Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Oct 23, 2025

This PR contains the following updates:

Package Change Age Confidence
github.com/stacklok/toolhive v0.3.11 -> v0.4.2 age confidence

Release Notes

stacklok/toolhive (github.com/stacklok/toolhive)

v0.4.2

Compare Source

What's Changed

Full Changelog: stacklok/toolhive@v0.4.1...v0.4.2

v0.4.1

Compare Source

🚀 Toolhive v0.4.1 is live!

This release focuses on improved networking flexibility, observability enhancements, and better resource efficiency in Kubernetes deployments.

Networking & Infrastructure
• Added --network option for more flexible network configurations
• Kubernetes agents can now be merged between local and project-specific setups for streamlined deployments

Observability & Telemetry
• Custom OpenTelemetry resource attributes are now supported for richer trace metadata
• Registry data source API added for better integration and data access

Developer Experience
• New /check-contribution command added to Claude integration for easier contribution validation
• Controller helpers extracted into dedicated package for cleaner codebase architecture
• MCPServer CRD size reduced by optimizing PodTemplateSpec handling

Documentation
• Clarified file naming conventions for proposal documents

Dependencies
• Updated ginkgo/v2 → v2.27.1
• Updated cedar-policy/cedar-go → v1.2.8
• Registry synced with toolhive-registry release v2025.10.23
• Toolhive images updated to v0.4.0

👋 Welcome to our newest contributors @​therealnb, @​tgrunnagle, @​dmartinol, @​ChrisJBurns, and @​blkt! 🥳

Change log

Full Changelog: stacklok/toolhive@v0.4.0...v0.4.1

v0.4.0

Compare Source

🚀 Toolhive v0.4.0 is live!

This release brings major enhancements to Kubernetes integration, MCP server capabilities, and developer tooling support!

Developer Experience
• Added support for Trae IDE and Continue.dev clients for more flexible development workflows
• New Claude Code skills and agents help automate documentation and PR tasks
• Improved developer guide with updated Go version references
• Export command now supports Kubernetes format for easier deployments

Architecture & Documentation
• Added comprehensive architecture documentation
• New MCP _meta field support improves request parsing capabilities
• Registry API has been fully externalized from the core project

MCP & Kubernetes
• Introduced MCPRemoteProxy CRD controller for seamless remote MCP server proxying
• MCPGroup now supported in Kubernetes environments for better organization
• Internal MCP optimizer group is now hidden for cleaner interfaces
• Fixed regression that broke detection of already-running remote MCP servers

Workloads & APIs
• New proxy-logs endpoint gives visibility into workload logging
• Enhanced token-exchange middleware with comprehensive unit tests

Infrastructure & Reliability
• Fixed nil pointer dereference in environment variable validation
• Resolved race condition in keyring provider that caused concurrent restart failures
• OpenShift values now properly aligned with core Kubernetes values
• Fixed chainsaw install for e2e tests
• Registry updates pulled from multiple releases (v2025.10.18–v2025.10.22)

Dependencies
• Bumped lestrrat-go/jwx/v3 → 3.0.12
• Bumped cedar-policy/cedar-go → 1.2.7
• Bumped mark3labs/mcp-go → 0.42.0
• Updated golang.org/x/exp/jsonrpc2
• Go downgraded to 1.24 for UBI alignment

👋 Welcome to our newest contributor @​tgrunnagle! 🥳

🔗 Full changelog: stacklok/toolhive@v0.3.11...v0.4.0


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
Copy link
Contributor Author

renovate bot commented Oct 23, 2025

ℹ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 8 additional dependencies were updated

Details:

Package Change
github.com/cedar-policy/cedar-go v1.2.6 -> v1.2.8
github.com/lestrrat-go/jwx/v3 v3.0.11 -> v3.0.12
github.com/mark3labs/mcp-go v0.41.1 -> v0.42.0
github.com/segmentio/asm v1.2.0 -> v1.2.1
golang.org/x/crypto v0.42.0 -> v0.43.0
golang.org/x/exp/jsonrpc2 v0.0.0-20251009144603-d2f985daa21b -> v0.0.0-20251017212417-90e834f514db
golang.org/x/net v0.44.0 -> v0.45.0
golang.org/x/text v0.29.0 -> v0.30.0

@github-actions
Copy link

🔒 MCP Security Scan Results

✅ adb-mysql-mcp-server

  • Status: Passed
  • Tools scanned: 3
  • Result: No security issues detected

✅ agentql-mcp

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ arxiv-mcp-server

  • Status: Passed
  • Tools scanned: 4
  • Result: No security issues detected

✅ astra-db-mcp

  • Status: Passed
  • Tools scanned: 16
  • Result: No security issues detected

✅ aws-diagram

  • Status: Passed
  • Tools scanned: 3
  • Result: No security issues detected

✅ aws-documentation

  • Status: Passed
  • Tools scanned: 3
  • Result: No security issues detected

✅ blender-mcp

  • Status: Passed
  • Tools scanned: 17
  • Result: No security issues detected

✅ brightdata-mcp

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ browserbase-mcp-server

  • Status: Passed
  • Tools scanned: 8
  • Result: No security issues detected

✅ chroma-mcp

  • Status: Passed
  • Tools scanned: 13
  • Result: No security issues detected

✅ context7

  • Status: Passed
  • Tools scanned: 2
  • Result: No security issues detected

✅ graphlit-mcp-server

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ heroku-mcp-server

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ ida-pro-mcp

  • Status: Passed
  • Tools scanned: 48
  • Result: No security issues detected

✅ magic-mcp

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ mcp-clickhouse

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ mcp-jetbrains

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ mcp-neo4j-aura-manager

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ mcp-neo4j-cypher

  • Status: Passed
  • Tools scanned: 3
  • Result: No security issues detected

✅ mcp-neo4j-memory

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ mcp-server-box

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ mcp-server-circleci

  • Status: Passed
  • Tools scanned: 16
  • Result: No security issues detected

✅ mcp-server-neon

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ netbird

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ notion

  • Status: Passed
  • Tools scanned: 19
  • Result: No security issues detected

✅ onchain-mcp

  • Status: Passed
  • Tools scanned: 10
  • Result: No security issues detected

✅ phoenix-mcp

  • Status: Passed
  • Tools scanned: 19
  • Result: No security issues detected

✅ sentry-mcp-server

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ supabase-mcp-server

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

✅ tavily-mcp

  • Status: Passed
  • Tools scanned: 0
  • Result: No security issues detected

Summary: Scanned 30 MCP server(s), all passed security checks. ✅

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants