Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
296 commits
Select commit Hold shift + click to select a range
907f22d
eval(mcpdo): headless OAuth behavior case with an auto-consent user s…
BobDickinson Sep 28, 2026
edbd546
eval(mcpdo): elicitation behavior case with an intrinsic-elicitation …
BobDickinson Sep 29, 2026
71a2b52
mcpdo: batch-update SKILL.md and add skill-gaps regression eval cases
BobDickinson Sep 29, 2026
d848252
mcpdo: reshape agent-help around the skill body
BobDickinson Sep 29, 2026
9baebbf
mcpdo evals: fix two harness OAuth bugs, run both agents, keep failur…
BobDickinson Sep 29, 2026
ea1cf46
mcpdo: restore per-file coverage thresholds with targeted tests
BobDickinson Sep 29, 2026
25395c2
mcpdo evals: spawn agents with a minimal environment, not the develop…
BobDickinson Sep 29, 2026
bca417e
mcpdo evals: assert the helpdesk case's mapped argument values
BobDickinson Sep 29, 2026
4554444
mcpdo evals: prettier fix for skill-eval.test.mjs
BobDickinson Sep 29, 2026
1eacc6b
mcpdo: atomic sign-in flow reservation; gate authUrl OSC 8 links
BobDickinson Sep 29, 2026
d999969
fix(daemon-cli): keep auth wait timer ref'ed and make stale-lock stea…
BobDickinson Sep 29, 2026
8934389
Merge v2/main (1716af17) into v2/mcpi-client
BobDickinson Sep 29, 2026
a5576e3
fix(daemon-cli): pin default env to the caller; fail loud on transcri…
BobDickinson Sep 29, 2026
c3e8823
fix(daemon-cli): JSON Schema code-point lengths, fixture ticket hashi…
BobDickinson Sep 29, 2026
548826c
fix(cli, daemon-cli): buffer early subscribe updates; ownership-safe …
BobDickinson Sep 29, 2026
c385f1d
docs(daemon-cli): describe parked elicitation instead of the former a…
BobDickinson Sep 29, 2026
c4e713a
mcpdo: connections/show completes a finished out-of-band sign-in; lis…
BobDickinson Sep 30, 2026
e3b3722
fix(daemon-cli): override esbuild to ^0.28.2 (GHSA-g7r4-m6w7-qqqr)
BobDickinson Sep 30, 2026
45c45af
fix(daemon-cli): daemon robustness — shutdown, socket decoding, abort…
BobDickinson Sep 30, 2026
a606e39
fix(daemon-cli): keep piped stdin answers across elicitation questions
BobDickinson Sep 30, 2026
2cabc86
fix(daemon-cli): review round-2 follow-ups in terminal output paths
BobDickinson Sep 30, 2026
8250d0b
fix(scripts, docs): eval-harness correctness and shipped-skill guardr…
BobDickinson Sep 30, 2026
138dd59
fix(daemon-cli): park teardown unwires elicitation; ensureDaemon wait…
BobDickinson Sep 30, 2026
3c3de07
feat(scripts): eval pool error containment + end-to-end mcpdo smoke
BobDickinson Sep 30, 2026
4d884fa
docs(release): add the release-notes step and the re-cut procedure
cliffhall Sep 30, 2026
4c05d3b
docs(release): tighten the notes recipe and the re-cut step (Copilot)
cliffhall Sep 30, 2026
f729055
docs(release): fix the recipe's scan() indexing and notes-file placeh…
cliffhall Sep 30, 2026
c5a1f00
docs(release): delete the stale local tag too during a re-cut (Copilot)
cliffhall Sep 30, 2026
0bcc4f9
docs(release): check npm by exact version; retry transient downstream…
cliffhall Sep 30, 2026
cd05288
Merge pull request #2555 from modelcontextprotocol/v2/docs/2554-relea…
cliffhall Oct 1, 2026
bee94ef
fix(scripts, docs): Copilot round-37 findings — Windows env keys, sta…
BobDickinson Oct 1, 2026
a8c6d91
Scope secret-store entries by a per-state-file namespace
BobDickinson Oct 1, 2026
205f6f4
docs: URL elicitation has no decline; AGENTS.md says connection CLI
BobDickinson Oct 1, 2026
82343a7
Clarify stale-leftover risk in cleanup warning and adoption docs
BobDickinson Oct 1, 2026
cfd93f5
Address review round 2: namespace convergence, per-id cleanup, remova…
BobDickinson Oct 1, 2026
49dcf99
Gate legacy secret-namespace migration on the real file lock
BobDickinson Oct 1, 2026
d6da6d1
Allow mint-only adoption for entry-less legacy files; pin removal sem…
BobDickinson Oct 1, 2026
d211178
Type the parsed namespace read in adapters.test.ts
BobDickinson Oct 1, 2026
3e4b4ec
Abort the namespace re-key when the baseline restore fails
BobDickinson Oct 1, 2026
4517108
Merge branch 'v2/main' into v2/fix/2549-secret-store-namespace
cliffhall Oct 1, 2026
e3a61c4
Promote recurring pr-flow/board-ops command blocks into scripts/ helpers
BobDickinson Oct 1, 2026
9c9f0c9
Address review round 1
BobDickinson Oct 1, 2026
741d2f1
Convert remaining skill template blocks to scripts
BobDickinson Oct 1, 2026
db8767d
Address review round 3
BobDickinson Oct 1, 2026
088d3c1
Address review round 4
BobDickinson Oct 1, 2026
697481c
Address review round 5
BobDickinson Oct 1, 2026
b64be54
Address review round 6
BobDickinson Oct 1, 2026
f2af508
Address review round 7
BobDickinson Oct 2, 2026
953158d
Address review round 8
BobDickinson Oct 2, 2026
2135518
Address review round 9
BobDickinson Oct 2, 2026
5a52250
Address review round 10
BobDickinson Oct 2, 2026
c62e29d
Address review round 11
BobDickinson Oct 2, 2026
6fc4a4a
Address review round 12
BobDickinson Oct 2, 2026
cf13478
Address review round 13
BobDickinson Oct 2, 2026
512d25a
Address review round 14
BobDickinson Oct 2, 2026
9874079
Address review round 15
BobDickinson Oct 2, 2026
65dfedc
Address review round 16
BobDickinson Oct 2, 2026
66b4455
Address review round 17
BobDickinson Oct 2, 2026
aab6138
Address review round 18
BobDickinson Oct 2, 2026
6a1827d
Address review round 19
BobDickinson Oct 2, 2026
b60450a
Address review round 20
BobDickinson Oct 2, 2026
04b14c1
Address human review (docs, error-message escape, JSDoc placement)
BobDickinson Oct 2, 2026
4930bb1
Merge pull request #2556 from modelcontextprotocol/v2/fix/2549-secret…
cliffhall Oct 2, 2026
4b531f5
Merge remote-tracking branch 'origin/v2/main' into v2/chore/2558-main…
BobDickinson Oct 2, 2026
7ba3519
Merge pull request #2559 from modelcontextprotocol/v2/chore/2558-main…
cliffhall Oct 2, 2026
4dbcdae
Merge remote-tracking branch 'origin/v2/main' into v2/mcpi-client
BobDickinson Oct 3, 2026
1b43634
Park EMA IdP login on a detached helper for non-TTY callers
BobDickinson Oct 4, 2026
c1ac963
refactor(core): drive Tasks through @modelcontextprotocol/ext-tasks
cliffhall Oct 4, 2026
1dee243
refactor(core): gather the ext-tasks host adapter in core/extension/t…
cliffhall Oct 4, 2026
ca912e4
test(core): cover task progress routing and pending-input cancel bran…
cliffhall Oct 4, 2026
885d03c
feat(ema): return IdP end-session URL from sign-out
BobDickinson Oct 4, 2026
5682429
fix(core): swallow late responses to abandoned raw-wire requests
cliffhall Oct 4, 2026
b04f1aa
docs(test-servers): describe the modern Tasks flow as it runs on ext-…
cliffhall Oct 4, 2026
3c90dca
fix(core): accept the Tasks extension only in the shape ext-tasks does
cliffhall Oct 4, 2026
9393237
Merge pull request #2564 from modelcontextprotocol/v2/refactor/2316-a…
cliffhall Oct 4, 2026
3ca1d05
refactor(ema): build end-session URL from login-time metadata cache
BobDickinson Oct 4, 2026
18a8b88
Merge remote-tracking branch 'origin/v2/main' into v2/mcpi-client
BobDickinson Oct 4, 2026
064cfe5
Address smoke-test review: elicitation, abort, secret-store, CLI polish
BobDickinson Oct 4, 2026
e458ef3
Harden EMA IdP discovery and logout URL (Copilot round 40)
BobDickinson Oct 4, 2026
06e8a40
Fix comment nits from Copilot round 41
BobDickinson Oct 4, 2026
ebab9eb
Make OIDC issuer binding an exact match (Copilot round 42)
BobDickinson Oct 4, 2026
a438cf6
Name the real command in stale-lock recovery messages
BobDickinson Oct 4, 2026
9fc2e38
Type formatElicitationPendingHuman with ElicitationPendingInfo
BobDickinson Oct 4, 2026
f32b34a
feat(cli): --output <path> and --output-format raw|json to save a res…
cliffhall Oct 5, 2026
6eea831
fix: redact URL query secrets in error text shown by the web and TUI …
cliffhall Oct 5, 2026
83cd5e3
feat(web): show the OAuth redirect URI with copy in Server Settings (…
cliffhall Oct 5, 2026
ee8ecc6
feat(web): add an unauthenticated GET /healthz probe to the backend
cliffhall Oct 5, 2026
357614b
feat(cli): add -q/--quiet to print only the result or the error (#2435)
cliffhall Oct 5, 2026
9aa4253
fix(web): compare deep-link auth tokens in constant time
cliffhall Oct 5, 2026
cb54c84
feat(cli): emit bash/zsh/fish completion scripts with --completion (#…
cliffhall Oct 5, 2026
acf4cdb
ci: replace the suspended DCO app with a signoff check we own
cliffhall Oct 5, 2026
1c0d181
fix(cli): read stored-auth tokens from the active issuer slot
cliffhall Oct 5, 2026
fe73dbc
test(web): drop the unjustified double cast in storage-browser.test.ts
cliffhall Oct 5, 2026
f790f28
feat(scripts): script the release notes and Release creation (release…
cliffhall Oct 5, 2026
a0e6d47
test(cli): prove the catalog-budget escape hatch round-trips
cliffhall Oct 5, 2026
1851809
fix(cli): drop Commander's usage diagnostic under --quiet (#2435)
cliffhall Oct 5, 2026
37452a9
fix(cli): keep core's secret-store notice off stderr under --quiet (#…
cliffhall Oct 5, 2026
9a6edc3
fix(cli): complete --opt=value in bash and zsh completion
cliffhall Oct 5, 2026
d6cc7fb
feat(cli): servers/add, servers/edit, servers/remove catalog writes (…
cliffhall Oct 5, 2026
f003441
fix(cli): mute console.warn for the whole --quiet run (#2435)
cliffhall Oct 5, 2026
a4d03ba
fix(core): own-property server lookup so --server constructor reports…
cliffhall Oct 5, 2026
e2b1db9
fix(cli): refuse servers/edit --rename on an in-memory secret store
cliffhall Oct 5, 2026
7f616de
fix(cli): detect -q inside a combined short-option cluster (#2435)
cliffhall Oct 5, 2026
43ae67c
fix(cli): decode --output raw binary strictly, refusing invalid base6…
cliffhall Oct 5, 2026
0a1c0d4
fix(cli): decide --quiet from Commander's parsed state, not an argv s…
cliffhall Oct 5, 2026
0fe5c2a
fix(cli): reject stdio-only flags on a URL target and a blank --rename
cliffhall Oct 5, 2026
1376303
fix(cli): refuse a blank --config and treat malformed entries as not …
cliffhall Oct 5, 2026
c0e4ccc
Address cliffhall smoke-test re-run review (R1–R5)
BobDickinson Oct 5, 2026
679c5ce
docs(web): state that a custom token's length stays observable
cliffhall Oct 5, 2026
e5c2124
feat(cli,tui): --skill-catalog-max-skills/--skill-catalog-max-bytes f…
cliffhall Oct 5, 2026
0f99e4d
test(web): add the purpose header to the /healthz test file
cliffhall Oct 5, 2026
d513efd
fix(web): point EMA users at the IdP client for the redirect URI (#2524)
cliffhall Oct 5, 2026
58a58a9
fix(core): name the decimal-digit and safe-integer limits in the budg…
cliffhall Oct 5, 2026
a95c905
fix(web): one scrollbar for long JSON tool results (#2525)
cliffhall Oct 5, 2026
c22de80
refactor(web): route the dev /healthz through a tested Node adapter
cliffhall Oct 5, 2026
93cf3ed
docs(tui): say the skills budget flags do not bound the one-skill Ski…
cliffhall Oct 5, 2026
783e3e9
test(tui): cover runTui forwarding of --skill-catalog-max-* to the lo…
cliffhall Oct 5, 2026
411bb7f
fix: redact the remaining displayed error paths flagged in review
cliffhall Oct 5, 2026
f8b51d0
fix(cli): require --verify for --skill-catalog-max-* (#2420)
cliffhall Oct 5, 2026
f792cb2
fix(scripts): reject --previous-tag outside preview in release:notes
cliffhall Oct 5, 2026
637f88b
docs(release): quote the release:notes argument placeholders
cliffhall Oct 5, 2026
c78e764
fix(scripts): ignore closing keywords GitHub ignores in release:notes
cliffhall Oct 5, 2026
55a1fe8
fix: redact the TUI OAuth catches and revocation details flagged in r…
cliffhall Oct 5, 2026
b2e156d
fix(scripts): follow GFM's closing-fence rule; fetch before publishing
cliffhall Oct 5, 2026
aa42f66
fix(core): keep the server-controlled URI out of the suggested command
cliffhall Oct 5, 2026
cf85f55
test(core): add a crashable stdio fixture and cover mid-session crash…
cliffhall Oct 5, 2026
5ef0a06
fix(test-servers): flush stdout before crash_server exits
cliffhall Oct 5, 2026
c03fd53
refactor(test-servers): drop crash_server's untested exitCode option
cliffhall Oct 5, 2026
05179ee
fix(core): purge secret-store entries under a stripped namespace stamp
cliffhall Oct 5, 2026
658f98f
fix(core): scope ledger purges to the backend, retry them on ordinary…
cliffhall Oct 5, 2026
79d2a96
fix(core): resolve the deferred store and follow keychain hand-offs i…
cliffhall Oct 5, 2026
b157763
Merge pull request #2584 from modelcontextprotocol/v2/chore/2538-stor…
cliffhall Oct 5, 2026
c1e53b9
fix(core): never infer a finished hand-off from a missing secrets file
cliffhall Oct 5, 2026
3f7f7da
Merge pull request #2595 from modelcontextprotocol/v2/chore/2428-skil…
cliffhall Oct 5, 2026
a610279
Merge pull request #2598 from modelcontextprotocol/v2/chore/2437-cras…
cliffhall Oct 5, 2026
ddb72d3
Merge pull request #2593 from modelcontextprotocol/v2/fix/2525-result…
cliffhall Oct 5, 2026
d151b79
Merge pull request #2577 from modelcontextprotocol/v2/fix/2429-deepli…
cliffhall Oct 5, 2026
49a513c
Merge pull request #2585 from modelcontextprotocol/v2/feat/2438-web-h…
cliffhall Oct 5, 2026
a50569f
Merge pull request #2586 from modelcontextprotocol/v2/feat/2524-oauth…
cliffhall Oct 5, 2026
33323de
Merge pull request #2588 from modelcontextprotocol/v2/fix/2490-redact…
cliffhall Oct 5, 2026
cedea8b
Merge pull request #2583 from modelcontextprotocol/v2/fix/2537-own-pr…
cliffhall Oct 5, 2026
ff8f590
Merge pull request #2572 from modelcontextprotocol/v2/fix/2517-cli-st…
cliffhall Oct 5, 2026
7a29605
Merge pull request #2576 from modelcontextprotocol/v2/feat/2435-cli-q…
cliffhall Oct 5, 2026
323798a
Merge pull request #2579 from modelcontextprotocol/v2/feat/2434-cli-s…
cliffhall Oct 5, 2026
adcb3bf
Merge remote-tracking branch 'origin/v2/main' into HEAD
cliffhall Oct 5, 2026
5767f0b
Merge pull request #2600 from modelcontextprotocol/v2/fix/2560-orphan…
cliffhall Oct 5, 2026
5d6aae7
ci(dco): run the checker from the base branch; keep merges in the repair
cliffhall Oct 5, 2026
7e34d68
Merge pull request #2581 from modelcontextprotocol/v2/feat/2433-cli-s…
cliffhall Oct 5, 2026
1559fee
Merge remote-tracking branch 'origin/v2/main' into HEAD
cliffhall Oct 5, 2026
7ffb68e
Merge pull request #2591 from modelcontextprotocol/v2/chore/2550-scri…
cliffhall Oct 5, 2026
474a022
ci(dco): scope to v2/main, rerun on retarget, correct the rollout story
cliffhall Oct 5, 2026
e856b92
Merge pull request #2582 from modelcontextprotocol/v2/feat/2431-cli-o…
cliffhall Oct 5, 2026
a4876e8
Merge pull request #2587 from modelcontextprotocol/v2/feat/2420-skill…
cliffhall Oct 5, 2026
0b82060
fix(dco): NUL-separate log records; scope the docs to v2 PRs
cliffhall Oct 5, 2026
262ca87
Merge pull request #2603 from modelcontextprotocol/v2/chore/2566-dco-…
cliffhall Oct 5, 2026
2d21b78
feat(tui): copy values out of the TUI via OSC 52, with a file fallback
cliffhall Oct 5, 2026
fd294e2
fix(tui): cap Protocol tab request/response bodies like the Network pane
cliffhall Oct 5, 2026
a3119d9
fix(tui): tie Auth tab OAuth state to its client so Y/W cannot copy a…
cliffhall Oct 5, 2026
dc02863
feat(tui): w on the tool result view saves the result to a file (#2571)
cliffhall Oct 5, 2026
293e25e
docs: describe the CLI --output encodings as planned, not shipped (#2…
cliffhall Oct 5, 2026
672dbe5
fix(tui): only the latest save may report its status (#2571)
cliffhall Oct 5, 2026
6e4cbbd
fix(tui): serialize result saves; singular byte unit (#2571)
cliffhall Oct 5, 2026
e5f83cd
fix(tui): queue result saves process-wide; accurate hints (#2571)
cliffhall Oct 5, 2026
94b44e6
fix(tui): only the latest save reports; deterministic queue test (#2571)
cliffhall Oct 5, 2026
30e97e2
fix(tui,web): handle a browser opener that cannot be spawned (#2533)
cliffhall Oct 5, 2026
2626e26
feat(tui): add a `/` filter to the Tools, Resources, Prompts and Skil…
cliffhall Oct 5, 2026
f37a9ea
fix(tui): only a plain w opens the save prompt (#2571)
cliffhall Oct 5, 2026
5a4d89e
fix(tui): keep the manual-open note visible mid-OAuth (#2533)
cliffhall Oct 5, 2026
1427942
fix(tui): match template titles and key list rows by unfiltered position
cliffhall Oct 5, 2026
1926b10
fix(tui): route ToolTestModal keys to the latest render's state (#2571)
cliffhall Oct 5, 2026
4215228
Merge pull request #2597 from modelcontextprotocol/v2/fix/2539-protoc…
cliffhall Oct 5, 2026
ec00102
Merge pull request #2575 from modelcontextprotocol/v2/fix/2533-browse…
cliffhall Oct 5, 2026
efa52d3
Merge pull request #2573 from modelcontextprotocol/v2/feat/2421-tui-o…
cliffhall Oct 5, 2026
d8c591c
Merge pull request #2578 from modelcontextprotocol/v2/feat/2430-tui-l…
cliffhall Oct 5, 2026
17f1fa6
Merge pull request #2594 from modelcontextprotocol/v2/feat/2571-tui-s…
cliffhall Oct 5, 2026
0ec9f7e
feat(tui): add a '?' keybinding help overlay (#2436)
cliffhall Oct 5, 2026
d603acc
fix(tui): keep help-overlay isolation robust and accurate (#2436)
cliffhall Oct 5, 2026
d4ffb92
fix(tui): hold back a details dialog that arrives while help is open …
cliffhall Oct 5, 2026
9d73d71
fix(tui): let '?' reach a list filter, and list the sibling keys in h…
cliffhall Oct 5, 2026
1e36d8b
Merge pull request #2592 from modelcontextprotocol/v2/feat/2436-tui-k…
cliffhall Oct 5, 2026
e9766dc
feat(tui): add Tasks and Subscriptions tabs and a Roots editor (#2432)
cliffhall Oct 5, 2026
76b0137
fix(tui): route wrapped subscription auth errors to recovery; justify…
cliffhall Oct 5, 2026
7b322af
fix: own task auto-refresh rejections; serialize TUI task actions (#2…
cliffhall Oct 5, 2026
d9eb21e
fix(tui): guard roots, subscription and clear actions against re-entr…
cliffhall Oct 5, 2026
1248fd9
fix(tui): wire Tasks, Subscriptions and Roots into copy and help (#2432)
cliffhall Oct 5, 2026
49e5687
Rename daemon-cli client to mcpdo and daemon process to mcpdod
BobDickinson Oct 5, 2026
dba6d62
Merge pull request #2599 from modelcontextprotocol/v2/feat/2432-tui-t…
cliffhall Oct 5, 2026
b688420
Add disconnect --clear-auth flag and -r/--relogin short aliases
BobDickinson Oct 5, 2026
5f20945
mcpdo: correlate auth/list and auth/clear with server names
BobDickinson Oct 5, 2026
3d4bf46
mcpdo: fix auth/clear for non-URL store keys; label EMA IdP logins
BobDickinson Oct 5, 2026
2a67e07
mcpdo: move EMA IdP marker to trailing suffix in auth/list
BobDickinson Oct 5, 2026
7b21c4a
fix(web): chain MRTR rounds when the server rotates requestState
cliffhall Oct 6, 2026
284b6dc
fix(web): check the MRTR hand-off in the list's sort direction only
cliffhall Oct 6, 2026
622c6cd
mcpdo: relay OAuth sign-in URL before turn-end; align ema-logout link
BobDickinson Oct 6, 2026
ff51b5a
mcpdo: fix stale bin path in root lockfile after daemon-cli rename
BobDickinson Oct 6, 2026
5c7eab1
Merge remote-tracking branch 'origin/v2/main' into v2/mcpi-client
BobDickinson Oct 6, 2026
e7e19b6
mcpdo: cancel the abandoned call on parked-elicitation expiry/teardown
BobDickinson Oct 6, 2026
95cedcd
test(web): subscribe the fetch log before connecting in timeout-diagn…
cliffhall Oct 7, 2026
c940c5a
Merge pull request #2612 from modelcontextprotocol/v2/fix/2580-timeou…
cliffhall Oct 7, 2026
b815c31
Merge branch 'v2/main' into v2/mcpi-client
cliffhall Oct 7, 2026
f3cd206
Merge branch 'v2/main' into v2/fix/2608-mrtr-rotating-request-state
cliffhall Oct 7, 2026
59c7e71
Merge pull request #1783 from modelcontextprotocol/v2/mcpi-client
cliffhall Oct 7, 2026
b60fabf
chore(core): promote the CLI surface mcpdo shares into core/cli (#2461)
cliffhall Oct 7, 2026
ad16be2
feat(tui): verify the whole skills catalog with v, so the catalog bud…
cliffhall Oct 7, 2026
6197966
docs(testing): record the core/cli test-placement and coverage except…
cliffhall Oct 7, 2026
054bc33
Merge branch 'v2/main' into v2/fix/2608-mrtr-rotating-request-state
cliffhall Oct 7, 2026
de88759
Merge pull request #2610 from modelcontextprotocol/v2/fix/2608-mrtr-r…
cliffhall Oct 7, 2026
2c67704
ci: run the DCO check on every v2 PR now, before push, and after merg…
cliffhall Oct 7, 2026
38862e6
docs(dco): describe the PR check's scope as every v2 PR, stacked ones…
cliffhall Oct 7, 2026
702001e
ci(dco): scope the PR job to v2/** bases rather than excluding main a…
cliffhall Oct 7, 2026
fa6538c
docs(dco): stacked-branch check and repair guidance, and refresh the …
cliffhall Oct 7, 2026
ba63ed8
Merge branch 'v2/main' into v2/chore/2461-shared-cli-surface
cliffhall Oct 7, 2026
15762ac
fix(dco): match GitHub's web-flow identity whole, and document the sq…
cliffhall Oct 7, 2026
08ad529
fix(tui): keep a read verdict over a repeated entry's, prune stale ve…
cliffhall Oct 7, 2026
8ee5754
docs(dco): the push backstop does not cover a PR that edits the check…
cliffhall Oct 7, 2026
8448039
fix(dco): local:dco excludes origin/main, so the gate passes on a mil…
cliffhall Oct 7, 2026
0849fab
fix(tui): do not cache a verdict for an entry removed while verify-al…
cliffhall Oct 7, 2026
03cf7bb
fix(tui): sync the skills listing ref in a layout effect
cliffhall Oct 7, 2026
fcd9ede
test(tui): build the budgeted Skills client on mockClient instead of …
cliffhall Oct 7, 2026
a33aea0
Merge pull request #2619 from modelcontextprotocol/v2/chore/2616-dco-…
cliffhall Oct 7, 2026
aa46c2e
Merge branch 'v2/main' into v2/chore/2461-shared-cli-surface
cliffhall Oct 7, 2026
a8b33ca
Merge branch 'v2/main' into v2/feat/2590-tui-skills-verify-all
cliffhall Oct 7, 2026
3f1048b
Merge pull request #2613 from modelcontextprotocol/v2/chore/2461-shar…
cliffhall Oct 7, 2026
64700f0
Merge branch 'v2/main' into v2/feat/2590-tui-skills-verify-all
cliffhall Oct 7, 2026
a06e6e0
Merge pull request #2620 from modelcontextprotocol/v2/feat/2590-tui-s…
cliffhall Oct 7, 2026
b342eba
test(tui): stop parsing the wrapped frame for the saved-copy path (#2…
cliffhall Oct 7, 2026
f3b025e
Merge pull request #2626 from modelcontextprotocol/v2/fix/2609-tui-co…
cliffhall Oct 7, 2026
0190ce9
fix(deps): bump proxy-addr to 2.0.8 for GHSA-jqcg-44mw-7w3h (#2622)
cliffhall Oct 7, 2026
3e37fdb
fix(deps): bump source-map-js to 1.2.2 for GHSA-68fv-2mgg-jv7q (#2622)
cliffhall Oct 7, 2026
307473c
chore(release): bump version to 2.10.0 (#2622)
cliffhall Oct 7, 2026
710c990
Merge pull request #2627 from modelcontextprotocol/v2/chore/2622-bump…
cliffhall Oct 7, 2026
7d971c3
chore: merge v2/main into main for the v2.10.0 release
cliffhall Oct 7, 2026
73ff4ce
fix(cli): complete servers/add, servers/edit, servers/remove and --ou…
cliffhall Oct 7, 2026
617532f
Merge pull request #2634 from modelcontextprotocol/v2/fix/2629-comple…
cliffhall Oct 7, 2026
62b6c7a
docs(ci): describe DCO as a required check on v2/main (#2621)
cliffhall Oct 7, 2026
2500815
chore: merge v2/main into main for the v2.10.0 release
cliffhall Oct 7, 2026
c6c29b8
fix(tui): route Tasks, Subscriptions and Roots errors through the red…
cliffhall Oct 7, 2026
65a1e2e
fix(mcpdo): flush the daemon's startup error before exiting (#2638)
cliffhall Oct 7, 2026
b25bb58
fix: clear CodeQL #78-#81 from the v2.10.0 milestone merge (#2638)
cliffhall Oct 7, 2026
b9a898a
Merge pull request #2639 from modelcontextprotocol/v2/fix/2638-merge-…
cliffhall Oct 7, 2026
c4f2a25
chore: merge v2/main into main for the v2.10.0 release
cliffhall Oct 7, 2026
db3371b
Merge branch 'v2/main' into v2/chore/2621-dco-required-ruleset
cliffhall Oct 7, 2026
36db875
Merge pull request #2635 from modelcontextprotocol/v2/chore/2621-dco-…
cliffhall Oct 7, 2026
9c88e30
fix(scripts): escape backslashes before pipes in sweep table cells (#…
cliffhall Oct 7, 2026
7a2c154
docs(env): document mcpdo's daemon variables and add it to Read by (#…
cliffhall Oct 7, 2026
4195f6a
style(scripts): prettier reflow after the cell() change (#2546)
cliffhall Oct 7, 2026
0c7648a
docs(env): drop mcpdo from the proxy rows; qualify the CLI/TUI-only f…
cliffhall Oct 7, 2026
337d5b1
docs(env): mcpdo's non-TTY OAuth hand-off, and its daemon-dir home fa…
cliffhall Oct 7, 2026
643df82
Merge pull request #2641 from modelcontextprotocol/v2/fix/2546-sweep-…
cliffhall Oct 7, 2026
1bc8136
chore: merge v2/main into main for the v2.10.0 release
cliffhall Oct 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
189 changes: 84 additions & 105 deletions .claude/skills/board-ops/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,25 +57,19 @@ a fix exists. The flow is `/security-advisory`.

⚠️ **A draft card has no repository and no issue number, so the issue-side
lookup below cannot find one**, and `item-add --url` has no URL to be given.
Look it up by **title** in the full listing instead, then feed that item id to
`item-edit` or `item-delete` exactly as usual:
Look it up by **title** with the script (`scripts/board-draft-find.mjs`,
#2558), then feed the printed item id to `item-edit` or `item-delete` exactly
as usual:

```sh
GHSA=GHSA-xxxx-yyyy-zzzz # the advisory's real id
ITEM_ID= # never let an earlier lookup's id survive a failed one
BOARD=$(gh project item-list 28 --owner modelcontextprotocol --format json --limit 2000)
if jq -e '(.items | length) == .totalCount' <<<"$BOARD" >/dev/null; then
ITEM_ID=$(jq -r '.items[] | select(.content.type=="DraftIssue")
| select(.content.title | startswith("['"$GHSA"']")) | .id' <<<"$BOARD")
[ -n "$ITEM_ID" ] || echo "no draft card titled [$GHSA] on #28" >&2
else
echo "item-list incomplete or failed — raise --limit; not concluding anything" >&2
fi
npm run board:find-draft -- --ghsa GHSA-xxxx-yyyy-zzzz # prints ITEM=<id> <title>
```

Match on the **bracketed GHSA id**, not on words from the summary — a summary is
free text and two advisories can share one. Advisory drafts live on #28 only;
`/issue-triage`'s audit reports one found anywhere else.
It matches on the **bracketed GHSA id**, not on words from the summary — a
summary is free text and two advisories can share one — and it trusts the
listing only when complete, so a truncated dump reads as an error rather than
as "no draft card". Advisory drafts live on #28 only; `/issue-triage`'s audit
reports one found anywhere else.

## V2 board (#28) IDs

Expand Down Expand Up @@ -142,34 +136,40 @@ Don't try to set one here; the field id doesn't exist.

### Add a card and set its fields

Use the script (`scripts/board-card-add.mjs`, #2558) — it adds the card,
resolves every field and option id by name, sets Status (and Priority when
given), and verifies each by reading it back before printing `card: …`:

```sh
# Prints the item id (PVTI_…); capture it.
ITEM_ID=$(gh project item-add 28 --owner modelcontextprotocol --url <issue-url> --format json --jq '.id')
# An issue you filed through the create flow is approved by definition → Todo.
npm run board:add -- --issue <N> --status Todo --priority Medium
```

# Status → Todo (an issue you filed through the create flow is approved by definition)
gh project item-edit --project-id PVT_kwDOCt2Azc4BJVxt --id "$ITEM_ID" \
--field-id PVTSSF_lADOCt2Azc4BJVxtzg5iI8c --single-select-option-id fbdaf21e
For an issue swept in at triage, the differences are `--status Incoming`, a
`--priority` still scored with the rubric in `/issue-triage` (every v2 card
carries one — `board:audit` flags a card without it), and that you do **not**
set a milestone.

# Priority → Medium
gh project item-edit --project-id PVT_kwDOCt2Azc4BJVxt --id "$ITEM_ID" \
--field-id PVTSSF_lADOCt2Azc4BJVxtzg5iJE4 --single-select-option-id da944a9c
```
For **v1**, the same against board #11 — and **no `--priority`**, which that
board has no field for:

Each `item-edit` sets **one** field, so setting both takes two calls — there is
no combined form.
```sh
npm run board:add -- --issue <N> --status Todo --board 11
```

For an issue swept in at triage, the only difference is Status → **Incoming**
(`721a3d4c`) and that you do **not** set a milestone.
### Move an existing card

For **v1**, the same shape against board #11:
**For a plain Status move, use the script** (`scripts/board-card-status.mjs`,
#2558) — it does everything this recipe describes (name-resolved ids,
issue-side lookup, edit, verify re-read) and prints `card: <Status>` only on a
confirmed move:

```sh
ITEM_ID=$(gh project item-add 11 --owner modelcontextprotocol --url <issue-url> --format json --jq '.id')
gh project item-edit --project-id PVT_kwDOCt2Azc4BA5sz --id "$ITEM_ID" \
--field-id PVTSSF_lADOCt2Azc4BA5szzgzkS-g --single-select-option-id f75ad846
npm run board:status -- --issue <N> --status "In Review" # --board 11 for a v1 issue
```

### Move an existing card
The manual recipe below remains for what the scripts do not do — adapting the
lookup for another field — and as the record of how the lookup works.

Look the item id up **from the issue** rather than re-adding it. An issue's
`projectItems` lists the cards it has on every board, so the lookup does not
Expand Down Expand Up @@ -219,18 +219,20 @@ fi

**`Done` means the work shipped.** An issue closed as duplicate / won't fix /
not planned / obsolete / superseded shipped nothing, so its card is **deleted**,
not parked in Done:
not parked in Done. Use the script (`scripts/board-card-delete.mjs`, #2558) —
it looks the card up from the issue, deletes it, and verifies it is gone:

```sh
# ITEM_ID from the issue-side LOOKUP block in "Move an existing card" above —
# the lookup only, not the item-edit that follows it.
if [ -n "$ITEM_ID" ]; then
gh project item-delete 28 --owner modelcontextprotocol --id "$ITEM_ID"
else
echo "no ITEM_ID — nothing deleted" >&2
fi
npm run board:delete -- --issue <N> # --board 11 for a v1 card
npm run board:delete -- --issue <N> --reason duplicate # …and close the issue
```

An absent card always fails the run — including with `--reason`, so a wrong
`--board` or a typo'd issue number cannot close an issue whose real card
survives. The one legitimate absent-card case is retrying a run that deleted
the card and then failed the close; declare it with `--allow-missing-card` to
proceed to the close anyway.

Deleting the card removes it from the board only — **the issue itself is
untouched**, keeps its labels and comments, and stays searchable and linkable
forever. Nothing is lost; the board simply stops claiming the work was
Expand All @@ -240,15 +242,9 @@ later.

The close **reason** is the machine-readable form of the same distinction.
`gh issue close --reason` accepts only `completed` and `not planned`, so
**`duplicate` must be set through the API**:

```sh
gh api repos/modelcontextprotocol/inspector/issues/<N> -X PATCH \
-f state=closed -f state_reason=duplicate
```

(or "Mark as duplicate" in the web UI, which additionally records a
duplicate-of link).
`--reason duplicate` goes through the API (a PATCH setting
`state_reason=duplicate`) — the script does that for you. "Mark as duplicate"
in the web UI additionally records a duplicate-of link.

## ⚠️ The option-deletion hazard

Expand All @@ -272,10 +268,9 @@ Safe alternatives, in order of preference:
`id`s**, then call `updateProjectV2Field` echoing back every existing option
**including its `id`**, appending only the new one.
`ProjectV2SingleSelectFieldOptionInput.id` is an optional `String`, so a mixed
list works. Verify afterward that no card lost its value — snapshot
`gh project item-list … --format json --limit 2000` before and after, check
each is complete the way the snapshot below does, and diff; don't just
spot-check. Send those dumps to `$BOARD_TMP` too, for the reason above.
list works. Verify afterward that no card lost its value — take a
`npm run board:snapshot` before and after and diff the two dumps; don't just
spot-check. The script keeps both out of the worktree, for the reason below.

Both the `Incoming` Status option and the Urgent/High/Medium/Low Priority
options were added this way (#1891), with the before/after diff confirming all
Expand All @@ -294,15 +289,13 @@ so a snapshot is a full dump of item IDs and every card's Status and Priority.
Left in the working tree it is one `git add -A` away from being published in a
PR (Copilot).

The script (`scripts/board-snapshot.mjs`, #2558) enforces both hazards: it
writes to a fresh temp dir by default, refuses a `--dir` inside the working
tree, and writes nothing from a truncated listing — a truncated snapshot
cannot restore the cards it dropped:

```sh
BOARD_TMP=$(mktemp -d)
gh project item-list 28 --owner modelcontextprotocol --format json --limit 2000 \
> "$BOARD_TMP/board-snapshot.json"
# A truncated snapshot cannot restore the cards it dropped — refuse to proceed on one.
jq -e '(.items | length) == .totalCount' "$BOARD_TMP/board-snapshot.json" >/dev/null \
&& echo "snapshot: $BOARD_TMP/board-snapshot.json" \
|| { echo "SNAPSHOT INCOMPLETE — raise --limit and retake it before editing options" >&2
rm -f "$BOARD_TMP/board-snapshot.json"; false; }
npm run board:snapshot # prints snapshot: <path> (<count> items)
```

Note the printed path; you need it to recover.
Expand All @@ -313,55 +306,41 @@ This has happened twice — once via the API (~197 items, reconstructed by
inference) and once via the UI (the `Done` column, 247 items, restored from a
snapshot in minutes). With a snapshot the recovery is mechanical.

The recipe below is written for a deleted **Status** option. For a deleted
**Priority** option it is the same three steps with two substitutions: read
`.priority` instead of `.status` (`gh project item-list --format json` exposes
each single-select field under its lowercased name, so both keys are present),
and pass the Priority field id `PVTSSF_lADOCt2Azc4BJVxtzg5iJE4`.
The recipe is three steps; the two mechanical ones are the script
(`scripts/board-recover.mjs`, #2558), written for Status by default — pass
`--field Priority` for a deleted **Priority** option. Step 2 — the one that
edits the field schema, which is what the hazard above is about — stays a
deliberate human act.

```sh
# 0. Same temp dir the snapshot went to — keep every dump out of the worktree.
BOARD_TMP=${BOARD_TMP:-$(mktemp -d)}

# 1. Which cards lost their value, and what did they hold? lost-ids.json is
# kept ONLY when the dump is complete AND the snapshot reports what those cards
# held — step 3 refuses to run without it, so neither a truncated dump nor a
# missing snapshot can turn into a silent no-op or an unconfirmed re-apply.
rm -f "$BOARD_TMP/lost-ids.json"
gh project item-list 28 --owner modelcontextprotocol --format json --limit 2000 \
> "$BOARD_TMP/board-broken.json"
if jq -e '(.items | length) == .totalCount' "$BOARD_TMP/board-broken.json" >/dev/null; then
jq -r '[.items[]|select(.status==null)|.id]' "$BOARD_TMP/board-broken.json" \
> "$BOARD_TMP/lost-ids.json" || rm -f "$BOARD_TMP/lost-ids.json"
jq -r --slurpfile L "$BOARD_TMP/lost-ids.json" '($L[0]) as $lost
| [.items[] | select(.id as $i | $lost|index($i)) | .status // "(none)"]
| group_by(.) | map({s:.[0],c:length}) | .[] | "was \(.s): \(.c)"' \
"$BOARD_TMP/board-snapshot.json" \
|| { echo "no usable snapshot — cannot confirm what these cards held; not re-applying" >&2
rm -f "$BOARD_TMP/lost-ids.json"; }
else
echo "board-broken.json INCOMPLETE — raise --limit and re-run step 1" >&2
rm -f "$BOARD_TMP/board-broken.json"
fi
# 1. Which cards lost their value, and what did they hold? Writes
# lost-ids.json beside the snapshot, from a complete dump only, and prints
# "was <value>: <count>" from the snapshot.
npm run board:recover -- --phase diff --snapshot <path-from-board:snapshot>

# 2. Recreate the option, echoing every surviving option's id (see above).
# NOTE: the recreated option gets a NEW id — the deleted one never comes back.
# 2. Recreate the option — in the web UI, or echoing every surviving option's
# id (see above). NOTE: the recreated option gets a NEW id — the deleted
# one never comes back.

# 3. Re-apply it to the orphaned cards.
if [ -s "$BOARD_TMP/lost-ids.json" ]; then
for id in $(jq -r '.[]' "$BOARD_TMP/lost-ids.json"); do
gh project item-edit --project-id PVT_kwDOCt2Azc4BJVxt --id "$id" \
--field-id PVTSSF_lADOCt2Azc4BJVxtzg5iI8c --single-select-option-id <NEW_OPTION_ID>
sleep 0.4
done
else
echo "no lost-ids.json — step 1 did not complete; nothing re-applied" >&2
fi
# 3. Re-apply the new option id to the orphaned cards (paced).
npm run board:recover -- --phase reapply --lost <dir>/lost-ids.json --option-id <NEW_OPTION_ID>
```

Step 1's grouping is the safety check: confirm the orphaned set is exactly the
cards that held the deleted option, so you don't overwrite a card someone
legitimately moved in the meantime.
Step 1's grouping is the safety check, and the script enforces it: a card is
counted as lost only when it is blank now **and** held a value in the snapshot
(a card blank before the deletion, or added since, is excluded), and
`lost-ids.json` is written only when every lost card held the **same** value —
a mixed grouping is printed and refused, since one option id cannot restore
two. Step 3 refuses to run without step 1's file, so neither a truncated dump
nor a missing snapshot can turn into a silent no-op or an unconfirmed
re-apply. The file also records the board, the field and the value the lost
cards held, and step 3 verifies `--option-id` against them — an option id that
is valid on the field but is not the recreated option for that value is
refused rather than rewriting every lost card to the wrong one. Finally, step
3 re-reads each card immediately before editing it and aborts — naming how far
it got — if any card was deleted or set in the meantime, so a stale lost list
never overwrites a value a maintainer legitimately set; re-run step 1 and
retry with the remainder.

Because the recreated option carries a **new id**, the tables above and every
reference to it must be updated in the same change — `grep` the old id across
Expand Down
Loading
Loading