Version Packages - #509
Merged
Merged
Version Packages#509
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release the merged MCP security fixes together with the pending SDK, schema, and Viewer changes. This batch was regenerated with the repository’s Changesets command from current main; the protected version branch was updated through normal signed commits.
Releases
@transloadit/mcp-server@0.3.34
Patch Changes
10febdc: Restrict MCP file inputs to base64 and URLs, and require public HTTP(S) targets for server-side
downloads. Local filesystem path inputs are no longer supported in hosted or self-hosted MCP;
upload local files with
npx -y @transloadit/node uploadinstead.Validate Assembly references and resolve them through the configured API endpoint so MCP callers
cannot redirect authenticated status, wait, or resume requests to arbitrary hosts. Resume uploads
from public URL inputs without requiring the original Assembly Instructions.
Add the SDK's
followRedirectsoption (defaulting totrue) and disable API redirects in MCP,including responses for Assemblies configured with
redirect_url.b1fb7d3: Default image generation to OpenAI Images 2.5 Flare and expose Images 2.5 Sunburst as an explicit precision option. Existing explicit OpenAI and Google model selections are preserved. Add Claude Opus 5.5 image/PDF capabilities to the shared Robot schemas while retaining Opus 5 and Fable 5.1.
be56c7f: Request server-generated image placeholders with
storeImage(..., { placeholder: 'blur' })or
storage store --placeholder blur, without adding a native image decoder to the SDK.Extraction is optional and best-effort; successful extraction adds metadata usage equal to 20%
of the file's bytes. Omission performs no extraction.
Preserve
thumbhashandhas_alphain Storage receipts, native asset reads, Assembly recovery,batch results and catalog sync. Viewer remains alpha and accepts server alpha metadata as well
as older
hasAlphacatalogs. Private request-authorized delivery still omits inline preview pixels.Hashed upload replays never overwrite or re-upload an image to generate missing metadata.
Release MCP alongside the SDK to keep its validated dependency versions aligned.
Updated dependencies [10febdc]
Updated dependencies [b1fb7d3]
Updated dependencies [be56c7f]
@transloadit/node@4.14.0
Minor Changes
b1fb7d3: Default image generation to OpenAI Images 2.5 Flare and expose Images 2.5 Sunburst as an explicit precision option. Existing explicit OpenAI and Google model selections are preserved. Add Claude Opus 5.5 image/PDF capabilities to the shared Robot schemas while retaining Opus 5 and Fable 5.1.
be56c7f: Request server-generated image placeholders with
storeImage(..., { placeholder: 'blur' })or
storage store --placeholder blur, without adding a native image decoder to the SDK.Extraction is optional and best-effort; successful extraction adds metadata usage equal to 20%
of the file's bytes. Omission performs no extraction.
Preserve
thumbhashandhas_alphain Storage receipts, native asset reads, Assembly recovery,batch results and catalog sync. Viewer remains alpha and accepts server alpha metadata as well
as older
hasAlphacatalogs. Private request-authorized delivery still omits inline preview pixels.Hashed upload replays never overwrite or re-upload an image to generate missing metadata.
Release MCP alongside the SDK to keep its validated dependency versions aligned.
Patch Changes
10febdc: Restrict MCP file inputs to base64 and URLs, and require public HTTP(S) targets for server-side
downloads. Local filesystem path inputs are no longer supported in hosted or self-hosted MCP;
upload local files with
npx -y @transloadit/node uploadinstead.Validate Assembly references and resolve them through the configured API endpoint so MCP callers
cannot redirect authenticated status, wait, or resume requests to arbitrary hosts. Resume uploads
from public URL inputs without requiring the original Assembly Instructions.
Add the SDK's
followRedirectsoption (defaulting totrue) and disable API redirects in MCP,including responses for Assemblies configured with
redirect_url.transloadit@4.14.0
Minor Changes
b1fb7d3: Default image generation to OpenAI Images 2.5 Flare and expose Images 2.5 Sunburst as an explicit precision option. Existing explicit OpenAI and Google model selections are preserved. Add Claude Opus 5.5 image/PDF capabilities to the shared Robot schemas while retaining Opus 5 and Fable 5.1.
be56c7f: Request server-generated image placeholders with
storeImage(..., { placeholder: 'blur' })or
storage store --placeholder blur, without adding a native image decoder to the SDK.Extraction is optional and best-effort; successful extraction adds metadata usage equal to 20%
of the file's bytes. Omission performs no extraction.
Preserve
thumbhashandhas_alphain Storage receipts, native asset reads, Assembly recovery,batch results and catalog sync. Viewer remains alpha and accepts server alpha metadata as well
as older
hasAlphacatalogs. Private request-authorized delivery still omits inline preview pixels.Hashed upload replays never overwrite or re-upload an image to generate missing metadata.
Release MCP alongside the SDK to keep its validated dependency versions aligned.
Patch Changes
10febdc: Restrict MCP file inputs to base64 and URLs, and require public HTTP(S) targets for server-side
downloads. Local filesystem path inputs are no longer supported in hosted or self-hosted MCP;
upload local files with
npx -y @transloadit/node uploadinstead.Validate Assembly references and resolve them through the configured API endpoint so MCP callers
cannot redirect authenticated status, wait, or resume requests to arbitrary hosts. Resume uploads
from public URL inputs without requiring the original Assembly Instructions.
Add the SDK's
followRedirectsoption (defaulting totrue) and disable API redirects in MCP,including responses for Assemblies configured with
redirect_url.@transloadit/types@4.5.0
Minor Changes
be56c7f: Request server-generated image placeholders with
storeImage(..., { placeholder: 'blur' })or
storage store --placeholder blur, without adding a native image decoder to the SDK.Extraction is optional and best-effort; successful extraction adds metadata usage equal to 20%
of the file's bytes. Omission performs no extraction.
Preserve
thumbhashandhas_alphain Storage receipts, native asset reads, Assembly recovery,batch results and catalog sync. Viewer remains alpha and accepts server alpha metadata as well
as older
hasAlphacatalogs. Private request-authorized delivery still omits inline preview pixels.Hashed upload replays never overwrite or re-upload an image to generate missing metadata.
Release MCP alongside the SDK to keep its validated dependency versions aligned.
Patch Changes
@transloadit/zod@4.5.0
Minor Changes
be56c7f: Request server-generated image placeholders with
storeImage(..., { placeholder: 'blur' })or
storage store --placeholder blur, without adding a native image decoder to the SDK.Extraction is optional and best-effort; successful extraction adds metadata usage equal to 20%
of the file's bytes. Omission performs no extraction.
Preserve
thumbhashandhas_alphain Storage receipts, native asset reads, Assembly recovery,batch results and catalog sync. Viewer remains alpha and accepts server alpha metadata as well
as older
hasAlphacatalogs. Private request-authorized delivery still omits inline preview pixels.Hashed upload replays never overwrite or re-upload an image to generate missing metadata.
Release MCP alongside the SDK to keep its validated dependency versions aligned.
Patch Changes
@transloadit/viewer@0.0.2
Patch Changes
be56c7f: Request server-generated image placeholders with
storeImage(..., { placeholder: 'blur' })or
storage store --placeholder blur, without adding a native image decoder to the SDK.Extraction is optional and best-effort; successful extraction adds metadata usage equal to 20%
of the file's bytes. Omission performs no extraction.
Preserve
thumbhashandhas_alphain Storage receipts, native asset reads, Assembly recovery,batch results and catalog sync. Viewer remains alpha and accepts server alpha metadata as well
as older
hasAlphacatalogs. Private request-authorized delivery still omits inline preview pixels.Hashed upload replays never overwrite or re-upload an image to generate missing metadata.
Release MCP alongside the SDK to keep its validated dependency versions aligned.
Viewer remains alpha and will be published with its alpha npm tag and a prerelease GitHub release.