This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+5 more
Affected surfaces
Summary
AI summaryUpdated @noble/post-quantum import path for API change.
Full changelog
Major Dependency Updates
Updates all dependencies to their latest versions including major version bumps:
Changed
- @noble/post-quantum 0.2.1 → 0.5.4 (FIPS 203/204/205 post-quantum cryptography updates)
- dotenv 16.6.1 → 17.2.3
- env-paths 3.0.0 → 4.0.0
- globby 14.1.0 → 16.1.0
- zod 3.25.76 → 4.3.6
- @types/node 20.19.21 → 20.19.30
Fixed
- @noble/post-quantum import path - Updated import from
@noble/post-quantum/ml-kemto@noble/post-quantum/ml-kem.js(API change in v0.5.4)
Installation
npm install @pan-sec/[email protected]
Full Changelog: https://github.com/Pantheon-Security/notebooklm-mcp-secure/compare/v2026.1.7...v2026.1.8
Breaking Changes
- @noble/post-quantum import changed from '@noble/post-quantum/ml-kem' to '@noble/post-quantum/ml-kem.js'
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Pantheon-Security/notebooklm-mcp-secure
Security-hardened NotebookLM MCP with post-quantum encryption (ML-KEM-768), GDPR/SOC2/CSSF compliance, and 14 security layers. Query Google's Gemini-grounded research from Claude and AI agents.
Related context
Beta — feedback welcome: [email protected]