Skip to content

This release adds 3 notable features for engineering teams evaluating rollout.

Published 11d MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

agent-reliability ai-agents ai-safety amp claude-code codex
+11 more
cursor developer-tools feedback-loop gemini guardrails mcp mcp-server opencode pre-action-checks thompson-sampling thumbgate

Summary

AI summary

Updates Release Links, Verification Standard, and Patch Changes across a mixed release.

Changes in this release

Security High

Redacts Gemini/Vertex authentication failures to scalar summaries and clears ambient provider credentials in tests.

Redacts Gemini/Vertex authentication failures to scalar summaries and clears ambient provider credentials in tests.

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Adds lesson-retrieval.js, lesson-reranker.js, cross-encoder-reranker.js, and lesson-embedding-index.js to public npm package.

Adds lesson-retrieval.js, lesson-reranker.js, cross-encoder-reranker.js, and lesson-embedding-index.js to public npm package.

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Raises audited public-bundle ceiling from 333 to 337 files intentionally.

Raises audited public-bundle ceiling from 333 to 337 files intentionally.

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Reduces guardrail noise by limiting network warnings to executable egress and requiring contextual recurring-memory matches before hard denial.

Reduces guardrail noise by limiting network warnings to executable egress and requiring contextual recurring-memory matches before hard denial.

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Makes self-harness prompt mutation explicit opt-in instead of silently editing and committing AGENTS.md/GEMINI.md after negative feedback.

Makes self-harness prompt mutation explicit opt-in instead of silently editing and committing AGENTS.md/GEMINI.md after negative feedback.

Source: llm_adapter@2026-07-15

Confidence: high

Full changelog

[email protected]

Release Links

  • npm: https://www.npmjs.com/package/thumbgate/v/1.28.3
  • GitHub Release: https://github.com/IgorGanapolsky/ThumbGate/releases/tag/v1.28.3
  • Compare: https://github.com/IgorGanapolsky/ThumbGate/compare/v1.28.2...v1.28.3
  • Publish workflow: https://github.com/IgorGanapolsky/ThumbGate/actions/runs/29441789061
  • npm published at: 2026-07-15T18:46:01.172Z
  • npm shasum: bbf2d445058fd4bf48a82c4368492838d2b89afa
  • npm tarball: https://registry.npmjs.org/thumbgate/-/thumbgate-1.28.3.tgz
  • Release ref: 2f3f223e36060aee6a4b572256ae241c95e13a91

npm Email Companion

npm controls the native "Successfully published" email template, so the email itself stays short. Treat this generated artifact as the full release-note companion for that email: it carries the Changeset summaries, CHANGELOG entry, publish workflow, npm tarball, and shasum when available.

Full Changeset Release Notes

No changed .changeset/*.md entries were detected for this release range.

CHANGELOG.md Entry

1.28.3

Patch Changes

  • Capture explicit thumbs feedback in the same turn with a durable event ID, distinguish capture from reusable-memory promotion, and deduplicate repeated hook deliveries including emoji-only signals without storing raw session identifiers.

    Expose only executable MCP tools for the active profile, label unavailable private-core capabilities internally, use the documented essential factory profile, and fail clearly instead of returning an empty retrieval result when a required capability is missing.

    Ship lesson-retrieval.js, lesson-reranker.js, cross-encoder-reranker.js, and lesson-embedding-index.js in the public npm package so retrieve_lessons works after installation. This intentionally raises the audited public-bundle ceiling from 333 to 337 files.

    Reduce guardrail noise by limiting network warnings to executable egress, applying task scope only to mutating actions, and requiring contextual recurring-memory matches before hard denial. Self-harness prompt mutation is now explicit opt-in instead of silently editing and committing AGENTS.md/GEMINI.md after negative feedback.

    Keep learned deny/warn policy advisory for read-only inspection, while retaining the prediction in structured diagnostics and preserving enforcement for execution-oriented actions.

    Redact Gemini/Vertex authentication failures to scalar summaries and clear ambient provider credentials in tests so an accidental live authentication call cannot expose structured credential metadata.

Verification Standard

  • Publish only runs from main after version sync, tests, and runtime proof pass.
  • The npm package is smoke-tested after publish by installing thumbgate@VERSION in a clean runtime.
  • GitHub Release notes are generated from Changesets, not only GitHub auto-generated PR titles.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track IgorGanapolsky/mcp-memory-gateway

Get notified when new releases ship.

Sign up free

About IgorGanapolsky/mcp-memory-gateway

Pre-action gates that prevent AI coding agents from repeating known mistakes. Captures explicit feedback, auto-promotes failures into prevention rules, and enforces them via hooks.

All releases →

Beta — feedback welcome: [email protected]