Skip to content

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agent-reliability ai-agents ai-cost-optimization ai-safety amp claude-code
+14 more
codex cursor developer-tools feedback-loop gemini guardrails mcp mcp-server opencode pre-action-checks reduce-llm-cost save-llm-tokens thompson-sampling thumbgate

Summary

AI summary

Refreshed GTM revenue loop to use non‑vulnerable @anthropic‑ai/sdk v1.x.

Full changelog

[email protected]

Release Links

  • npm: https://www.npmjs.com/package/thumbgate/v/1.16.9
  • GitHub Release: https://github.com/IgorGanapolsky/ThumbGate/releases/tag/v1.16.9
  • Compare: https://github.com/IgorGanapolsky/ThumbGate/compare/v1.16.8...v1.16.9
  • Publish workflow: https://github.com/IgorGanapolsky/ThumbGate/actions/runs/25280195590
  • npm published at: 2026-05-03T13:17:08.020Z
  • npm shasum: 64a2b34267aec967cbccc2f25834e304d36a6e03
  • npm tarball: https://registry.npmjs.org/thumbgate/-/thumbgate-1.16.9.tgz
  • Release ref: 2df738c4acdbbeed5e7c94d87c0eee609bb0d11a

npm Email Companion

npm controls the native "Successfully published" email template, so the email itself stays short. Treat this generated artifact as the full release-note companion for that email: it carries the Changeset summaries, CHANGELOG entry, publish workflow, npm tarball, and shasum when available.

Full Changeset Release Notes

No changed .changeset/*.md entries were detected for this release range.

CHANGELOG.md Entry

1.16.9

Patch Changes

  • #1361 20c6eeb Thanks @IgorGanapolsky! - Include the Aiventyx marketplace plan in the autonomous GTM revenue-loop bundle and refresh the checked-in operator sales assets from the unified automation flow.

  • #1365 5d331f9 Thanks @IgorGanapolsky! - Harden the GTM revenue-loop buyer-intent routing so low-intent educational targets are filtered from the operator queue and first-touch Pro outreach stays discovery-first until pain is confirmed.

  • #1367 24fc667 Thanks @IgorGanapolsky! - Add Codex plugin follow-up sequences to the revenue pack and refresh the operator sales asset.

  • #1421 69ec01a Thanks @IgorGanapolsky! - Add a Codex-ready target queue export to the revenue pack and refresh the operator-facing Codex sales asset.

  • #1392 2c26dcd Thanks @IgorGanapolsky! - Refresh the GTM outreach renderer so operator-ready follow-up, warm discovery, and cold GitHub targets are generated from the current evidence-backed revenue queue instead of a stale static draft.

  • #1354 aa0e652 Thanks @IgorGanapolsky! - Add evidence-backed Gemini CLI channel outreach exports to the GTM demand pack, including active social drafts and a dedicated operator CSV artifact.

  • #1413 433ae05 Thanks @IgorGanapolsky! - Refresh the autonomous GTM runner so it regenerates the GitHub outreach asset from the current revenue-loop queue and keeps the checked-in outreach targets aligned with the latest evidence-backed pipeline state.

  • #1455 8c39c59 Thanks @IgorGanapolsky! - Refresh the GTM revenue loop with a live GitLab review-automation discovery lane, keep self-serve hook prospects on the guide-first close path, and regenerate the operator outreach pack from the updated evidence set.

  • #1457 2b6a352 Thanks @IgorGanapolsky! - Broaden GTM discovery toward GitLab review workflows and keep self-serve hook prospects on the guide-first outreach lane.

  • #1448 40f4077 Thanks @IgorGanapolsky! - Expand the revenue loop's GitHub discovery into ServiceNow agent workflow, approval-policy, and workflow-guardrail repos, then refresh the checked-in operator handoff assets from the stronger governance-focused evidence mix.

  • #1387 9e3e724 Thanks @IgorGanapolsky! - Enrich the GTM revenue-loop prospect queue with public GitHub website and company surfaces, carry the extra contact metadata into the generated operator assets, and skip the hosted revenue-status audit when local metrics are explicitly requested so local evidence-backed artifact refreshes complete quickly.

  • #1358 c5a3606 Thanks @IgorGanapolsky! - Align the customer discovery sprint guide with the actual revenue-loop artifact pack, including the default docs/marketing outputs, warm-outreach handoff files, and ChatGPT acquisition assets.

  • #1390 277bfd6 Thanks @IgorGanapolsky! - Restore authenticated GitHub prospecting in the GTM revenue loop by falling back to the local gh login when explicit GitHub API tokens are not set, and refresh the checked-in operator acquisition assets with the recovered cold-target queue.

  • #1373 3c60cef Thanks @IgorGanapolsky! - Emit stable lead IDs and per-target sales pipeline commands in the GTM revenue loop operator assets.

  • #1383 86415db Thanks @IgorGanapolsky! - Preserve the canonical Pro checkout CTA in generated GTM marketplace assets when the current target set is sprint-only.

  • #1444 39ee871 Thanks @IgorGanapolsky! - Broaden the revenue loop's GitHub discovery toward workflow approval, review, incident, and Jira control-surface repos while filtering portfolio-style false positives, then refresh the checked-in operator handoff assets from the new evidence mix.

  • #1441 46b816a Thanks @IgorGanapolsky! - Harden the GTM revenue loop so operator assets distinguish live hosted billing proof from historical or local fallback data before they claim current revenue traction.

  • #1377 2d5b20c Thanks @IgorGanapolsky! - Prefer hosted revenue-status truth in the GTM revenue loop when the local operational summary falls back, and refresh the generated marketplace and outreach assets with the verified hosted billing snapshot.

  • #1465 8578d03 Thanks @IgorGanapolsky! - Clarify the public landing-page buying paths so Sprint, Solo Pro, and free OSS routing match the repo's current commercial truth.

  • #1396 e7b993f Thanks @IgorGanapolsky! - Add a queue-backed LinkedIn workflow hardening pack to the GTM revenue loop, including tracked founder-post, comment, DM, and self-serve follow-on assets.

  • #1467 cb884a4 Thanks @IgorGanapolsky! - Add machine-readable landing-page buyer paths for the install guide, Pro checkout, and Workflow Hardening Sprint so search parsers and operators can route buyers to the right conversion path.

  • #1431 bc72c63 Thanks @IgorGanapolsky! - Refresh the GTM marketplace generator so the operator pack always surfaces an evidence-backed self-serve tooling lane alongside warm workflow-hardening targets, and keep the generated marketplace copy, handoff notes, and sample targets aligned with that mixed acquisition motion.

  • #1461 55c2002 Thanks @IgorGanapolsky! - Add evidence-backed marketplace listing variants to the GTM revenue loop, regenerate the operator queue artifacts, and keep the marketplace copy pack aligned to proof-backed sprint versus guide-to-Pro motions.

  • #1428 d0577b6 Thanks @IgorGanapolsky! - Add an operator-ready MCP directory repair pack that captures live ThumbGate vs legacy listing drift, wire it into the autonomous sales loop, and keep the discovery sprint artifact list plus workflow test coverage in sync.

  • #1475 b3edbe8 Thanks @IgorGanapolsky! - Track MCP directory follow-on offers with machine-readable UTM attribution and add a dedicated ThumbGate Pro CTA so self-serve paid intent is measurable alongside the guide and workflow sprint motions.

  • #1446 5bcaf85 Thanks @IgorGanapolsky! - Align the public FAQ and GTM revenue-loop assets around the current Pro versus Workflow Hardening Sprint offer split so operator copy stays consistent across discovery and conversion surfaces.

  • #1394 b9abbc6 Thanks @IgorGanapolsky! - Add a machine-readable operator-priority-handoff.json revenue-loop artifact so operators and automations can consume the ranked outreach queue, CTA, proof rules, and sales pipeline commands without scraping markdown.

  • #1399 3493fa7 Thanks @IgorGanapolsky! - Keep operator handoff markdown aligned with the GTM revenue-loop JSON summary by preserving summary contact surfaces and why-now fields during rendering.

  • #1436 bbdc183 Thanks @IgorGanapolsky! - Persist the GTM operator pack sidecar JSON and CSV artifacts in docs/marketing when the revenue loop writes checked-in docs, so the machine-readable queues and listing metadata stay aligned with the published Markdown packs.

  • #1408 d002036 Thanks @IgorGanapolsky! - Split self-serve Pro prospects out of the generic operator cold queue so GTM handoff assets preserve the selected motion and make self-serve closes explicit.

  • #1463 c593d66 Thanks @IgorGanapolsky! - Add a flattened operator send-now CSV and JSON export to the GTM revenue loop so operators can batch outreach and sales-pipeline updates without reformatting the ranked handoff output.

  • #1418 eb53f67 Thanks @IgorGanapolsky! - Refresh the outreach handoff generator so self-serve Pro prospects render in their own operator lane instead of being mixed into the generic cold GitHub queue.

  • #1371 80f0c2f Thanks @IgorGanapolsky! - Prioritize active revenue follow-ups in the GTM loop, suppress terminal leads from operator queues, and refresh the evidence-backed outreach bundle.

  • #1473 8c0f2a9 Thanks @IgorGanapolsky! - Surface production-rollout buyers as a first-class GTM queue lane and regenerate the operator handoff, send-now export, and marketplace copy from the live evidence-backed revenue loop.

  • #1375 ffd08ea Thanks @IgorGanapolsky! - Keep public dashboard and numbers surfaces proof-safe by removing fabricated demo revenue copy, refreshing the generated numbers snapshot wording, and pinning both behaviors with regression tests.

  • #1410 546531c Thanks @IgorGanapolsky! - Export pipeline lead ids, next-operator actions, and ready-to-run sales stage commands in the GTM target queue CSV so operators can execute outreach and stage advances directly from the flat queue artifact.

  • #1369 15d37db Thanks @IgorGanapolsky! - Keep README buyer CTAs on live ThumbGate surfaces so checkout, dashboard, and guide links preserve the intended path and UTM attribution.

  • #1426 ce17de0 Thanks @IgorGanapolsky! - Add an evidence-backed Reddit DM workflow hardening pack to the autonomous revenue loop so warm Reddit leads ship with tracked operator queues, proof-timed follow-ups, and copy-paste close drafts.

  • #1453 9eaeb3b Thanks @IgorGanapolsky! - Refresh the checked-in GTM revenue-loop assets from the latest hosted billing snapshot and live GitHub discovery so operator handoff copy, marketplace listing themes, and target queues stay aligned with current buyer signals.

  • #1403 f0871f5 Thanks @IgorGanapolsky! - Diversify the GTM revenue loop so operator assets surface both workflow-hardening targets and self-serve tooling prospects, route Pro-oriented first touch through the proof-backed setup guide, and keep generated sales-command notes aligned with the selected motion.

  • #1433 ed8460a Thanks @IgorGanapolsky! - Stabilize the hosted GTM revenue loop by retrying transient hosted-summary fallbacks, selecting the freshest hosted billing window with real commercial signal, and regenerating the operator outreach assets from that verified state.

  • #1385 0c2f70d Thanks @IgorGanapolsky! - Keep GTM revenue-loop marketplace assets evidence-backed by tightening the post-revenue headline language and preserving canonical sprint and Pro CTAs after rebases.

  • #1459 db9557b Thanks @IgorGanapolsky! - Refresh the evidence-backed GTM revenue queue and sanitize generated sales-command notes so operator artifacts do not leak outreach-instruction phrasing.

  • #1363 a978550 Thanks @IgorGanapolsky! - Refresh the autonomous GTM revenue-loop prospecting queries and regenerate the operator sales asset bundle with direct owner contact surfaces.

  • #1406 d397402 Thanks @IgorGanapolsky! - Extend the GTM revenue loop with self-serve tool-path follow-ups, checkout-close drafts, and paid-stage sales commands so operator handoff artifacts carry proof-backed conversion copy from first touch through purchase.

  • #1471 702a3da Thanks @IgorGanapolsky! - Widen the autonomous GTM revenue queue toward stronger self-serve plugin and hook targets, and refresh the operator handoff assets around those evidence-backed prospects.

  • #1424 daed1ab Thanks @IgorGanapolsky! - Keep the Claude, Gemini CLI, LinkedIn, and ChatGPT sales packs aligned with the live GTM revenue loop so operator copy stays cold-start truthful and the generated docs stop implying verified revenue before it exists.

  • #1561 c56b223 Thanks @IgorGanapolsky! - Make the Team workflow sprint intake visible on the landing page, add first-party telemetry for Team intake starts and submit attempts, and upgrade @anthropic-ai/sdk to a non-vulnerable version.

Verification Standard

  • Publish only runs from main after version sync, tests, and runtime proof pass.
  • The npm package is smoke-tested after publish by installing thumbgate@VERSION in a clean runtime.
  • GitHub Release notes are generated from Changesets, not only GitHub auto-generated PR titles.

Security Fixes

  • Upgraded @anthropic-ai/sdk to a non‑vulnerable version (CVE details not specified in changelog)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track IgorGanapolsky/mcp-memory-gateway

Get notified when new releases ship.

Sign up free

About IgorGanapolsky/mcp-memory-gateway

Pre-action gates that prevent AI coding agents from repeating known mistakes. Captures explicit feedback, auto-promotes failures into prevention rules, and enforces them via hooks.

All releases →

Beta — feedback welcome: [email protected]