Skip to content

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 4d MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-agents claude-code code-analysis code-intelligence c# .net
+5 more
dotnet-tool mcp mcp-server roslyn static-analysis

Affected surfaces

deps

Summary

AI summary

Pinned brace-expansion dependency to 1.1.16 to resolve a denial‑of‑service vulnerability.

Full changelog

2.13.0 (2026-07-22)

Features

  • get_instantiation_options — how do I construct this type (#327) (d17352c)

Bug Fixes

  • deps: pin brace-expansion to 1.1.16 to clear the DoS alert (#329) (7f4201b)

Security Fixes

  • **deps:** pin brace-expansion to 1.1.16 — resolves DoS alert

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track MarcelRoozekrans/roslyn-codelens-mcp

Get notified when new releases ship.

Sign up free

About MarcelRoozekrans/roslyn-codelens-mcp

Roslyn-based MCP server with 22 semantic code intelligence tools for .NET. Type hierarchies, call graphs, DI registrations, diagnostics, code fixes, complexity metrics, and more. Sub-millisecond lookups via pre-built indexes.

All releases →

Related context

Earlier breaking changes

  • v2.0.0 errors: introduces structured tool errors and cancellation pass-through

Beta — feedback welcome: [email protected]