Repository navigation
release: 0.10.1 - #56
Merged
Merged
Conversation
A patch release for one reported bug and the blindness that let it hide. 0.10.0 shipped a `verify` extra containing semgrep, which hard-pins `mcp==1.29.0`; installing the verification layer downgraded a user's mcp from 2.1.0 and broke unrelated tooling. semgrep was never imported by this project, only spawned, so it moves to its own `taint` extra with pipx as the documented path. `[verify]` resolves to 15 packages now instead of 68. The second fix is why the first is safe: tool availability was PATH presence, so `capabilities` reported taint fully available on a machine where semgrep could not execute. It probes by running the tool now. `date-released` in CITATION.cff is unchanged: 0.10.0 shipped this morning and this goes out the same day. The Unreleased block is promoted rather than rewritten. A release note typed a second time is a second chance to describe the change differently from the change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Patch release for the bug reported against 0.10.0, plus the blindness that let it hide.
pyproject.toml0.10.0→0.10.1CITATION.cffdate-releasedunchanged, both shipped 2026-08-31CHANGELOG.md[0.10.1]What it fixes
pip install 'cca-audit[verify]'downgraded a user'smcpfrom 2.1.0 to 1.29.0 and broke unrelated MCP tooling. semgrep hard-pinsmcp==1.29.0,ruamel.yaml.clibandpywin32, and it was sitting inverifydespite never being imported by this project:semgrep_check.pyresolves it on PATH and spawns it, exactly likecargo. It moves to its owntaintextra, withpipx install semgrepdocumented as the right install.[verify]now resolves to 15 packages instead of 68.capabilitiesprobes tools by running them. Availability wasresolve_tool(name) is not None, which answers whether a file is on PATH rather than whether it can run. On the reporting machine semgrep resolved fine and died withOSError: [WinError 4551] An Application Control policy has blocked this file, whilecapabilitiesreportedtaintfully available and every taint claim escalated. That fix is what makes removing semgrep fromverifysafe rather than a silent loss of coverage.Note
The changelog block is promoted, not rewritten. A release note typed a second time is a second chance to describe the change differently from the change.
🤖 Generated with Claude Code