This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+8 more
Affected surfaces
Summary
AI summaryFixed a transitive qs DoS vulnerability by bumping express and qs.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Bugfix | Medium |
Bump express and qs dependencies to resolve transitive qs DoS issue. Bump express and qs dependencies to resolve transitive qs DoS issue. Source: llm_adapter@2026-06-04 Confidence: high |
— |
Full changelog
What's Changed
- fix(deps): bump express/qs — resolve transitive qs DoS (LED-1680) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/115
- docs: minimum-privilege adoption path (LED-2305) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/116
- release: v4.7.3 — docs/metadata: min-privilege README on npm + 28-type correction by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/117
Full Changelog: https://github.com/delimit-ai/delimit-mcp-server/compare/v4.7.2...v4.7.3
Seal attestation
Signed, replayable Seal receipt for this release (governed Layer-0 run: PASS, 0 findings):
curl -LO https://github.com/delimit-ai/delimit-mcp-server/releases/download/v4.7.3/seal-receipt-delimit-cli-4.7.3.json
npx -y [email protected] seal-verify seal-receipt-delimit-cli-4.7.3.json
Replay it live: https://delimit.ai/att/e0fe370e93fb44cb (goes live with the next site deploy)
Security Fixes
- Bumped express and qs to resolve transitive qs denial‑of‑service vulnerability (LED-1680).
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About delimit-ai/delimit
API governance server that detects breaking changes in OpenAPI specs. Diffs two spec versions, applies configurable policy rules (strict/default/relaxed), and returns structured pass/fail verdicts. 23 change types, 10 breaking. Supports OpenAPI 3.0, 3.1, and Swagger 2.0.
Related context
Beta — feedback welcome: [email protected]