency not pinned by hash detected -- score normalized to 5",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "45223e3fe3c460b0a78b211139a9c675ff6c2ebb",
"ran_at": "2026-07-26T03:23:57Z",
"aggregate_score": 6.2,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-25T19:55:47Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-25T19:53:49Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/klarlabs-studio/mcp-go",
"host": "github.com",
"name": "mcp-go",
"owner": "klarlabs-studio"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 65,
"inputs": {
"security": 62,
"vitality": 86,
"community": 36,
"governance": 53,
"engineering": 84
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 86,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 76,
"inputs": {
"commits_last_year": 213,
"human_commit_share": 1,
"days_since_last_push": 0,
"active_weeks_last_year": 18
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "18/52 weeks with commits",
"points": 12.5,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 18
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "213 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 213
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 38,
"latest_release_tag": "v1.24.0",
"releases_from_tags": false,
"days_since_latest_release": 14,
"mean_days_between_releases": 3.6
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "38 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 38
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 14 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 14
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~3.6 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 3.6
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 0,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 0 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 0
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 36,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 2,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "2 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 2
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "good",
"name": "Community health",
"note": null,
"notes": [],
"value": 77,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 53,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 13,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 71,
"inputs": {
"merged_prs": 76,
"open_issues": 0,
"closed_issues": 18,
"issue_closed_ratio": 1,
"closed_unmerged_prs": 42
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "100% of issues closed",
"points": 46.8,
"status": "met",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 100
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "76/118 decided PRs merged",
"points": 24.6,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 76,
"decided": 118
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/13 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 44,
"inputs": {
"followers": 1,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "klarlabs-studio",
"public_repos": 32,
"account_age_days": 49
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "1 followers of klarlabs-studio",
"points": 2.2,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 1,
"login": "klarlabs-studio"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "32 public repos, account ~0 yr old",
"points": 11.3,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 32
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"go.klarlabs.de/mcp"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 14
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 14 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 14
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "38 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 38
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 84,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 80,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "6 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 6
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".golangci.yml",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "11 out of 13 merged PRs checked by a CI test -- score normalized to 8",
"points": 16,
"status": "partial",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": "https://klarlabs-studio.github.io/mcp-go/",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://klarlabs-studio.github.io/mcp-go/",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 62,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Branch-Protection, Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"branch_protection",
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 62,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 15,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 3,
"scorecard_aggregate": 6.2
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "11 out of 13 merged PRs checked by a CI test -- score normalized to 8",
"points": 2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/13 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 5",
"points": 2.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 2
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 83,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 14404
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 100,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 77,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [
"Makefile"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [
"go.mod"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".golangci.yml",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 5",
"points": 5,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 63600,
"source_files_sampled": 168,
"oversized_source_files": 1
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "1/168 source files over 60KB",
"points": 54.7,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 168,
"oversized": 1
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "good",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 80,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": false,
"api_schema_files": [
"transport/grpc/mcp.proto"
]
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": "transport/grpc/mcp.proto",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "transport/grpc/mcp.proto"
}
}
],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"Could not fetch npm package 'mcp-go-website' from its registry",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-26T03:24:11.146609Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/k/klarlabs-studio/mcp-go.svg",
"full_name": "klarlabs-studio/mcp-go",
"license_state": "standard",
"license_spdx": "MIT"
}