This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
Affected surfaces
Summary
AI summaryAdded opt‑in inline image preview and spend confirmation UX layers.
Full changelog
Lands #21 (thanks @KillerQueen-Z!) — re-integrated on top of the 0.24.x charge path. Two opt-in blockrun_image UX layers, both default to prior behavior:
- Inline preview —
inlineparam (orBLOCKRUN_INLINE_IMAGES=1) returns a downscaled JPEG thumbnail as atype:"image"block alongside the full-res URL, so rich clients render it in-conversation. Best-effort with source download/decode caps; tunable viaBLOCKRUN_INLINE_MAX_DIM/_QUALITY/_MAX_BYTES. - Spend confirmation — MCP elicitation before charging, with an "approve all this session" checkbox. Off by default (
BLOCKRUN_CONFIRM_SPEND=on); fails open (only an explicit decline aborts, releasing the reservation and charging nothing; auto-approve latches only on an explicit accept).
Re-integrated so the 0.24.x SSRF guard, Content-Length cap, and concurrency-safe reserveBudget reservation all stay intact — the confirmation runs once inside the reserve→record→release flow. 84 unit tests. Full details in CHANGELOG.md.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About blockrunai/blockrun-mcp
Live data for AI agents — search, research, markets, crypto, X/Twitter. Pay-per-call via x402 micropayments.
Related context
Beta — feedback welcome: [email protected]