This release adds 3 notable features for engineering teams evaluating rollout.
Published 1mo
MCP Developer Tools
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
agents
ai
ai-tools
claude
codex
cursor
+14 more
dollhousemcp
ensembles
llm
mcp
mcp-server
memory
model-context-protocol
personas
prompt-engineering
skills
templates
typescript
vscode
windsurf
Affected surfaces
rce_ssrf
Summary
AI summaryUpdates Highlights, Pull Requests, and Validation across a mixed release.
Full changelog
Highlights
- Harden converter and CLI output path handling so generated files stay inside their intended output directories.
- Restore SonarCloud main quality gate health with path traversal coverage, accessibility, and reliability fixes.
- Update MCP registry publisher workflow verification for the current publisher release and OIDC audience.
- Backfill the v2.0.34 changelog entry for release-history completeness.
Validation
- PR #2295 passed SonarCloud, Security Audit, DollhouseMCP Security Audit, CodeQL, Docker amd64/arm64, Docker Compose, build artifacts, dependency review, documentation validation, Claude review, and the full OS/Node test matrix.
- Local validation before the release PR included npm run build, npm test -- --maxWorkers=4, npm run verify:package-assets, and npm run security:audit with 0 findings.
Pull Requests
- #2289 Fix MCP registry publisher OIDC workflow
- #2292 Fix main Sonar quality gate findings
- #2295 Release 2.0.35
Package
- npm package: @dollhousemcp/[email protected]
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About DollhouseMCP/mcp-server
One-line installable MCP server that adds reusable customization elements — personas, skills, templates, agents, memory, and ensembles (collected customization tools)
Related context
Beta — feedback welcome: [email protected]