NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #864 by repository stars
Last release today
05 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Some releases are documented
notes for 22 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
1 years old
628 releases · first in 2025
One column per month.
…— the precondition for a future release to drop deprecated API versions. No new pods or RBAC objects are created. To opt out anyway, set operator.feat…
This release delivers first-class support for the new MCP 2026-07-28 ("Modern") specification revision across every ToolHive surface — the transport proxies, the transparent proxy, and Virtual MCP now recognize, serve, and bridge both the session-based 2025-11-25 revision and the new stateless revision, including mixed client×backend combinations. It also ships a reproducible project-skills workflow (thv skill sync/upgrade with a lock file and Sigstore groundwork), an opt-in Envoy network-isolation backend, and RFC 8693 token exchange with full delegation-chain auditing.
operator.rbac.scope=namespace) fail helm upgrade at render time unless they set operator.features.storageVersionMigrator: false; cluster-scoped installs need no action (#5603)-32600 instead of being executed; batches previously bypassed authorization, tool filtering, and audit, and MCP removed batching in 2025-06-18, so send individual requests (#5931)-32029 to 429 — the MCP 2026-07-28 spec reserves -32020..-32099; clients branching on error.code == -32029 must match 429 (the HTTP 429 status, Retry-After header, and data.retryAfterSeconds are unchanged) (#6120)The chart now enables the StorageVersionMigrator controller by default (operator.features.storageVersionMigrator: true), and a new chart validation rejects that combination with operator.rbac.scope=namespace — the controller cannot sync its cluster-scoped CRD informer under namespace RBAC. Affected users see helm install/helm upgrade fail with:
operator.features.storageVersionMigrator requires operator.rbac.scope=cluster
Cluster-scoped installs (the chart default) need no action: the operator pod restarts once with the migrator enabled and begins automatically trimming status.storedVersions on ToolHive CRDs — the precondition for a future release to drop deprecated API versions. No new pods or RBAC objects are created. To opt out anyway, set operator.features.storageVersionMigrator: false.
Namespace-scoped installs must opt out explicitly:
operator:
rbac:
scope: namespaceoperator:
rbac:
scope: namespace
features:
storageVersionMigrator: falsehelm get values <release> -n <ns> — you are affected if operator.rbac.scope is namespace and operator.features.storageVersionMigrator is unset or true.operator.features.storageVersionMigrator: false to your values (or pass --set operator.features.storageVersionMigrator=false).helm upgrade as usual.status.storedVersions by other means (e.g. a one-off run of kube-storage-version-migrator) before any future release drops a deprecated CRD version. See docs/operator/storage-version-migration.md.PR: #5603
Migration guide: JSON-RPC batch rejection and rate-limit error codeBatch requests (#5931) — affects only clients sending JSON-RPC batches (removed from MCP in 2025-06-18); no conformant 2025-11-25 or 2026-07-28 client emits them.
[{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{...}},
{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{...}}]Each request must be its own POST; a batch now returns:
{"jsonrpc":"2.0","id":null,"error":{"code":-32600,"message":"Invalid Request: batch requests are not supported"}}Rate-limit error code (#6120) — affects only clients branching on the JSON-RPC error.code for backoff.
{"jsonrpc":"2.0","error":{"code":-32029,"message":"rate limited","data":{"retryAfterSeconds":30}}}{"jsonrpc":"2.0","error":{"code":429,"message":"rate limited","data":{"retryAfterSeconds":30}}}error.code == 429 — or, better, key off the HTTP 429 status or data.retryAfterSeconds, which are stable across versions.HMACSecretRefs secret file carried leading/trailing whitespace bytes, previously-minted authorization codes and refresh tokens fail validation once after upgrade and clients re-authenticate; ensure the mounted secret is exactly the raw random bytes (no trailing newline).-32603), id omitted rather than null, generic denial messages, and filtered tool calls answered with -32602 over HTTP 200 instead of a bodyless 400 — monitoring or scripts keyed to the old malformed shapes need updating.input_required seam lands as groundwork for MRTR (SEP-2322) (#6074)io.modelcontextprotocol/* keys are stripped from backend response _meta so backends cannot spoof protocol metadata (#6024)_meta (SEP-414), joining backend spans to the client→proxy→server trace (#5964)x-mcp-header annotations (SEP-2243) are rejected as the spec requires (#6013)MCP-Protocol-Version header validation for the streamable proxy (#5957)list_changed notifications are consumed and propagated to clients for tools (#5965) and for resources and prompts (#5971)toolhive.lock.yaml lock file (#5892, #5893, #5894)thv skill sync restores a project's pinned skill set on any machine and verifies on-disk content in CI (#5895)thv skill upgrade re-resolves pinned skills to newer content without silent lock drift (#5896)act claim and full delegation chain, so "agent X acting for Alice" is distinguishable from Alice (#6046, refined in #6096 and adopted as the toolhive-core canonical schema in #6107)act claims are rejected at token exchange per RFC 8693 §4.1 (#6114)TOOLHIVE_NETWORK_PROXY=envoy) consolidates egress and ingress into one container (#5907, seam extracted in #5906)AllowPort permissions translate into Envoy egress RBAC policy, matching Squid's port ACLs (#5927)thv run and thv build gain a repeatable --build-with flag to constrain build-time dependencies (e.g. --build-with 'mcp<2' for uvx:// packages) (#6111, #6116)email (#6022)MCPOIDCConfig.caBundleRef, fixing OIDC discovery against self-signed issuers (#4923)event: message, unbreaking spec-lenient clients such as @ai-sdk/mcp (#5954)tag@digest) no longer fail at container create (#5978)thv list no longer poisons workload status when transient Docker errors occur (#6076), the ingress proxy port is no longer derived from a fixed upstream port (#6069), and concurrent isolated-workload startups no longer race on network creation and ingress DNS (#6071, #6083)thv run in warn mode (#6063)oneOf/anyOf/enum keywords through vMCP ingestion (#5990)| Module | Version |
|---|---|
google.golang.org/grpc |
v1.82.1 (security) |
github.com/klauspost/compress |
v1.18.7 (security, #6041) |
github.com/stacklok/toolhive-catalog |
v0.20260727.0 |
actions/checkout |
digest d23441a |
github/codeql-action |
digest e4fba86 |
golang/govulncheck-action |
digest 032d455 |
anthropics/claude-code-action |
digest be7b93b |
👋 Welcome to our newest contributors: @amir-rezaei and @stantheman0128 🎉
Full commit logNote truncated.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Serve prompts per-session in vMCP by @JAORMX in #5857
Full Changelog: v0.40.0...v0.40.1
Nothing published for this version
This release hardens Virtual MCP authorization end-to-end — explicit HTTP 403 denials, a unified authz gate, and complete capability pagination — whil
This release hardens Virtual MCP authorization end-to-end — explicit HTTP 403 denials, a unified authz gate, and complete capability pagination — while laying the groundwork for agentic auth (RFC 8693 token exchange, the MCP 2026-07-28 revision) and moving MCP protocol handling onto the official modelcontextprotocol/go-sdk. It also fixes network isolation silently breaking --network host workloads and closes an SSRF gap in upstream Dynamic Client Registration.
sub) and the acting agent (act.sub) — the foundation for agentic delegation (not yet wired into the server) (#5822).Mcp-Method/Mcp-Name header and _meta vocabulary, and server/discover/subscriptions/listen authz registration — dormant until later slices wire it into proxy routing, with no change to existing traffic (#5834).tools/call, resources/read, or prompts/get, instead of a misleading -32602 "not found" at HTTP 200 — and records the denial as denied in the audit log (#5841).thv run --network host no longer silently loses outbound connectivity: network isolation (on by default) is dropped for host/none networking with a warning, and explicitly combining --isolate-network=true with --network host now fails fast with an actionable error instead of starting a broken workload (#5794).execute_tool_script now fails loudly instead of being silently shadowed by the code-mode virtual tool (#5850).allow_private_ips setting (#5826).mark3labs/mcp-go to the go-sdk-backed toolhive-core/mcpcompat compatibility shim (a pure, atomic import swap with no call-site logic changes), moving ToolHive onto the official modelcontextprotocol/go-sdk. Note: the stdio bridge currently forwards only progress/message notifications, so tools/list_changed and similar notifications are dropped — dynamic-capability servers may show stale lists until clients re-list (#5729).task test passes on macOS (/var → /private/var); product code is unchanged (#5849).| Module | Version |
|---|---|
github.com/stacklok/toolhive-core |
v0.0.29 |
github.com/stacklok/toolhive-catalog |
v0.20260716.0 |
github/codeql-action |
7188fc3 |
golang.org/x/exp/jsonrpc2 |
9ea1abe |
Full Changelog: v0.39.0...v0.40.0
Stop VirtualMCPServer hot-reconcile on cleared imagePullSecrets by @jhrozek in #5821
Full Changelog: v0.38.0...v0.39.0
Fix tool-filter terminal drain dropping error bodies by @aponcedeleonch in #5816
Full Changelog: v0.37.0...v0.38.0
Document operator phase conventions by @buyicoder in #5766
Full Changelog: v0.36.0...v0.37.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →