Skip to content

SoapyRED/freightutils-mcp

v2.6.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-agents freight logistics mcp model-context-protocol

Summary

AI summary

Minor fixes and improvements.

Full changelog

Changed

  • Repositioned as the neutral freight reference layer for AI agents (metadata/copy only — no tool, schema, or behaviour change). The package.json description, README lead, and server.json/registry description now lead with the neutral-layer voice: authoritative dangerous-goods, customs, location and freight-calculation data an agent can call and cite, from primary sources (ADR 2025 / UNECE, HS 2022 / WCO, IATA-regulated airline prefixes) — neutral by design, no freight to sell and no carrier to push. Mirrors the same repositioning applied across the website, OpenAPI spec, llms.txt and GitHub About so every source agents and directories read is consistent. Removed "basic usage" framing from the install copy. Still 19 tools, same names and schemas; minor bump so the corrected metadata propagates to npm, the MCP Registry, Smithery, and Glama on re-scan.

Security

  • Verified @modelcontextprotocol/sdk is on 1.29.0 (installed), at or above 1.26.0 which patches CVE-2026-25536 — no change required.

Security Fixes

  • dep: CVE-2026-25536 — patched in @modelcontextprotocol/sdk version 1.29.0

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track SoapyRED/freightutils-mcp

Get notified when new releases ship.

Sign up free

About SoapyRED/freightutils-mcp

17 freight calculation and reference tools — ADR dangerous goods, HS codes, LDM/CBM/chargeable weight calculators, duty estimation, airline codes, UN/LOCODE, and more. Free REST APIs + MCP server.

All releases →

Related context

Earlier breaking changes

  • v1.0.5 /api/mcp promoted as canonical Streamable HTTP transport URL.

Beta — feedback welcome: [email protected]