Skip to content

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agent-reliability ai-agents ai-cost-optimization ai-safety amp claude-code
+14 more
codex cursor developer-tools feedback-loop gemini guardrails mcp mcp-server opencode pre-action-checks reduce-llm-cost save-llm-tokens thompson-sampling thumbgate

Affected surfaces

auth rbac deps breaking_upgrade crypto_tls

Summary

AI summary

Add SQL MCP pre‑action gates for database safety, tighten free tier limits, and enforce pricing congruence across public surfaces.

Full changelog

What's Changed

  • feat: team governance pivot, AEO, LinkedIn fix by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/656
  • fix: serve llms.txt from public route (no auth) by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/668
  • chore: retry published runtime smoke after npm propagation by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/670
  • fix: copy .well-known/ into Docker image for llms.txt by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/669
  • fix: harden merge integrity and legacy webhook checks by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/676
  • feat: reframe product around team workflow hardening by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/672
  • feat: add SQL MCP pre-action gates for database safety by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/677
  • fix: stabilize live GitHub About verification by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/681
  • chore: technical debt audit — dead code, stale docs, shared utils by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/680
  • fix: split GitHub About metadata from landing copy by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/682
  • feat: AI authenticity enforcement positioning across all discovery surfaces by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/683
  • chore: harden docs claim hygiene by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/678
  • Fix $12→$99 pricing + Memento-Skills validation + content engine by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/675
  • feat: meta-agent self-improvement loop + gate-program.md by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/684
  • fix: submit automerge PRs through trunk by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/695
  • fix: align team pricing congruence by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/696
  • feat: tighten free tier limits + Pro CTA in CLI + Reddit seeding posts by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/694
  • fix: restore clickable statusline affordances + harden localhost links by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/693
  • feat: ForgeCode adapter + Plausible tracking + daily revenue workflow by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/690
  • fix: harden merge integrity enforcement + branch protection checks by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/692
  • feat: weave AI authenticity enforcement angle across all discovery surfaces by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/699
  • fix: handle Zernio post quota skips by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/700
  • feat: prompt engineering improvements + autonomy directive in CLAUDE.md by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/691
  • feat: context-stuffing mode for lesson injection by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/707
  • fix: enforce pricing congruence across public surfaces by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/709
  • chore: consolidate duplicated filesystem helpers by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/687
  • feat: publish standalone codex plugin bundle by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/701
  • fix: block raw github auto merge by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/686
  • fix: harden HTML sanitization + fix SonarCloud security hotspots by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/689
  • feat: Google Cloud safety framework alignment by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/725
  • feat: AI agent security campaign — blog, social, site update by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/726
  • docs: tighten PR hygiene session directives by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/727
  • feat: promote Codex plugin install path by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/729
  • feat: Install for Your Agent sections in README + landing page by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/733
  • fix: clarify statusline lesson context by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/731
  • feat: Claude plugin marketplace spec compliance by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/737
  • feat: harden quick-start with budget enforcement and self-protection by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/735
  • chore: release v1.4.0 — budget enforcement + self-protection + compliance by @IgorGanapolsky in https://github.com/IgorGanapolsky/ThumbGate/pull/740

Full Changelog: https://github.com/IgorGanapolsky/ThumbGate/compare/v1.3.0...v1.4.0

Security Fixes

  • Harden HTML sanitization and fix SonarCloud security hotspots

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track IgorGanapolsky/mcp-memory-gateway

Get notified when new releases ship.

Sign up free

About IgorGanapolsky/mcp-memory-gateway

Pre-action gates that prevent AI coding agents from repeating known mistakes. Captures explicit feedback, auto-promotes failures into prevention rules, and enforces them via hooks.

All releases →

Beta — feedback welcome: [email protected]