Skip to content

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1y MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

mcp mcp-server model-context-protocol model-context-protocol-servers sonarcloud sonarqube
+1 more
typescript

Summary

AI summary

Fixed externally-controlled format string security issue.

Full changelog

What's Changed

Fixed

  • Resolved SonarQube issue S6551 in tracing.ts - replaced deprecated url.parse() with WHATWG URL API (#237)
  • Fixed object stringification issues to prevent "[object Object]" in logs (#236)
  • Improved error formatting in logger for better debugging
  • Fixed externally-controlled format string security issue (#232)

Changed

  • Updated README.md documentation and organization (#233, #234, #235)

Full Changelog

https://github.com/sapientpants/sonarqube-mcp-server/compare/v1.6.0...v1.6.1

Security Fixes

  • Fixed externally-controlled format string security issue (#232)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track sapientpants/sonarqube-mcp-server

Get notified when new releases ship.

Sign up free

About sapientpants/sonarqube-mcp-server

A Model Context Protocol (MCP) server that integrates with SonarQube to provide AI assistants with access to code quality metrics, issues, and quality gate statuses

All releases →

Beta — feedback welcome: [email protected]