This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+11 more
Affected surfaces
Summary
AI summaryAdded Instant Form cover photo upload and OAuth scope, fixed credential writers to be atomic with backups.
Full changelog
Added
- Instant Form cover photo —
meta_ads_pages_upload_photouploads a Page photo (POST /{page_id}/photos) and returns thephoto_idfor an Instant Form introcontext_card.cover_photo_id. Adds thepages_manage_postsOAuth scope (existing tokens must re-run Meta auth to pick it up). (#151)
Fixed
- Credential / STRATEGY.md writers fail closed on malformed or partial input — no more silent loss of other providers' credentials or strategy text; atomic writes +
.bakbackups. (#276) - Budget/bid mutations validated and the MCP dispatcher now enforces each built-in tool's
inputSchema(e.g. budget/bidminimum: 1) server-side before any real-spend call. (#277)
Full changelog: see CHANGELOG.md.
Breaking Changes
- OAuth scope `pages_manage_posts` required for Instant Form cover photo upload; existing tokens must re-authorize.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About logly/mureo
Framework for AI agents (Claude Code, Cursor, Codex, Gemini) to operate Google Ads, Meta Ads, and Search Console. Grounded in a local STRATEGY.md — not metric-chasing. Defense-in-depth security, local-first. Apache 2.0.
Related context
Related tools
Beta — feedback welcome: [email protected]