Skip to content

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 1mo MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

agent-reliability ai-agents ai-safety amp claude-code codex
+11 more
cursor developer-tools feedback-loop gemini guardrails mcp mcp-server opencode pre-action-checks thompson-sampling thumbgate

Affected surfaces

auth deps

Summary

AI summary

Updates span checkout, revenue, SEO/compare, statusline, security, activation, integrations, homepage, distribution, telemetry, positioning, adapters, api, and dependency management.

Full changelog

What's Changed

  • fix(checkout): restore interstitial bypass, serve /about route, and patch tests by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2518
  • feat(checkout): capture abandonment reasons by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2519
  • feat(checkout): sample bypass traffic for objections by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2520
  • ci(release): auto-regenerate codex marketplace pack on version bump by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2522
  • seo(guides): canonical PreToolUse + MCP-tool-gating page by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2523
  • fix(revenue): reduce pricing checkout friction by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2527
  • feat(seo): auto-include compare pages in sitemap + FAQ schema for AI Overview eligibility by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2521
  • fix(revenue): add paid CTA to persistent memory article by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2530
  • seo(compare): /compare/cycode buyer-intent comparison page by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2528
  • seo(compare): /compare/claude-code-hooks-mastery (disler) buyer-intent page by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2529
  • fix(analytics): add owned funnel revenue assist by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2538
  • feat(database): add agent safety gate pack by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2542
  • fix(statusline): aggregate feedback across all stores (stop per-folder slice) by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2545
  • seo(compare): wire all live /compare pages into the hub + homepage by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2548
  • fix(statusline): aggregate feedback across all stores by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2549
  • chore(deps): combined dependency bumps (unblocks dependabot #2435/#2437/#2438/#2439/#2436) by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2550
  • feat(seo): add agentic web governance guide by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2553
  • fix(statusline): stop double-counting cached aggregates (1152→727 bug) by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2554
  • chore(pricing): retire dead Team CSS + fix stale verify-pricing-surfaces skill; refresh GTM cockpit by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2557
  • test(statusline): true e2e test for cross-store feedback aggregation by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2558
  • fix(gates): block stateful helper script bypasses by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2564
  • fix(repo): remove public scratchpads and harden observability by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2562
  • fix(repo): redact internal AI-orchestration paths after r/devops leak by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2560
  • feat(activation): guided first-rule onboarding (thumbgate quickstart) by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2568
  • chore: remove orphaned feedback-aggregate-stats (superseded by feedback-aggregate) by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2559
  • docs(security): add THREAT_MODEL.md — honest policy-vs-containment boundary by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2578
  • fix(docs): remove 13 launch-theater root markdown files (wave 7) by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2570
  • test(verification): restore golden tests + fix pre-commit FORBIDDEN_PATTERNS gap by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2581
  • fix(ci): skip changeset:check for dependabot PRs by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2587
  • fix(health): report the actually-deployed commit (RAILWAY_GIT_COMMIT_SHA) by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2589
  • chore(activation): fix SonarCloud maintainability smells in quickstart by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2574
  • chore(deps): bump protobufjs from 8.6.0 to 8.6.1 by @dependabot[bot] in https://github.com/IgorGanapolsky/ThumbGate/pull/2585
  • chore(deps): bump @anthropic-ai/sdk from 0.100.1 to 0.102.0 by @dependabot[bot] in https://github.com/IgorGanapolsky/ThumbGate/pull/2584
  • chore(deps-dev): bump undici from 8.3.0 to 8.4.1 by @dependabot[bot] in https://github.com/IgorGanapolsky/ThumbGate/pull/2583
  • feat(integrations): OPA/Rego interop — export gates as policy-as-code by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2597
  • revert(integrations): remove unvalidated OPA policy from main by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2599
  • docs(compare): ThumbGate vs SigmaShake comparison page by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2594
  • feat(homepage): animated demo GIF in hero (replaces static proof card) by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2592
  • feat(homepage): answer 'why not write my own hooks?' objection by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2593
  • chore: fix LangGraph wording overclaim + remove 2 dormant scripts by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2601
  • feat(seo): /compare/snowflake-cortex-agent-governance GEO page by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2595
  • docs(readme): honest local-first retrieval/latency diagram by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2596
  • fix(security): redact secrets at capture-time and export-time by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2608
  • feat(distribution): discoverable /thumbgate-* slash-commands (GSD-style command palette) by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2611
  • feat(distribution): discoverable auto-triggering /thumbgate-* skills (Anthropic Skills spec) by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2615
  • feat(telemetry): sync prod funnel into local store so get_business_metrics is real by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2614
  • feat(gates): regression-gated rule promotion (Self-Harness stage 3) by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2610
  • fix(landing): hero lede leads with mechanism, not vibes by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2612
  • fix(media): serve static media route and add regression tests by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2620
  • fix(repo): delete broken skool asset symlinks to unblock deployment by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2622
  • Fix landing page card links by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2623
  • Fix Pay diagnostic CTA navigation by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2624
  • Add Hermes Agent positioning by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2625
  • Add agent context governance positioning by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2626
  • feat(anti-claim): catch more lie-phrases + strict hard-block mode by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2621
  • feat(landing): surface 'self-improving enforcement' positioning by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2627
  • fix(landing): route sticky workflow CTA to intake by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2632
  • fix(revenue): separate external customer revenue by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2634
  • feat(positioning): frame safe Hermes self-evolution by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2635
  • fix(revenue): recognize hosted tracking signals by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2637
  • feat(adapters): hermes-gate — PreToolUse governance for Nous Hermes Agent by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2636
  • feat(positioning): add vLLM serving guardrails by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2640
  • feat/fix codeql alerts by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2631
  • fix(revenue): repair tracked offer routes and guide sitemap by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2644
  • fix(pricing): complete Team→Enterprise retirement across 50 public pages by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2642
  • Position ThumbGate as governance, not logging by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2652
  • Fix worker npm audit gap by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2654
  • Fix Railway deploy scope for worker maintenance by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2662
  • fix(api): harden analytics JSON against XSS by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2664
  • fix(api): constrain checkout HTML attribution by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2667
  • fix(api): allowlist public html routes by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2668
  • fix(api): avoid OAuth authorize reflection by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2669
  • fix(api): escape OAuth consent token attribute by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2671
  • Fix npm audit transitive dependency advisories by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2674
  • Add MCPMarket seller pack by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2676
  • Add Headroom and sovereign coding model guardrail pages by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2679
  • Release Guardian policy adapter gates by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/2682

Full Changelog: https://github.com/IgorGanapolsky/ThumbGate/compare/v1.27.6...v1.27.8

Security Fixes

  • fix(security): redact secrets at capture-time and export-time
  • fix(repo): remove public scratchpads and harden observability
  • fix(repo): redact internal AI-orchestration paths after r/devops leak

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track IgorGanapolsky/mcp-memory-gateway

Get notified when new releases ship.

Sign up free

About IgorGanapolsky/mcp-memory-gateway

Pre-action gates that prevent AI coding agents from repeating known mistakes. Captures explicit feedback, auto-promotes failures into prevention rules, and enforces them via hooks.

All releases →

Beta — feedback welcome: [email protected]