This release includes 2 breaking changes for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+13 more
Summary
AI summaryLicense switched from MIT to BUSL-1.1 with automatic conversion to Apache 2.0 in 2030.
Full changelog
Highlights
- License switched from MIT to BUSL-1.1. Personal self-custodial use stays free — running
vaultpilot-mcpon your own machine to manage your own portfolio (yield, swaps, lending, staking) is expressly permitted, even if it generates monetary returns. Competitive offerings to third parties on a paid hosted, managed, or embedded basis now require a separate commercial license. Auto-converts to Apache 2.0 on 2030-04-26. Versions ≤ 0.8.2 remain MIT-licensed forever; the new terms apply to v0.9.0 onward only. - Contributor License Agreement. Every external PR signs the CLA before merge via the
CLA AssistantGitHub Action. The CLA grants the project the right to relicense future contributions, so the BUSL → Apache 2.0 conversion (and any future license change) won't get stuck on contributor consent.
Included PRs
- #286 chore(license): switch to BUSL-1.1, bump to 0.9.0
- #294 chore(cla): add CLA + CLA Assistant workflow
- #296 fix(cla): allowlist Claude co-author + bot wildcard
- #295 chore(release): bump to 0.9.1
Deliberately deferred
- TRON
CHECKS PERFORMEDtemplate parity with EVM — tracked in #285. The TRON prepare path emits only theVERIFY BEFORE SIGNINGblock today; no agent-task scaffolding mirrors EVM's preview-timerenderPreviewVerifyAgentTaskBlock. Will land in a follow-up release. - 0.9.0 was never published to npm. Registry jumps from 0.8.2 → 0.9.1 directly; 0.9.0 lived only on
mainbetween the BUSL merge and the CLA-fix bump.
Breaking Changes
- License changed from MIT to BUSL-1.1 for versions v0.9.0 onward; commercial use now requires a separate commercial license.
- All external PRs must sign the Contributor License Agreement (CLA) via CLA Assistant before merge.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About szhygulin/recon-crypto-mcp
Self-custodial crypto portfolio for AI agents. Reads EVM wallet balances, ENS, token prices, and DeFi positions across Ethereum/Arbitrum/Polygon/Base (Aave V3, Compound V3, Morpho Blue, Uniswap V3 LP, Lido, EigenLayer), surfaces health-factor alerts and protocol risk scores, then prepares unsigned transactions (supply, borrow, repay, withdraw, stake, send, LiFi swap/bridge) signed on Ledger via WalletConnect — private keys never leave the hardware wallet.
Related context
Beta — feedback welcome: [email protected]