Changelog

1.1.45 (2026-08-28)

Changed

  • reference: regenerate the released-artifacts matrix from GHCR (#284) (ad5cc1a)
  • reference: upgrade guide for 2.15.0 (#282) (ca025f4)

1.1.44 (2026-08-28)

Changed

  • guides: link the containers guide to the official-servers page (#281) (5908e15)
  • guides: one canonical page for the official servers (#279) (1b19166)
  • guides: the containers guide uses the official images (#278) (ed13ecc)

1.1.43 (2026-08-24)

Changed

  • reference: regenerate the released-artifacts matrix from GHCR (#275) (317ba53)
  • reference: regenerate the released-artifacts matrix from GHCR (#277) (b8520ec)

1.1.42 (2026-08-24)

Changed

  • approval_list does not work for prompts or resources (#263) (5ce5ac6)
  • architecture: ADR-024 -- a human hold belongs on a tool call, not a fetch (#266) (85fa971)
  • guides: bring over upgrade notes for the latest release (#273) (7c18ab5)
  • guides: document header exposure and the x-mcp-header controls (#272) (d5babca), closes #271
  • guides: upgrade note for 2.13.1 (#268) (d62f48e)
  • reference: document the access: and ui_resources: config blocks (#267) (22140fa)
  • reference: regenerate the released-artifacts matrix from GHCR (#261) (22d00ec)
  • reference: regenerate the released-artifacts matrix from GHCR (#270) (90da218)
  • reference: regenerate the released-artifacts matrix from GHCR (#274) (34d5485)

1.1.41 (2026-08-20)

Fixed

  • repo: catch up with the v1alpha2 CRD split, cover 2.13.0, and stop the freshness gate reading its own example (#260) (911bbba)

Changed

  • guides: mirror the Helm 3/4 support statement into the install docs (#257) (62ea5d4), closes #235
  • reference: regenerate the released-artifacts matrix from GHCR (#259) (fc9e575)

1.1.40 (2026-08-18)

Changed

  • guides: bring over upgrade notes for the latest release (#253) (2308e09)

1.1.39 (2026-08-18)

Changed

  • reference: document truncation/interceptors/hot_loading and correct ADR-020 claims (#250) (ca986b6)

1.1.38 (2026-08-18)

Changed

  • reference: regenerate the released-artifacts matrix from GHCR (#247) (c6e8301)

1.1.37 (2026-08-18)

Changed

  • guides: requireApproval routes to the approval gate since core 2.11.0 (#243) (b44be02)
  • repo: re-verify DOCS_VALIDATION.md against 2.11.0 and fold in the 2.11.0 upgrade notes (#245) (1c2ee05)

1.1.36 (2026-08-17)

Changed

  • reference: regenerate the released-artifacts matrix from GHCR (#241) (8001081)

1.1.35 (2026-08-17)

Changed

  • reference: regenerate the released-artifacts matrix from GHCR (#239) (ea703ac)

1.1.34 (2026-08-17)

Changed

  • reference: regenerate the released-artifacts matrix from GHCR (#236) (7291609)

1.1.33 (2026-08-17)

Changed

  • reference: regenerate the released-artifacts matrix from GHCR (#233) (0df560b)

1.1.32 (2026-08-17)

Changed

  • architecture: adr-023 — the MCP Registry entry describes a package, not a service (#230) (0c92475)
  • guides: bring over upgrade notes for the latest release (#231) (417a506)
  • reference: regenerate the released-artifacts matrix from GHCR (#212) (61759a0)
  • reference: regenerate the released-artifacts matrix from GHCR (#232) (8fefaaa)

1.1.31 (2026-08-15)

Changed

  • reference: stop restating generated versions, and drop the dispatch nobody sends (#210) (c613b01), closes #209

1.1.30 (2026-08-15)

Changed

  • reference: regenerate the released-artifacts matrix from GHCR (#207) (1d83c17)

1.1.29 (2026-08-15)

Changed

  • guides: make the testing guide describe the suite that exists (#205) (7eec727)
  • guides: point observability at the chart, not core's deleted monitoring/ (#204) (7c37662)

1.1.28 (2026-08-14)

Changed

  • guides: KUBERNETES.md teaches only fields the operator honours (#202) (148301a)

1.1.27 (2026-08-14)

Changed

  • cookbook: sticky routing is a requirement of running replicas (#195) (7ca06b9)
  • guides: a replica set no longer requires sticky routing (#199) (ad46144)
  • reference: regenerate the released-artifacts matrix from GHCR (#201) (2cee7d1)
  • reference: the version surfaces move to 2.7.0 (#200) (12126fe)

1.1.26 (2026-08-12)

Changed

  • guides: approval delivery routes, is named after its surface, and says when it is silent (#191) (e22d979)

1.1.25 (2026-08-11)

Changed

  • repo: draw the diagrams instead of spelling them in ASCII (#189) (0fbd390)

1.1.24 (2026-08-11)

Changed

  • architecture: record two decisions the code was carrying in comments (#185) (4983bcf)
  • reference: the upgrade note for 2.6.0 (#187) (1e1d162)
  • reference: the version surfaces move to 2.6.0 (#188) (58f4bb0)

1.1.23 (2026-08-11)

Changed

  • reference: the version surfaces move to 2.5.3 (#183) (1288d52)

1.1.22 (2026-08-10)

Changed

  • release: the version surfaces move to 2.5.2 (#181) (aa240b4)

1.1.21 (2026-08-10)

Changed

  • guides: the connect-time guard survives a restart from 2.5.1 (#178) (cee253d)
  • release: the version surfaces and the SSRF caveat move to 2.5.1 (#177) (1668bc0)

1.1.20 (2026-08-10)

Changed

  • architecture: record which of ADR-019's limits coordination settled (#175) (2c86d5f)
  • guides: what the SSRF guard covers, and what a replica set needs installed (#174) (2a5a36d)
  • reference: the reference surfaces 2.5.0 changed (#172) (5e19b40)
  • release: the pages that name a version name 2.5.0 (#173) (a1db213)
  • repo: one changelog file, and release-please writes to it (#171) (1f41794)

1.1.19 (2026-08-10)

Changed

  • guides: point the deepest pages back at the concept behind them (#168) (1849ef0)
  • operations: write down the release surfaces so they stop drifting (#169) (fd0cd9c)
  • reference: regenerate the released-artifacts matrix from GHCR (#165) (352e16f)
  • reference: regenerate the released-artifacts matrix from GHCR (#167) (d03c9a4)
  • security: settle MCP04 and MCP09 against the operator source (#170) (5b7eee5)

1.1.18 (2026-08-09)

Changed

  • discovery source-management Preview + connect-time SSRF + pg pooling (#162) (55f2448)
  • release: advertise mcp-hangar 2.5.0 (#164) (2c51c6d)

1.1.17 (2026-08-08)

Changed

  • reference: the CLI and the source listing say what they do (#159) (54a92fb)
  • release: the upgrade note for 2.5.0 (#160) (b5ff3e7)

1.1.16 (2026-08-08)

Changed

  • guides: the recipes can be run again (#154) (ec5a913)
  • guides: three dead ends that are no longer dead (#158) (2124ff4)
  • reference: remove two knobs nothing reads, and correct a third (#157) (38cc999)
  • reference: the REST reference matches the API (#156) (b07e563)

1.1.15 (2026-08-07)

Changed

  • architecture: ADR-019, one storage decision and two backends (#149) (d028c7d)
  • architecture: the tool catalogue is not a projection, and the tenure is the holder's (#152) (91e0099)
  • architecture: what it takes to run more than one gateway (ADR-020) (#150) (f40558a)
  • guides: running more than one replica, and the config that decides it (#151) (ef1bd42)
  • guides: stop recommending a multi-replica deployment that breaks approvals (#148) (6f0ba55)
  • guides: the recipes a second replica changes (#153) (c0ed65a)
  • release: move the version surfaces to 2.4.0, and write the upgrade note (#146) (d6129f8)

1.1.14 (2026-08-05)

Changed

  • architecture: ADR-018, event sourcing as actually wired (#144) (21326d9)

1.1.13 (2026-08-05)

Changed

  • guides: document extending discovery and the namespace policy move (#140) (0cd084f)
  • guides: install instructions that work, and two claims that did not (#143) (c2822b2)

1.1.12 (2026-08-05)

Changed

  • guides: document the changelog-fragment convention (#138) (80e8be4)

1.1.11 (2026-08-04)

Changed

  • guides: renumber the upgrade note to 2.3.0 and add the launcher removal (#136) (922687a)

1.1.10 (2026-08-04)

Changed

  • architecture: lock_hierarchy moved to the shared kernel (#135) (004a48a)
  • reference: regenerate the released-artifacts matrix from GHCR (#130) (63f4b60)
  • release: move the version surfaces to core 2.2.1 (#131) (53fbbaa)
  • upgrade: add the 2.2.2 note for the event-sourcing auth store (#134) (faeae19)

1.1.9 (2026-08-03)

Changed

  • reference: document the 2.2.0 upgrade and correct the role table (#128) (dbe14b6)

1.1.8 (2026-08-01)

Changed

  • guides: state what argument secret-pattern scanning does not catch (#126) (2e7e30e)

1.1.7 (2026-08-01)

Changed

1.1.6 (2026-08-01)

Changed

  • reference: document the approval gate and move version surfaces to 2.1.0 (#122) (f94c218)

1.1.5 (2026-07-31)

Changed

  • release: move the version surfaces to core 2.0.1 (#120) (ea185a4)

1.1.4 (2026-07-31)

Changed

  • guides: correct the RBAC role table against roles.py (#119) (43809ef)
  • guides: fix the API paths and framing that reach AI consumers verbatim (#118) (dec9824)
  • reference: fix what the first 2.0.0 pass missed (#116) (62b75d9)
  • reference: move the compatibility matrix onto the 2.0.0 line (#115) (7915ceb)
  • reference: regenerate the released-artifacts matrix from GHCR (#114) (57f6956)
  • reference: the chart that installs 2.0.0 exists now (#117) (daf8f1c)
  • release: move the documentation to 2.0.0 (#112) (5de8fea)

1.1.3 (2026-07-29)

Changed

  • architecture: add ADR-016 and the approval adapter guide (#109) (c8308f3)
  • architecture: add ADR-017 on the approval input-request namespace (#111) (f72dad8)

1.1.2 (2026-07-28)

Changed

  • architecture: record that the Tasks wire is vendored, not taken from the SDK (#99) (80b13bc)
  • guides: bring the governed-tasks pages back to what actually ships (#101) (15121d4)
  • guides: move to 2.0.0rc3 and retire the gap warnings (#104) (3fcceb3)
  • guides: record that the task relay is on by default again (#102) (50025f0)
  • guides: stop the tasks pages contradicting themselves and the artifact (#103) (bb2b245)
  • reference: move the version surfaces to 1.6.3 and fix a dead anchor (#106) (5d3d2a8)
  • reference: the compatibility matrix still named the rc.1 candidate (#105) (781f8d4)

1.1.1 (2026-07-27)

Changed

  • reference: move the version surfaces to core 1.6.2 and the 2.0.0rc1 candidate (#92) (9e7262f)
  • reference: resync the artifact matrix after both charts published (#94) (e36926b)

1.1.0 (2026-07-26)

Added

  • guides: renovation phase 1 — truth-now docs for 1.6.0 (#87) (2543475)
  • guides: renovation phase 2 — governed tasks guide + v2 preview notes (#88) (ef58f40)

Fixed

  • release: drop stale pre-v0.14.0 release caveats (#89) (d0adc57)

Changed

  • accuracy/currency review — align content to the current project state (cb72bd6)
  • adr-014: record task-relay activation (2026-07-22) (#86) (743a820)
  • adr: ADR-013 egress policy enforcement model (MCPEgressPolicy) (#72) (8e2480d)
  • adr: amend ADR-009 with the prerelease / pre-GA branch lane (#77) (ba4749e)
  • architecture: add ADR-012 (interceptor SEP-pin tracking policy) (#70) (6ac3f1d)
  • architecture: add ADR-014 (tasks relayed with governance, partially supersedes ADR-008) (#78) (1aaa1a6)
  • architecture: correct ADR-009 amendment — prereleases publish to prod PyPI (#85) (37f4288)
  • architecture: ratify ADR-014 (Proposed -> Accepted) (#79) (469e5ac)
  • bump version surfaces to core 1.6.1 + v2 preview 2.0.0a2 (#90) (347a21c)
  • currency pass — v0.14.0 L7 delivery, release matrix, rebuilt architecture overview (8ca8381)
  • guides: add the MCPEgressPolicy egress policy guide (#73) (fda8656)
  • guides: reflect the 1.6.0 observability/semconv changes (#76) (5dfd3fb)
  • guides: refresh MCPEgressPolicy guide for the completed feature (#74) (2df3798)
  • reference: add operational runbooks for the shipped alerts (#75) (a06dd93)
  • strip 'enterprise' tier/marketing framing (no paid tier) (e046c8c)

1.0.4 (2026-07-18)

Changed

  • architecture: add ADR-011 (single source of truth for cross-repo facts) (#68) (ae530b5)
  • guides: fix stale github.io helm-repo refs to OCI + add domain-lint (ADR-011) (#69) (cd9360e)
  • reference: add OWASP MCP Top 10 coverage page (#66) (a01ce74)

1.0.3 (2026-07-18)

Changed

  • architecture: add ADR-010 retiring the agent + Hangar Cloud tier (#52) (858c173)
  • reference: add EU AI Act / SOC 2 compliance posture doc (#55) (b5fd9d9)
  • reference: generate the released-artifacts matrix + immutable-tags status (Track 2) (#56) (c52fd54)
  • reference: update compatibility matrix to core 1.5.1 (#53) (fb1cace)
  • release: correct the chart install status and record mutable chart tags (#46) (2bd19ff)
  • repo: retire hangar-agent / Hangar Cloud references (#51) (91561fd)

1.0.2 (2026-07-16)

Changed

  • guides: correct contributing and git-flow for the multi-repo topology (#44) (ed5a858)
  • reference: document event_store fail-fast and non-loopback auth requirement (#42) (1fe2671)
  • release: record the validated kubernetes range and the chart install status (#45) (6bfb7aa)

1.0.1 (2026-07-15)

Changed

  • reference: document the config.yaml command-bus rate_limit block (1.5.0) (#40) (49768f3)

1.0.0 (2026-07-15)

Added

  • content: migrate public docs from mcp-hangar/docs/ (0e4232f), closes #2

Changed

  • architecture: add ADR-008 -- task governance is relay-only (#12) (9321f43)
  • architecture: draft ADR-009 independent release topology (#32) (cf5c4de)
  • content: document mcp-hangar 1.3.0 (710b29a)
  • cookbook: add 1.3 digest pinning upgrade recipe (a3832ce)
  • cookbook: add interceptor discovery recipe (73e8d08)
  • guides: add a progressive deployment playbook (#23) (9f21a91)
  • guides: add external multi-tenant OIDC front door cookbook (#26) (982bbe2)
  • guides: add local dev and staging deployment profiles cookbook (#25) (20f3cb0)
  • guides: add production read-only and controlled-write boundaries cookbook (#24) (71c5248)
  • guides: cookbook harden a public authenticated MCP gateway (#29) (37b7172), closes #21
  • guides: correct rate-limit scope in cookbook 06 (#15) (c20f65a)
  • guides: document mcp-hangar 1.4.0 and add 1.4 cookbooks (#8) (9cda48c)
  • guides: fix drifted cookbook recipes against 1.4.0 source (#9) (9591ffc)
  • guides: fix duplicated recipe numbers in cookbook 21 and 22 (#31) (a52521f), closes #30
  • guides: use mcp-hangar as the Kubernetes namespace in examples (#36) (62d9806)
  • release: add 1.5.0 upgrade notes, CLI auth command, and compatibility matrix (#39) (57bbe9b)
  • release: add release compatibility and GHCR security policy (#33) (08a41c9)
  • release: add Releases & Artifacts install index (#11) (6808a91)
  • release: correct the core image as signed (it already is) (#38) (3483627)
  • release: record cosign signing done; all artifacts signed (#37) (27b75b7)
  • release: record verified Helm chart releases; all lanes published (#35) (ef65e84)
  • release: record verified operator and agent image releases (#34) (18aba8c)
  • sync with mcp-hangar source, document 1.3.0, add drift validation (#7) (45bef08)