Skip to content

This release adds 1 notable feature for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

agentskills ai-agents ai-tooling claude claude-code code-intelligence
+13 more
code-quality coding-agent developer-tools go language-server-protocol lsp mcp mcp-server model-context-protocol python rust static-analysis typescript

Affected surfaces

auth deps

Summary

AI summary

Add Windows install support via PowerShell, Scoop, and Winget.

Full changelog

Changelog

  • a857510d693f828b247855cce1b6af9e8c09b2f3 Merge saw/doctor-linescope/wave1-agent-A: ## Context Repository: /Users/dayna.blackwell/code
  • 881e2badc4ab8b0f17e4b7d6429b03298cac2808 Merge saw/doctor-linescope/wave1-agent-B: ## Context Repository: /Users/dayna.blackwell/code
  • b832d7a82b3fa9e5da6cf94f077bd9b12162afe0 Merge saw/five-new-skills/wave1-agent-A: ## Agent A — lsp-fix-all skill
  • dab28a42d72de08c1c2e8385c4ca94b3f1cd47d1 Merge saw/five-new-skills/wave1-agent-B: ## Agent B — lsp-refactor skill
  • 4ae510eb06016a92f4e00fd99388b38e876d8ecb Merge saw/five-new-skills/wave1-agent-C: ## Agent C — lsp-extract-function skill
  • cd799487c4050c550bd0c1f585ad16350e358951 Merge saw/five-new-skills/wave1-agent-D: ## Agent D — lsp-generate skill
  • 77d128334c85d4980fa28a6715e7827099ef8db8 Merge saw/five-new-skills/wave1-agent-E: ## Agent E — lsp-understand skill
  • b44e49346af9560efc44e26ebbd6459dd5b5fbba Merge saw/five-new-skills/wave2-agent-F: ## Agent F — Documentation update
  • f56d33716e44e43e8153937125fb026e5521ce3b Merge saw/http-transport-docker-security/wave1-agent-A: ## Role Go CLI transport routing — extend main.g
  • 6bc18a6a60ab53458f2876a70334bd1f90e8c2ca Merge saw/http-transport-docker-security/wave1-agent-B: ## Role Bearer token HTTP middleware — create in
  • 306d1baec228291bdd3b51dda3b694e530f730bc Merge saw/http-transport-docker-security/wave1-agent-C: ## Role Dockerfile hardening — add non-root user
  • 3e600fcb2bbf3700afe921422d8e3069c254ca65 Merge saw/http-transport-docker-security/wave1-agent-D: ## Role Entrypoint hardening — replace the unsaf
  • 49b91e893aa50c2ba27c0e1ce055d51325e937d0 Merge saw/http-transport-docker-security/wave1-agent-E: ## Role docker-compose.yml update — add HTTP mod
  • b7e85880b47fd74f04ec79f6dc19e65ffce60f00 Merge saw/lsp-explore-rename-globs/wave1-agent-A: ## Context Repository: /Users/dayna.blackwell/work
  • a78d1905175d911855f788648d4dfd9bf3341f78 Merge saw/lsp-explore-rename-globs/wave1-agent-B: ## Context Repository: /Users/dayna.blackwell/work
  • fcdd1fcf006fca197a4d504c42e2b00a247627c9 Merge saw/lsp-explore-rename-globs/wave1-agent-C: ## Context Repository: /Users/dayna.blackwell/work
  • d700d6426457af4c57b113d6399dd3f62c624283 add exclude_globs to rename_symbol: filter helper, wiring, tests
  • 34dc12a791d9aa5c6764bb83850170ea37f324c1 add lsp-explore skill (SKILL.md and references/patterns.md)
  • 2bf5fbcc82cbf56d5f1a66ac0547bb489212e95c assets: resize wordmark for GitHub social preview
  • 4a3699f65962c2eec19ab8621f1a2d3f43fcdb1e docker: harden Dockerfile with non-root user and EXPOSE 8080
  • 7ff44ba79369c06112100f9f85bf82cc24234f0e docs(impl): mark httpauth scaffold as committed (05d1f73)
  • dc84a2efceaeb4629d2675848e23f2fd85a2e1e7 docs(skills): fix two inaccuracies in skills.md
  • 27357e0fce066865571c2b94e2d8892af1bced7b feat(distribution): add Windows install story — PowerShell, Scoop, Winget
  • 2546ee69090042acabd5f6d25555bab3daee7077 feat(docker): add agent-lsp-http service for HTTP+SSE transport mode
  • 0ec02d1ae30513cc1a0c34ec94e718db86547ab0 feat(linescope): add ResolvePositionPatternInRange and line scope support
  • 996648e5f5572a11016bc9c7fb4db8d61b46dc77 feat: add /health endpoint; fix changelog; mark HTTP transport shipped
  • ea66b5f4126abb8550af858d2b77abb4d805c79f feat: add HTTP transport support to CLI (--http, --port, --token flags)
  • 4cecdfeb0787dfa26aa413d420376e30364cc332 feat: add agent-lsp doctor subcommand
  • e7c0f4ca6a512a692ad1ec388fbc53c835161a01 feat: add lsp-understand skill for deep-dive module exploration
  • dee557fd76dbda5b80d49fd1d32b7e96387c8ac5 feat: update install.sh to maintain agent-lsp skills block in CLAUDE.md
  • 023ea892a4d526288453a4cd464d18371d57c633 fix(docker): switch to root for package install in Dockerfile.combo and Dockerfile.full
  • 8eb0b595abffb9c18dd85cba9a3ffd3dd5fbc060 fix(docker): switch to root for package install in Dockerfile.lang — base image inherits USER nonroot
  • c7b784782ec7afc964bd80bd43204ba7d39dc5a7 fix(docker): use Dockerfile.release for GoReleaser — copies pre-built binary instead of compiling from source
  • baa067f2829577f225c521f7c7ed7d4005303f18 fix(release): use winget-releaser action + HOMEBREW_TAP_TOKEN instead of GoReleaser winget publisher
  • 46623b7fb06b815d4fc35dd837cecad9e79e8b78 fix(skills): correct BSD awk newline bug in install.sh CLAUDE.md update
  • 9107fd28a33d65dc15685bd0ff2ad7bf13f1a054 fix(skills): remove leaked SAW agent constraint from lsp-generate
  • eb4730ebe8508df84c9478bedadbe7326d568249 fix: address inspector findings in HTTP transport and Docker hardening
  • 2d4cebd644e6c8d8db5406be19b2f62d00f7037f fix: address second-pass security inspector findings
  • 803cd545baa14a43c3714a88be57f6f2d9aafb3c fix: update paths after moving docker files to docker/ directory
  • d3c7f02a4c8cf24beca82c781018decc6081ff69 implement httpauth.BearerTokenMiddleware with timing-safe token validation
  • fe87949d22a214d8d6100929eb855c73b4db5744 implement lsp-extract-function skill with LSP primary path and manual fallback
  • cb5cdc046258a2e2a37630f266157abcf52c34ec implement lsp-fix-all skill: bulk quick-fix code actions with per-fix re-collection
  • a06ace1ecc8e7964bbf4e88be4bc459e06400cae implement lsp-generate skill with SKILL.md and patterns reference
  • 276e43b77963bc8d5b495b74e9e53300cea1a403 implement lsp-refactor skill with 5-phase end-to-end refactor workflow
  • 5e3d35e70fe292aa4dac170ffd533799029644b5 license: add MIT LICENSE file
  • dddfbf57908cb8682d621e5418bbb613a6c8c474 saw: fix IMPL-five-new-skills validation
  • 2013c24f2361e1476529d086a923a596b87ec62d saw: fix IMPL-five-new-skills validation wave 2
  • 7a3014a107d010b2f0f606ff0b97e7bc967703b2 saw: fix V013 unknown key in IMPL-doctor-linescope
  • 05d1f731d45608a6e09dd63078c2b6ddeba7899a scaffold: add BearerTokenMiddleware stub for http-transport-docker-security
  • 6e3b61bc07af41ef722cff693e1e0317f2b608f7 security: replace eval with whitelist dispatcher in entrypoint.sh
  • ea2e31f03d3d14fc5040fc22e117846a5b2c374c security: third-pass hardening for HTTP transport and Docker
  • 377416f89b51c3b7f92295bc9e304ec5f46a98dc update README, ROADMAP, CHANGELOG for lsp-explore and rename-globs

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track blackwell-systems/agent-lsp

Get notified when new releases ship.

Sign up free

About blackwell-systems/agent-lsp

Stateful MCP server over real language servers. 50 tools, 30 CI-verified languages, 20 agent workflows. Persistent sessions keep the index warm across files and projects. Speculative execution simulates edits in memory before writing to disk.

All releases →

Related context

Earlier breaking changes

  • v0.11.0 `get_change_impact` renamed to `blast_radius`. Same handler, same parameters, new name.

Beta — feedback welcome: [email protected]