This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalThe release upgrades several dependencies and resolves all npm audit vulnerabilities, including one critical issue.
Why it matters: Resolving 16 npm audit vulnerabilities (1 critical, 7 high) reduces security risk to zero; upgrade @modelcontextprotocol/sdk, axios, winston, and dotenv as documented.
Summary
AI summaryResolved 16 npm audit vulnerabilities including one critical issue.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Resolved 16 npm audit vulnerabilities (1 critical, 7 high) reducing to zero Resolved 16 npm audit vulnerabilities (1 critical, 7 high) reducing to zero Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Dependency | High |
Updated @modelcontextprotocol/sdk from ^1.27.1 to ^1.29.0 Updated @modelcontextprotocol/sdk from ^1.27.1 to ^1.29.0 Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Dependency | High |
Updated axios from ^1.13.6 to ^1.18.1 Updated axios from ^1.13.6 to ^1.18.1 Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Dependency | High |
Updated winston from ^3.17.0 to ^3.19.0 and dotenv from ^17.2.2 to ^17.4.2 Updated winston from ^3.17.0 to ^3.19.0 and dotenv from ^17.2.2 to ^17.4.2 Source: llm_adapter@2026-07-16 Confidence: high |
— |
Full changelog
Dependency & security maintenance release.
Changes
- Updated
@modelcontextprotocol/sdk^1.27.1 → ^1.29.0 - Updated
axios^1.13.6 → ^1.18.1 - Updated
winston^3.17.0 → ^3.19.0,dotenv^17.2.2 → ^17.4.2 - Updated dev tooling: typescript-eslint, eslint, jest, prettier, ts-jest, esbuild, @types/node
- Resolves 16 npm audit vulnerabilities (1 critical, 7 high) → 0
Build, lint, and all 183 tests pass.
Security Fixes
- Resolved 16 npm audit vulnerabilities (1 critical, 7 high) across updated dependencies: @modelcontextprotocol/sdk ^1.27.1→^1.29.0, axios ^1.13.6→^1.18.1, winston ^3.17.0→^3.19.0, dotenv ^17.2.2→^17.4.2 and dev‑tooling upgrades.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About ianaleck/harvest-mcp-server
Harvest time tracking integration with 40+ tools for managing time entries, projects, clients, tasks, and generating time reports via the Harvest API v2
Related context
Beta — feedback welcome: [email protected]