Skip to content

Toolport

v0.3.17 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 1mo MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

ai ai-agents anthropic claude cursor developer-tools
+10 more
gateway llm local-first mcp mcp-server model-context-protocol react rust tauri vscode

Affected surfaces

auth

Summary

AI summary

Activity tab shows dollar savings of lazy discovery with selector and share button.

Full changelog

Token economics in the app

The Activity tab now shows the dollar value of what lazy discovery is saving you, not just the token count, with a model-price selector and a one-click Share button to copy your savings.

Security hardening

Three fixes from an internal security audit:

  • OAuth PKCE/state generation now fails loudly instead of silently producing a constant if the OS RNG is ever unavailable.
  • File writes use a unique atomic-write temp name, so two concurrent writers can't tear each other's contents.
  • A saved bearer token is refused over non-HTTPS to a public host.

Under the hood

Log rotation now uses the same atomic-write path, the Rust backend is fully clippy-clean, and a regression test was added for stable tool names across a live refresh. No High or Critical findings in the audit.

Security Fixes

  • OAuth PKCE/state generation now fails loudly when OS RNG unavailable
  • File writes use unique atomic temp name to prevent concurrent writer tearing
  • Saved bearer token rejected over non‑HTTPS to public host

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Toolport

Get notified when new releases ship.

Sign up free

About Toolport

All releases →

Beta — feedback welcome: [email protected]