This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+7 more
Affected surfaces
Summary
AI summaryUpdated rollup to 4.59.0 and @modelcontextprotocol/sdk to fix path traversal and hono timing vulnerabilities.
Full changelog
v1.2.0 (2026-02-28)
Bug Fixes
-
Biome trailing commas in vitest config (
05dc277) -
Standardize repo structure with enforce-commit hook (
8754ee5) -
Update README badges with Codecov, tech stack, and engineering standards (
e9dec88) -
Update rollup to 4.59.0 to fix path traversal vulnerability (CVE) (
3345780) -
Use vitest directly for coverage to fix codecov upload (
e60a2ae) -
ci: Fix Qodo Merge env variable dot notation bug (
336f4b4) -
ci: Fix Qodo model to gemini-3-flash-preview (
e9393ad) -
ci: Fix syntax errors and correctly configure Qodo + Gemini 3 Flash (
20835ca) -
ci: Move pr-agent config to .pr_agent.toml (
e6e29eb) -
ci: Update to supported Gemini 3 and 2.5 flash models (
c39d51a) -
deps: Update @modelcontextprotocol/sdk to fix hono timing vulnerability (
008247f)
Chores
-
Add Gemini Code Assist style guide (
a35097e) -
Change Renovate schedule to daily 5am (
7e846e8) -
Migrate to 2025-2026 tech stack (bun/biome) (
8ff9917) -
Remove CodeRabbit config, migrating to Gemini Code Assist (
59f1b9b)
Features
-
Add Codecov coverage upload and CodeRabbit config (
83822f2) -
ci: Add Renovate config for automated dependency updates (
30c083f) -
ci: Add StepSecurity Harden-Runner to all workflow jobs (audit mode) (
b979487) -
ci: Migrate to Qodo Merge AI Review (Gemini 3 Flash) (
ad58894)
Detailed Changes: v1.1.1...v1.2.0
Security Fixes
- rollup updated to 4.59.0 — fixes CVE path traversal vulnerability
- dep: @modelcontextprotocol/sdk updated — fixes hono timing vulnerability
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About n24q02m/better-godot-mcp
18 composite tools for structured Godot 4.x interaction: scenes, nodes, GDScript, shaders, animation, tilemap, physics, audio, navigation, UI, input mapping, and signals.
Related context
Beta — feedback welcome: [email protected]