This release keeps dependencies and maintenance posture current for teams operating this tool.
✓ No known CVEs patched in this version
Topics
+8 more
Affected surfaces
Summary
AI summaryMinor fixes and improvements.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Dependency | Low |
Switch npm publish to OIDC Trusted Publishing (no token). Switch npm publish to OIDC Trusted Publishing (no token). Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Dependency | Low |
Run publish job on Node 24 with npm 11.x for OIDC trusted publishing. Run publish job on Node 24 with npm 11.x for OIDC trusted publishing. Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Bugfix | Medium |
Fix E404 error when using OIDC trusted publishing (v4.7.1). Fix E404 error when using OIDC trusted publishing (v4.7.1). Source: llm_adapter@2026-06-04 Confidence: high |
— |
Full changelog
What's Changed
- ci(publish): switch npm publish to OIDC Trusted Publishing (no token) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/110
- release: v4.7.1 — verify OIDC trusted-publishing pipeline (provenance) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/111
- ci(publish): drop registry-url so OIDC trusted publishing works (v4.7.1 E404 fix) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/112
- ci(publish): run publish job on Node 24 (npm 11.x) for OIDC trusted publishing by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/113
Full Changelog: https://github.com/delimit-ai/delimit-mcp-server/compare/v4.7.0...v4.7.1
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About delimit-ai/delimit
API governance server that detects breaking changes in OpenAPI specs. Diffs two spec versions, applies configurable policy rules (strict/default/relaxed), and returns structured pass/fail verdicts. 23 change types, 10 breaking. Supports OpenAPI 3.0, 3.1, and Swagger 2.0.
Related context
Beta — feedback welcome: [email protected]