Skip to content

Toolport

v1.4.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 23d MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai ai-agents anthropic claude cursor developer-tools
+10 more
gateway llm local-first mcp mcp-server model-context-protocol react rust tauri vscode

Summary

AI summary

Updates Highlights, Fixed / calmer signals, and https://github.com/tsouth89/toolport/blob/main/CHANGELOG.md across a mixed release.

Full changelog

Toolport v1.4.0 is a design-forward release: a full visual redesign onto the brand palette, plus a round of security-signal and Activity refinements that make the app calmer and clearer to read.

Highlights

  • A full visual redesign. Deep navy ground with a single orange accent, applied consistently across every tab. Server health reads as a colored word (not just an 8px dot), the Servers header is a scannable status bar, and the transport label is demoted to neutral so color means health, not metadata.
  • The connect flow shows the product. Pointing a client that isn't connected yet now leads with a client -> Toolport -> your servers diagram and a clear call to action, instead of a wall of prose.
  • Tool identities are searchable and grouped by server. Activity → Tool identities collapses hundreds of tools into per-server sections with a filter box.
  • A security posture summary in Settings. A one-line read of whether you're protected (guarded / partly / unprotected) and what's active.
  • Pinned lazy-discovery tools now have a home in Settings, with one-click unpin.
  • Tool-poison flags now show the matched text, so an alert is verifiable instead of opaque.

Fixed / calmer signals

  • First-seen destructive tools are no longer quarantined (still gated by block/confirm/approval policies); legacy quarantine entries auto-clear.
  • No more spurious "integrity baseline lost" alarms from an empty or mid-swap read of the shared pin file (a genuinely truncated baseline is still treated as tampering).
  • A benign tool description ("do not mention if a column is boolean") no longer trips the poison scanner.
  • The Activity tab is calmer: new-tool flood quieted, recurring notices batched, stats/discovery collapsed by default, recent-calls no longer defaults to an alarming errors-only view.

Keychain, master key, bundle id, and data directory are unchanged from 1.3.0, so no secrets or servers are lost across the update.

See the full changelog for details.

Security Fixes

  • Security posture summary in Settings provides a clear read of protection status and active controls.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Toolport

Get notified when new releases ship.

Sign up free

About Toolport

All releases →

Beta — feedback welcome: [email protected]