This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Affected surfaces
Summary
AI summaryWrite permission probing distinguishes read‑only from read+write tokens in probe_token_capabilities.
Full changelog
What's New
Write permission probing in probe_token_capabilities — distinguishes read-only tokens from read+write tokens.
Added
- Probes
rollanddetachendpoints using real cluster IDs with fake instance IDs (safe dry-run) - Detects Spot.io's non-standard permission denials (400 "An unknown error occurred" instead of 403)
- Response now includes
read_access,write_access,write_deniedfields - Recommendation summary: "full read + write", "read-only", or "partial write"
- 4 new probe tests (82 total)
Changed
- CI workflows bumped to
actions/checkout@v6andactions/setup-python@v6(Node.js 24)
Full Changelog: https://github.com/arnstarn/mcp-server-spotinst/compare/v0.4.1...v0.5.0
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About arnstarn/mcp-server-spotinst
MCP server for Spot.io (Spotinst) API with 23 tools for managing Ocean clusters, VNGs, Elastigroups, costs, right-sizing, and logs across AWS and Azure with multi-account support.
Related context
Beta — feedback welcome: [email protected]