This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
Summary
AI summaryFixed latent architectural fragilities in tool response detection across @vurb/core and @vurb/oauth.
Full changelog
Fixed
@vurb/core — Unified Brand-Based ToolResponse Detection
Five fixes eliminating latent architectural fragilities discovered during a deep audit of the core framework.
- PostProcessor.isToolResponse() — shape-based heuristic replaced with
TOOL_RESPONSE_BRANDsymbol detection, eliminating false positives from domain objects coincidentally matching the ToolResponse shape - ResponseBuilder.build() — now stamps
TOOL_RESPONSE_BRAND(was missing, causing MVA layer corruption when usingresponse().uiBlock().build()) - GroupedToolBuilder.invalidateCache() — encapsulated cache reset replaces fragile duck-type private field mutation in ToolRegistry
- TOOL_RESPONSE_BRAND barrel export — symbol was not re-exported from
@vurb/core's public barrel, causing satellite package imports to resolve toundefined
@vurb/oauth — Branded Response Alignment
- createAuthTool ok()/fail() helpers — aligned with brand-based detection;
ok()now delegates tosuccess(),fail()stamps the brand explicitly
Changed
- ToolBuilder interface — added optional
mergeActions()andinvalidateCache()methods
Full test suite: 315 files, 6,379 tests — 0 failures.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About vinkius-labs/mcp-fusion
A TypeScript framework for building production-ready MCP servers with automatic tool discovery, multi-transport support (stdio/SSE/HTTP), built-in validation, and zero-config setup.
Related context
Related tools
Beta — feedback welcome: [email protected]