Summary
Patch since v2.0.1: bumps the MCP Go SDK to address GHSA-q382-vc8q-7jhj, and adds in-repo agent skills for maintainers (Cursor / Claude Code).
Security
- GHSA-q382-vc8q-7jhj — Improper handling of null Unicode character when parsing JSON in
github.com/modelcontextprotocol/go-sdk(affected ≤ v1.4.0). This release bumpsgithub.com/modelcontextprotocol/go-sdkto v1.4.1 (#268), which pulls in the fixedgithub.com/segmentio/encodingv0.5.4 per upstream guidance.
Internal / repository
- Agent skills for CLI releases:
skills/hookdeck-cli-release/, symlinks under.cursor/skillsand.claude/skills,CLAUDE.md, and relatedAGENTS.md/ README pointers (#272). No change to shipped CLI behavior for end users beyond the dependency update above.
Full Changelog: v2.0.1...v2.0.2