All notable changes to @socketsecurity/mcp will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
0.2.1 - 2026-09-17
- The README shows one Socket logo and uses text links for VS Code and Cursor installation.
0.2.0 - 2026-09-15
ci— normalize workflow labels
0.1.0 - 2026-09-14
mcp— structured audit logging for MCP tool executionsmcp— serve the stateless protocol on the v2 sdk
- The copyable socket-gate hook directory in the published package moved from
hooks/socket-gatetodist/socket-gate.
telemetry— forward MCP client identity to Socket APIbuild— omit dependency documentation from bundlestooling— keep debug client callbacks voidtooling— classify the product entrypointbuild— resolve current fleet entrypoint helpersoauth— reject tokens at expiration and verify reauthorization- match Socket coverage badge styling
server— refine artifact lookup and request checksfuzz— match .mts targets and stay quiet on an empty runworkspace— drop pnpm settings current pnpm rejectsdocs— remove trailing space inside a code spanorigin— trust the hosted deployment's Host over a strict Origin allowlist (#214)mcp— use socket-lib isPlainObject in maskArgsreadme— serve the four images from absolute raw URLscatalog— sync the sdk -stable alias to its base versioncatalog— sync the sdk -stable alias to the held base versionsoak— drop the unpublishable bare stuie excludescripts— drop npm-run-all2 and the dead llms-txt scriptoauth— bind tokens to this resource server and harden discoverybuild— stop the clean step racing concurrent cache writers
ci— consolidate pins and collect offline server testsci— read app client identifiers from secretsci— use public app client identifiersci— read payload client ids from secretsconfig— reconcile repository-owned filesci— use inline checkout bootstrapci— align lockfile with hydrated catalogsbootstrap— await the newest fleet referencedeps— restore the missing yaml catalog entrydeps— drop the orphaned pnpm package-manager pindeps— restore the payload importer the lockfile droppedci— keep the zizmor config tracked, it is not fleet payloadlint— escape raw NULs and hoist bypass markers
- OAuth-enabled HTTP deployments now accept
sktsec_Socket API tokens sent viaAuthorization: Bearer <token>.
- Organization tools now scope their results to the authenticated caller.
- Composer package URLs parse correctly:
packagistis accepted as a composer alias, bare-name packages resolve, and the vendor namespace is split from the package name. - The
depscoretool no longer errors on packages with missing or non-numeric score data. - The HTTP server limits the size of POST request bodies.
- OAuth tokens whose introspection response carries a malformed expiry are now rejected.
- The
package_filesandorganizationstools no longer fail withUnexpected tokenJSON errors against the live Socket API.
Initial tracked release.