Skip to content

delimit-ai/delimit

v4.16.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 12d MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-governance api-governance breaking-changes claude-code codex cross-model
+8 more
cursor deliberation devtools gemini-cli mcp mcp-server model-context-protocol openapi

Affected surfaces

auth breaking_upgrade

ReleasePort's take

Moderate signal
editorial:auto 12d

Bundle parity guard added to prevent proprietary source leaks; npm package description updated.

Why it matters: Security: Invert npm bundle to fail-CLOSED allowlist (LED-1879) mitigates proprietary leakage risk. Release v4.16.0 published 2026‑07‑14.

Summary

AI summary

Bundle parity guard, chat pre‑brief launch and per‑launch model selector added; npm package description updated.

Changes in this release

Security Critical

Invert npm bundle to fail-CLOSED allowlist (LED-1879)

Invert npm bundle to fail-CLOSED allowlist (LED-1879)

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Add `delimit chat --model <id>` per‑launch model selector

Add `delimit chat --model <id>` per‑launch model selector

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Launch pre‑brief and rename honest launcher (Fable doc-33)

Launch pre‑brief and rename honest launcher (Fable doc-33)

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Fix cross‑namespace handoff receipts in bundled MCP (LED-2451)

Fix cross‑namespace handoff receipts in bundled MCP (LED-2451)

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Prevent proprietary gateway source from being committed to the public repo (LED-1900)

Prevent proprietary gateway source from being committed to the public repo (LED-1900)

Source: llm_adapter@2026-07-15

Confidence: low

Bugfix Low

Sync‑gateway exclude parity and add parity guard for proprietary‑leak prevention

Sync‑gateway exclude parity and add parity guard for proprietary‑leak prevention

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Low

Correct truth‑drift issues in docs (banned phrase, phantom CHANGELOG, VERSION marker)

Correct truth‑drift issues in docs (banned phrase, phantom CHANGELOG, VERSION marker)

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Low

Fix VERSION marker ordering to unblock v4.16.0 publish

Fix VERSION marker ordering to unblock v4.16.0 publish

Source: llm_adapter@2026-07-15

Confidence: high

Full changelog

What's Changed

  • docs(npm): on-promise package description (LED-3700, STR-2195) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/150
  • feat(hooks): STR-2202 "tools fire tools" — HOOK half (SessionStart digest echo + subagent flight-recorder) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/151
  • fix(bundle): sync-gateway exclude parity + parity guard (proprietary-leak prevention) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/153
  • ci: fail-closed identity-guard (block non-anonymized commit identities) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/154
  • Glama coherence: DELIMIT_TOOLSET=core Docker pin + server.json version-sync by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/152
  • feat(chat): launch pre-brief + honest launcher naming (Fable doc-33) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/155
  • feat(chat): add delimit chat --model <id> per-launch model selector by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/156
  • Fix cross-namespace handoff receipts in bundled MCP (LED-2451) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/157
  • security(bundle): invert npm bundle to fail-CLOSED allowlist (LED-1879) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/158
  • chore(bundle): classify brand_notes.py INTERNAL (guard catch #1) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/159
  • chore(bundle): resync gateway bundle (memory projection budget fix) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/160
  • fix(docs): truth-drift corrections (banned phrase, phantom CHANGELOG, VERSION marker) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/161
  • docs: CHANGELOG 4.16.0 entry by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/162
  • fix(release): never commit proprietary gateway source to the public repo (LED-1900) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/163
  • release: v4.16.0 by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/164
  • fix(release): gateway/VERSION marker ordering (unblocks v4.16.0 publish) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/165

Full Changelog: https://github.com/delimit-ai/delimit-mcp-server/compare/v4.15.0...v4.16.0

Security Fixes

  • Bundle npm integration now fails-CLOSED on unauthorized access (LED-1879)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track delimit-ai/delimit

Get notified when new releases ship.

Sign up free

About delimit-ai/delimit

API governance server that detects breaking changes in OpenAPI specs. Diffs two spec versions, applies configurable policy rules (strict/default/relaxed), and returns structured pass/fail verdicts. 23 change types, 10 breaking. Supports OpenAPI 3.0, 3.1, and Swagger 2.0.

All releases →

Beta — feedback welcome: [email protected]