This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+5 more
Affected surfaces
Summary
AI summaryFixed-point SVG comment removal now correctly propagates to npm packages.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Enforces benchmark validators to match instructions literally, including sentence counts and structure requirements. Enforces benchmark validators to match instructions literally, including sentence counts and structure requirements. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Medium |
Corrects preflight message to accurately reflect unresolved CSS variable WARN status. Corrects preflight message to accurately reflect unresolved CSS variable WARN status. Source: llm_adapter@2026-07-18 Confidence: low |
— |
| Bugfix | Medium |
Fixes interleaved SVG comment fragments that could reassemble into a live `<!--` after sanitization. Fixes interleaved SVG comment fragments that could reassemble into a live `<!--` after sanitization. Source: llm_adapter@2026-07-18 Confidence: low |
— |
| Bugfix | Low |
Updates preflight warning message to correctly indicate unresolved CSS variables instead of claiming all checks pass. Updates preflight warning message to correctly indicate unresolved CSS variables instead of claiming all checks pass. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
Full changelog
Release-boundary closure: v0.14.2 was tagged before the final CodeQL fix merged, so npm consumers lacked it. This release ships everything to installed packages.
- Fixed-point SVG comment removal reaches npm — interleaved comment fragments cannot reassemble into a live
<!--after sanitization (closes the last CodeQL alert for consumers, not just the repo) - Preflight message matches its verdict — a WARN from unresolved CSS variables no longer claims "All checks pass"; it says what to define before the content can be verified
- Benchmark validators enforce instructions literally — blog exactly-3-sentences, CTA headline + button + style block (
must_matcharrays,min_sentences)
With this release: zero open CodeQL alerts, zero Dependabot alerts, zero npm advisories — true for the artifact users install, not merely for main.
Full changelog: https://github.com/Brandcode-Studio/brandsystem-mcp/blob/main/CHANGELOG.md
Security Fixes
- Prevents reassembly of interleaved SVG comment fragments that could lead to malicious payload injection.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Brand-System/brandsystem-mcp
Make your brand machine-readable. Extract brand identity (colors, fonts, logo, voice, visual rules) from any website via static CSS + rendered-page extraction, compile into DTCG tokens, brand runtime contracts, and interaction policies. 34 tools across 4 progressive sessions. Subscribable `brand://runtime` and `brand://policy` MCP resources. Content compliance scoring (0-100), pass/fail gate, and HTML/CSS preflight. Brandcode Studio connector for hosted brand sync.
Related context
Beta — feedback welcome: [email protected]