This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+13 more
Summary
AI summaryRuntime hardening closed remaining remediation items across multiple security‑related areas.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Refactor | Low |
Closed remaining runtime hardening items across verifier-command blocking, context-integrity coverage, secret redaction, safe-path validation, pricing, and cache invalidation. Closed remaining runtime hardening items across verifier-command blocking, context-integrity coverage, secret redaction, safe-path validation, pricing, and cache invalidation. Source: llm_adapter@2026-05-27 Confidence: high |
— |
| Refactor | Low |
Synced root package version, public README surfaces, quickstart docs, and release guard to `0.2.6` contract while keeping `@martinloop/mcp` on `0.2.5`. Synced root package version, public README surfaces, quickstart docs, and release guard to `0.2.6` contract while keeping `@martinloop/mcp` on `0.2.5`. Source: llm_adapter@2026-05-27 Confidence: high |
— |
Full changelog
Added
- Audit remediation closure — Added the root
0.2.6public release notes for the completed OSS security and correctness follow-up slice.
Changed
- Runtime hardening — Closed the remaining root-package remediation items across verifier-command blocking, context-integrity coverage, secret redaction, safe-path validation, pricing, and cache invalidation.
- Release proof lane — Synced the root package version, public README surfaces, quickstart docs, and root release guard to the shipped
0.2.6contract while keeping@martinloop/mcpon0.2.5.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Keesan12/Martin-Loop
All releases →Related context
Related tools
Earlier breaking changes
- vmcp-v0.1.3 martin_status uses oneOf for selector exclusivity, latest as const.
- vmcp-v0.1.3 maxIterations and maxTokens modeled as integers in tool schemas.
- vmcp-v0.1.3 Tool schemas enforce additionalProperties: false on public contracts.
- vmcp-v0.1.3 Packaged artifacts now require and ship server.json alongside package.json.
Beta — feedback welcome: [email protected]