Changelog
1.1.45 (2026-08-28)
Changed
- reference: regenerate the released-artifacts matrix from GHCR (#284) (ad5cc1a)
- reference: upgrade guide for 2.15.0 (#282) (ca025f4)
1.1.44 (2026-08-28)
Changed
- guides: link the containers guide to the official-servers page (#281) (5908e15)
- guides: one canonical page for the official servers (#279) (1b19166)
- guides: the containers guide uses the official images (#278) (ed13ecc)
1.1.43 (2026-08-24)
Changed
- reference: regenerate the released-artifacts matrix from GHCR (#275) (317ba53)
- reference: regenerate the released-artifacts matrix from GHCR (#277) (b8520ec)
1.1.42 (2026-08-24)
Changed
- approval_list does not work for prompts or resources (#263) (5ce5ac6)
- architecture: ADR-024 -- a human hold belongs on a tool call, not a fetch (#266) (85fa971)
- guides: bring over upgrade notes for the latest release (#273) (7c18ab5)
- guides: document header exposure and the x-mcp-header controls (#272) (d5babca), closes #271
- guides: upgrade note for 2.13.1 (#268) (d62f48e)
- reference: document the access: and ui_resources: config blocks (#267) (22140fa)
- reference: regenerate the released-artifacts matrix from GHCR (#261) (22d00ec)
- reference: regenerate the released-artifacts matrix from GHCR (#270) (90da218)
- reference: regenerate the released-artifacts matrix from GHCR (#274) (34d5485)
1.1.41 (2026-08-20)
Fixed
- repo: catch up with the v1alpha2 CRD split, cover 2.13.0, and stop the freshness gate reading its own example (#260) (911bbba)
Changed
- guides: mirror the Helm 3/4 support statement into the install docs (#257) (62ea5d4), closes #235
- reference: regenerate the released-artifacts matrix from GHCR (#259) (fc9e575)
1.1.40 (2026-08-18)
Changed
1.1.39 (2026-08-18)
Changed
1.1.38 (2026-08-18)
Changed
1.1.37 (2026-08-18)
Changed
- guides: requireApproval routes to the approval gate since core 2.11.0 (#243) (b44be02)
- repo: re-verify DOCS_VALIDATION.md against 2.11.0 and fold in the 2.11.0 upgrade notes (#245) (1c2ee05)
1.1.36 (2026-08-17)
Changed
1.1.35 (2026-08-17)
Changed
1.1.34 (2026-08-17)
Changed
1.1.33 (2026-08-17)
Changed
1.1.32 (2026-08-17)
Changed
- architecture: adr-023 — the MCP Registry entry describes a package, not a service (#230) (0c92475)
- guides: bring over upgrade notes for the latest release (#231) (417a506)
- reference: regenerate the released-artifacts matrix from GHCR (#212) (61759a0)
- reference: regenerate the released-artifacts matrix from GHCR (#232) (8fefaaa)
1.1.31 (2026-08-15)
Changed
- reference: stop restating generated versions, and drop the dispatch nobody sends (#210) (c613b01), closes #209
1.1.30 (2026-08-15)
Changed
1.1.29 (2026-08-15)
Changed
- guides: make the testing guide describe the suite that exists (#205) (7eec727)
- guides: point observability at the chart, not core's deleted monitoring/ (#204) (7c37662)
1.1.28 (2026-08-14)
Changed
1.1.27 (2026-08-14)
Changed
- cookbook: sticky routing is a requirement of running replicas (#195) (7ca06b9)
- guides: a replica set no longer requires sticky routing (#199) (ad46144)
- reference: regenerate the released-artifacts matrix from GHCR (#201) (2cee7d1)
- reference: the version surfaces move to 2.7.0 (#200) (12126fe)
1.1.26 (2026-08-12)
Changed
- guides: approval delivery routes, is named after its surface, and says when it is silent (#191) (e22d979)
1.1.25 (2026-08-11)
Changed
1.1.24 (2026-08-11)
Changed
- architecture: record two decisions the code was carrying in comments (#185) (4983bcf)
- reference: the upgrade note for 2.6.0 (#187) (1e1d162)
- reference: the version surfaces move to 2.6.0 (#188) (58f4bb0)
1.1.23 (2026-08-11)
Changed
1.1.22 (2026-08-10)
Changed
1.1.21 (2026-08-10)
Changed
- guides: the connect-time guard survives a restart from 2.5.1 (#178) (cee253d)
- release: the version surfaces and the SSRF caveat move to 2.5.1 (#177) (1668bc0)
1.1.20 (2026-08-10)
Changed
- architecture: record which of ADR-019's limits coordination settled (#175) (2c86d5f)
- guides: what the SSRF guard covers, and what a replica set needs installed (#174) (2a5a36d)
- reference: the reference surfaces 2.5.0 changed (#172) (5e19b40)
- release: the pages that name a version name 2.5.0 (#173) (a1db213)
- repo: one changelog file, and release-please writes to it (#171) (1f41794)
1.1.19 (2026-08-10)
Changed
- guides: point the deepest pages back at the concept behind them (#168) (1849ef0)
- operations: write down the release surfaces so they stop drifting (#169) (fd0cd9c)
- reference: regenerate the released-artifacts matrix from GHCR (#165) (352e16f)
- reference: regenerate the released-artifacts matrix from GHCR (#167) (d03c9a4)
- security: settle MCP04 and MCP09 against the operator source (#170) (5b7eee5)
1.1.18 (2026-08-09)
Changed
- discovery source-management Preview + connect-time SSRF + pg pooling (#162) (55f2448)
- release: advertise mcp-hangar 2.5.0 (#164) (2c51c6d)
1.1.17 (2026-08-08)
Changed
- reference: the CLI and the source listing say what they do (#159) (54a92fb)
- release: the upgrade note for 2.5.0 (#160) (b5ff3e7)
1.1.16 (2026-08-08)
Changed
- guides: the recipes can be run again (#154) (ec5a913)
- guides: three dead ends that are no longer dead (#158) (2124ff4)
- reference: remove two knobs nothing reads, and correct a third (#157) (38cc999)
- reference: the REST reference matches the API (#156) (b07e563)
1.1.15 (2026-08-07)
Changed
- architecture: ADR-019, one storage decision and two backends (#149) (d028c7d)
- architecture: the tool catalogue is not a projection, and the tenure is the holder's (#152) (91e0099)
- architecture: what it takes to run more than one gateway (ADR-020) (#150) (f40558a)
- guides: running more than one replica, and the config that decides it (#151) (ef1bd42)
- guides: stop recommending a multi-replica deployment that breaks approvals (#148) (6f0ba55)
- guides: the recipes a second replica changes (#153) (c0ed65a)
- release: move the version surfaces to 2.4.0, and write the upgrade note (#146) (d6129f8)
1.1.14 (2026-08-05)
Changed
1.1.13 (2026-08-05)
Changed
- guides: document extending discovery and the namespace policy move (#140) (0cd084f)
- guides: install instructions that work, and two claims that did not (#143) (c2822b2)
1.1.12 (2026-08-05)
Changed
1.1.11 (2026-08-04)
Changed
1.1.10 (2026-08-04)
Changed
- architecture: lock_hierarchy moved to the shared kernel (#135) (004a48a)
- reference: regenerate the released-artifacts matrix from GHCR (#130) (63f4b60)
- release: move the version surfaces to core 2.2.1 (#131) (53fbbaa)
- upgrade: add the 2.2.2 note for the event-sourcing auth store (#134) (faeae19)
1.1.9 (2026-08-03)
Changed
1.1.8 (2026-08-01)
Changed
1.1.7 (2026-08-01)
Changed
1.1.6 (2026-08-01)
Changed
1.1.5 (2026-07-31)
Changed
1.1.4 (2026-07-31)
Changed
- guides: correct the RBAC role table against roles.py (#119) (43809ef)
- guides: fix the API paths and framing that reach AI consumers verbatim (#118) (dec9824)
- reference: fix what the first 2.0.0 pass missed (#116) (62b75d9)
- reference: move the compatibility matrix onto the 2.0.0 line (#115) (7915ceb)
- reference: regenerate the released-artifacts matrix from GHCR (#114) (57f6956)
- reference: the chart that installs 2.0.0 exists now (#117) (daf8f1c)
- release: move the documentation to 2.0.0 (#112) (5de8fea)
1.1.3 (2026-07-29)
Changed
- architecture: add ADR-016 and the approval adapter guide (#109) (c8308f3)
- architecture: add ADR-017 on the approval input-request namespace (#111) (f72dad8)
1.1.2 (2026-07-28)
Changed
- architecture: record that the Tasks wire is vendored, not taken from the SDK (#99) (80b13bc)
- guides: bring the governed-tasks pages back to what actually ships (#101) (15121d4)
- guides: move to 2.0.0rc3 and retire the gap warnings (#104) (3fcceb3)
- guides: record that the task relay is on by default again (#102) (50025f0)
- guides: stop the tasks pages contradicting themselves and the artifact (#103) (bb2b245)
- reference: move the version surfaces to 1.6.3 and fix a dead anchor (#106) (5d3d2a8)
- reference: the compatibility matrix still named the rc.1 candidate (#105) (781f8d4)
1.1.1 (2026-07-27)
Changed
- reference: move the version surfaces to core 1.6.2 and the 2.0.0rc1 candidate (#92) (9e7262f)
- reference: resync the artifact matrix after both charts published (#94) (e36926b)
1.1.0 (2026-07-26)
Added
- guides: renovation phase 1 — truth-now docs for 1.6.0 (#87) (2543475)
- guides: renovation phase 2 — governed tasks guide + v2 preview notes (#88) (ef58f40)
Fixed
Changed
- accuracy/currency review — align content to the current project state (cb72bd6)
- adr-014: record task-relay activation (2026-07-22) (#86) (743a820)
- adr: ADR-013 egress policy enforcement model (MCPEgressPolicy) (#72) (8e2480d)
- adr: amend ADR-009 with the prerelease / pre-GA branch lane (#77) (ba4749e)
- architecture: add ADR-012 (interceptor SEP-pin tracking policy) (#70) (6ac3f1d)
- architecture: add ADR-014 (tasks relayed with governance, partially supersedes ADR-008) (#78) (1aaa1a6)
- architecture: correct ADR-009 amendment — prereleases publish to prod PyPI (#85) (37f4288)
- architecture: ratify ADR-014 (Proposed -> Accepted) (#79) (469e5ac)
- bump version surfaces to core 1.6.1 + v2 preview 2.0.0a2 (#90) (347a21c)
- currency pass — v0.14.0 L7 delivery, release matrix, rebuilt architecture overview (8ca8381)
- guides: add the MCPEgressPolicy egress policy guide (#73) (fda8656)
- guides: reflect the 1.6.0 observability/semconv changes (#76) (5dfd3fb)
- guides: refresh MCPEgressPolicy guide for the completed feature (#74) (2df3798)
- reference: add operational runbooks for the shipped alerts (#75) (a06dd93)
- strip 'enterprise' tier/marketing framing (no paid tier) (e046c8c)
1.0.4 (2026-07-18)
Changed
- architecture: add ADR-011 (single source of truth for cross-repo facts) (#68) (ae530b5)
- guides: fix stale github.io helm-repo refs to OCI + add domain-lint (ADR-011) (#69) (cd9360e)
- reference: add OWASP MCP Top 10 coverage page (#66) (a01ce74)
1.0.3 (2026-07-18)
Changed
- architecture: add ADR-010 retiring the agent + Hangar Cloud tier (#52) (858c173)
- reference: add EU AI Act / SOC 2 compliance posture doc (#55) (b5fd9d9)
- reference: generate the released-artifacts matrix + immutable-tags status (Track 2) (#56) (c52fd54)
- reference: update compatibility matrix to core 1.5.1 (#53) (fb1cace)
- release: correct the chart install status and record mutable chart tags (#46) (2bd19ff)
- repo: retire hangar-agent / Hangar Cloud references (#51) (91561fd)
1.0.2 (2026-07-16)
Changed
- guides: correct contributing and git-flow for the multi-repo topology (#44) (ed5a858)
- reference: document event_store fail-fast and non-loopback auth requirement (#42) (1fe2671)
- release: record the validated kubernetes range and the chart install status (#45) (6bfb7aa)
1.0.1 (2026-07-15)
Changed
1.0.0 (2026-07-15)
Added
Changed
- architecture: add ADR-008 -- task governance is relay-only (#12) (9321f43)
- architecture: draft ADR-009 independent release topology (#32) (cf5c4de)
- content: document mcp-hangar 1.3.0 (710b29a)
- cookbook: add 1.3 digest pinning upgrade recipe (a3832ce)
- cookbook: add interceptor discovery recipe (73e8d08)
- guides: add a progressive deployment playbook (#23) (9f21a91)
- guides: add external multi-tenant OIDC front door cookbook (#26) (982bbe2)
- guides: add local dev and staging deployment profiles cookbook (#25) (20f3cb0)
- guides: add production read-only and controlled-write boundaries cookbook (#24) (71c5248)
- guides: cookbook harden a public authenticated MCP gateway (#29) (37b7172), closes #21
- guides: correct rate-limit scope in cookbook 06 (#15) (c20f65a)
- guides: document mcp-hangar 1.4.0 and add 1.4 cookbooks (#8) (9cda48c)
- guides: fix drifted cookbook recipes against 1.4.0 source (#9) (9591ffc)
- guides: fix duplicated recipe numbers in cookbook 21 and 22 (#31) (a52521f), closes #30
- guides: use mcp-hangar as the Kubernetes namespace in examples (#36) (62d9806)
- release: add 1.5.0 upgrade notes, CLI auth command, and compatibility matrix (#39) (57bbe9b)
- release: add release compatibility and GHCR security policy (#33) (08a41c9)
- release: add Releases & Artifacts install index (#11) (6808a91)
- release: correct the core image as signed (it already is) (#38) (3483627)
- release: record cosign signing done; all artifacts signed (#37) (27b75b7)
- release: record verified Helm chart releases; all lanes published (#35) (ef65e84)
- release: record verified operator and agent image releases (#34) (18aba8c)
- sync with mcp-hangar source, document 1.3.0, add drift validation (#7) (45bef08)