## IBM/mcp-context-forge — v1.0.10…v1.0.11

_58 commits._

### Features
- **feat(plugins): migrate output length guard to Rust-backed CPEX package (#6846)** (9c02a8e)
- **feat: return per-caller OAuth token status from /oauth/status (#6620)** (f4b2055)
- **Enable cross-provider SSO account linking** — Added a new SSO_ALLOW_PROVIDER_LINKING setting (disabled by default) that lets users sign in with different SSO providers using the same verified email address. When enabled, an existing account is rebound to the new provider instead of being rejected; admin status is re-verified against the new provider to prevent privilege carryover. (f625315)
- **feat: Add tool preview endpoint (#6443)** (1b19c29)
- **feat: seed OAuth discovery metadata into mcp-catalog.yml (#6613)** (28bb0d3)
- **feat: support passwordless SSO-only users safely (#6603)** (221bd7b)
- **feat(teams): expose search_query filter on GET /v1/teams/ (#6652)** (cc6cae4)

### Fixes
- **Fix/truncation on large responses (#6200)** (d490d6a)
- **fix: isolate tool lookup cache across tenant scopes (#6968)** (a70c870)
- **fix: correct tool argument name in vault A2A-wrapped MCP tool test (#6967)** (7556108)
- **fix(tools): return MCP-compliant error responses for tool execution failures (#6181)** (525dad1)
- **fix: make MAX_HEADER_VALUE_LENGTH configurable via environment variable (#6654)** (9cf069c)
- **fix(tools): preserve empty dict in structuredContent handling (#6182)** (1023976)
- **fix: use shared HTTP client, add bounded spec cache with DNS-pinning and single-flight (#6933)** (2e68fb5)
- **fix(ui): handle object types in anyOf/oneOf schemas (#6421)** (9c87881)
- **fix(tests): allow real DNS passthrough for external IdP integration tests (#6797)** (3f53879)
- **fix: require explicit allowlist for CORS origin reflection (#6941)** (a17fd40)
- **fix: isolate async gateway audit sessions (#6455)** (1950bcb)
- **fix: persist CPEX deny-path control telemetry (#6806)** (03a0662)
- **Fix OAuth team scope resolution for missing or malformed token_teams (#6004)** (0da8673)
- **fix(catalog): normalize icon visual weight and strip pale badge surrounds (#6852)** (0b79a08)
- **fix: normalise auth_type spelling drift in mcp-catalog.yml (#6795)** (ee23b72)
- **Fix paginated mcps just showing the first page (#6809)** (34dda88)
- **fix(rust): upgrade rustls to 0.23.45 and chacha20 to 0.10.2 (#6831)** (33fa80e)
- **fix(devex): prevent package-lock.json mutation during local dev/serve runs (#6782)** (2af962a)
- **fix: discover catalogs from empty MCP capabilities (#6758)** (732d791)
- **fix: persist OAuth credentials on catalog server registration (#6588)** (aeb2fbd)
- **fix(gateways): persist health-check failure reason (#6368)** (b8925ed)
- **fix: expose APP_DOMAIN-derived url on ServerRead (#6656)** (e6ee61f)
- **Fix admin bootstrap password lockout** — Headless deployments (Kubernetes, Docker, CI) that set a custom PLATFORM_ADMIN_PASSWORD can now bootstrap without being locked out. The forced password-change requirement is now skipped when a custom password is provided, since the operator has already chosen a strong credential. Login errors now include a helpful hint for operators who are already locked out. (b13ebe4)
- **Improve resource error handling** — Fixed the system to properly distinguish between upstream fetch failures and empty resource content, and added better error handling for resource retrieval. Now when resources fail to load from upstream servers or contain invalid data, the API returns a 400 error instead of treating it as a 404 not found. (b9450be)
- **fix(security): harden SSO/SIEM against stored XSS (#5856) (#6615)** (aa12caf)
- **fix: implement IBM_VERIFY_GROUP_MAPPING for SSO team mapping (#6610)** (3865378)
- **fix(helm): fix OCP PGO deployment failures on fresh clusters (#6196)** (63d69ab)
- **fix(sso): flatten dict-shaped groups/roles claims in SSO normalization (#6427)** (e004fe0)
- **fix pw tests (#6572)** (d3dcd2f)

### Backend
- **Release/v1.0.11 (#6986)** (077071b)
- **Chore/mcp sdk v2 (#6868)** (7e3526b)
- **pinned cpex version to 1.0.3 (#6791)** (105a6d7)
- **Update security scan configuration** — Updated the Mend security scanning configuration to use Python 3.12 (aligned with project dependencies), changed the scan update mode from OVERRIDE to APPEND, added the project name, and configured the scanner to only resolve dependencies from pyproject.toml to avoid picking up unrelated requirement files. (b9027c7)
- **update release documentation (#6764)** (0a8d381)

### Tests
- **test: fix RBAC deny tests that swallow AssertionError (#6874)** (af4eeca)
- **test: add gateway registration and tool sync E2E coverage (#6848)** (11e1468)
- **test: add team lifecycle coverage to the live E2E suite (#6844)** (3268e63)
- **test(e2e): add token lifecycle coverage (#6838)** (bbff7d3)
- **test: verify E2E cross-replica consistency (#6804)** (6f42c34)
- **test: add user lifecycle coverage to the live E2E suite (#6833)** (5d01089)
- **test: add E2E virtual server lifecycle coverage (#6792)** (55e084f)
- **test: consolidate live MCP E2E suites (#6786)** (0896a3e)

### Docs
- **docs: document API-to-product vocabulary mapping (gateway/server → MCP server/virtual server) (#6770)** (380469f)
- **docs: adopt agent prose and clean code standards (#6803)** (5658bc3)
- **docs: correct incorrect package and image references in ADR-025 and altk README (#6788)** (3dfdd5e)
- **docs: fix IBM Cloud Code Engine deployment guide missing env secret (#6290)** (8d567c5)

### Chore
- **ci: preserve colors in conformance output (#6851)** (a1f380f)
- **ci: run legacy-to-legacy conformance with verified baselines (#6512)** (525413d)
- **ci: align coverage thresholds to 90% to match Makefile (#6801)** (034746c)
- **chore: align publisher schema with dataplane API (#6718)** (d104bf8)
- **chore: remove stdio wrapper in favor of FastMCP (#6201)** (5273986)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/IBM/mcp-context-forge?utm_source=github-action)._