This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+8 more
Affected surfaces
ReleasePort's take
Moderate signalBundle parity guard added to prevent proprietary source leaks; npm package description updated.
Why it matters: Security: Invert npm bundle to fail-CLOSED allowlist (LED-1879) mitigates proprietary leakage risk. Release v4.16.0 published 2026‑07‑14.
Summary
AI summaryBundle parity guard, chat pre‑brief launch and per‑launch model selector added; npm package description updated.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Invert npm bundle to fail-CLOSED allowlist (LED-1879) Invert npm bundle to fail-CLOSED allowlist (LED-1879) Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Add `delimit chat --model <id>` per‑launch model selector Add `delimit chat --model <id>` per‑launch model selector Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Launch pre‑brief and rename honest launcher (Fable doc-33) Launch pre‑brief and rename honest launcher (Fable doc-33) Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fix cross‑namespace handoff receipts in bundled MCP (LED-2451) Fix cross‑namespace handoff receipts in bundled MCP (LED-2451) Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Prevent proprietary gateway source from being committed to the public repo (LED-1900) Prevent proprietary gateway source from being committed to the public repo (LED-1900) Source: llm_adapter@2026-07-15 Confidence: low |
— |
| Bugfix | Low |
Sync‑gateway exclude parity and add parity guard for proprietary‑leak prevention Sync‑gateway exclude parity and add parity guard for proprietary‑leak prevention Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Low |
Correct truth‑drift issues in docs (banned phrase, phantom CHANGELOG, VERSION marker) Correct truth‑drift issues in docs (banned phrase, phantom CHANGELOG, VERSION marker) Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Low |
Fix VERSION marker ordering to unblock v4.16.0 publish Fix VERSION marker ordering to unblock v4.16.0 publish Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
What's Changed
- docs(npm): on-promise package description (LED-3700, STR-2195) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/150
- feat(hooks): STR-2202 "tools fire tools" — HOOK half (SessionStart digest echo + subagent flight-recorder) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/151
- fix(bundle): sync-gateway exclude parity + parity guard (proprietary-leak prevention) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/153
- ci: fail-closed identity-guard (block non-anonymized commit identities) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/154
- Glama coherence: DELIMIT_TOOLSET=core Docker pin + server.json version-sync by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/152
- feat(chat): launch pre-brief + honest launcher naming (Fable doc-33) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/155
- feat(chat): add
delimit chat --model <id>per-launch model selector by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/156 - Fix cross-namespace handoff receipts in bundled MCP (LED-2451) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/157
- security(bundle): invert npm bundle to fail-CLOSED allowlist (LED-1879) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/158
- chore(bundle): classify brand_notes.py INTERNAL (guard catch #1) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/159
- chore(bundle): resync gateway bundle (memory projection budget fix) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/160
- fix(docs): truth-drift corrections (banned phrase, phantom CHANGELOG, VERSION marker) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/161
- docs: CHANGELOG 4.16.0 entry by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/162
- fix(release): never commit proprietary gateway source to the public repo (LED-1900) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/163
- release: v4.16.0 by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/164
- fix(release): gateway/VERSION marker ordering (unblocks v4.16.0 publish) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/165
Full Changelog: https://github.com/delimit-ai/delimit-mcp-server/compare/v4.15.0...v4.16.0
Security Fixes
- Bundle npm integration now fails-CLOSED on unauthorized access (LED-1879)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About delimit-ai/delimit
API governance server that detects breaking changes in OpenAPI specs. Diffs two spec versions, applies configurable policy rules (strict/default/relaxed), and returns structured pass/fail verdicts. 23 change types, 10 breaking. Supports OpenAPI 3.0, 3.1, and Swagger 2.0.
Beta — feedback welcome: [email protected]