This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+10 more
Summary
AI summaryMCP price field type changed from number to string.
Full changelog
Fixed
- MCP price field type —
serverInfo sizesoutputSchemapricefield changed fromz.number()toz.string()to match actual API response format (e.g. "€3.79/mo") - Plugin env token mapping —
.mcp.jsonnow mapsHETZNER_TOKEN,DIGITALOCEAN_TOKEN,VULTR_TOKEN,LINODE_TOKENfrom host environment to MCP server process - CI publish pre-check —
publish.ymlnow runsnpm viewbefore publish; skips with warning if version already exists on npm
Changed
- Plugin description updated to reflect 17 MCP tools (was 13)
- README version banner updated
Breaking Changes
- serverInfo sizes outputSchema `price` field type changed from number (z.number()) to string (z.string()).
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About kastelldev/kastell
Server security auditing and hardening toolkit. 413 security checks across 29 categories (SSH, Firewall, Docker, TLS, HTTP Headers), CIS/PCI-DSS/HIPAA compliance mapping, 19-step production hardening, fleet management, and forensic evidence collection. Supports Hetzner, DigitalOcean, Vultr, and Linode. 13 MCP tools.
Related context
Related tools
Beta — feedback welcome: [email protected]