## smart-mcp-proxy/mcpproxy-go — v0.69.0…v0.70.0-rc.1

_81 commits._

### Features
- **feat(attention): Spec 108 warnings as attention kinds, profile scope on Servers and row links (Spec 109-l) (#1457)** (1a5044f)
- **feat(web): profile scope on Tools, Activity, Sessions and Usage (Spec 108-j) (#1448)** (9bff2f3)
- **feat(macos): profiles, client bindings, token profile, scoped views and explainer (Spec 108-k) (#1442)** (1628eeb)
- **feat(web): profiles, client bindings, token profile, explainer and Viewing chip (Spec 108-i) (#1444)** (571027c)
- **feat(mcp): profiles admin tool (Spec 108-h) (#1443)** (9031f9d)
- **feat(cli): profile, client binding and access explain commands (Spec 108-g) (#1441)** (a2815c1)
- **feat(api): profiles and clients REST surface, config funnel and access explainer (Spec 108-f) (#1439)** (337eecf)
- **feat(profiles): scope attribution and profile/client/token filters (Spec 108-e) (#1436)** (d463668)
- **feat(connect): per-client credentials, bindings service and connect guard (Spec 108-c2) (#1430)** (748e6ed)
- **feat: grouped sidebar, compact header, command palette and Add menu (Spec 109-i) (#1427)** (07554c6)
- **feat: forward allowlisted MCP client headers to upstreams (Spec 112) (#1426)** (400620e)
- **feat(clients): add unified clients hub (#1414)** (4807b21)
- **feat: add review queue UI (#1413)** (4ecc5bb)
- **feat(profile): enforce profile policy on every execution surface (Spec 108-d) (#1411)** (acfd057)
- **feat(catalog): add real popularity signal (Spec 110) (#1408)** (b95d09e)
- **feat(profile): discovery enforcement — hidden_by_profile, policy-aware search (Spec 108-b) (#1390)** (6e1615c)
- **feat(web,macos): one server-card status line + primary action (Spec 109-e) (#1381)** (59282da)
- **feat(attention): one needs-attention list for every surface (Spec 109-d) (#1382)** (1167208)
- **feat(ui): onboarding and Connect wizard hints across surfaces (Spec 109-b) (#1377)** (a045060)
- **feat(catalog): catalog-first Add Server across all surfaces (Spec 109-j) (#1383)** (4c002c3)
- **feat(auth,server): client-credential token model and dispatch gating (Spec 108-c) (#1389)** (74df81e)
- **feat(ui): activity scope filters, views and deep links (Spec 109-k) (#1385)** (fad8c67)
- **feat(index): versioned Bleve mapping with automatic migration and a real RebuildIndex (#1386)** (03ab4a3)
- **feat(health): status vocabulary across surfaces (Spec 109 FR-010-012) (#1376)** (281b5c8)
- **feat(profile): v3 policy fields + FR-009a rollout gate (Spec 108-a) (#1380)** (fe1c15c)
- **feat(ui): navigation, review and tool-tier quick wins (Spec 109-a) (#1378)** (a15dc2a)

### Fixes
- **fix: first-run docs, changelog, upgrade-start log noise and set_profile reach (#1482)** (a1101fb)
- **fix(review): review screen starts fail-closed with exact-count approve (Spec fix-review-defaults) (#1481)** (335477e)
- **fix: telemetry opt-out shown as effective state; macOS Settings names the connected core (Spec fix-usertest-telemetry-macos) (#1471)** (8e5ccd3)
- **fix: first-run user test findings in setup import, secrets, status pill and profile Try it (Spec fix-usertest-web) (#1473)** (a348403)
- **fix(profiles): nested refusal block_reason and explain move-client hint (Spec fix-nested-refusal) (#1468)** (a25f887)
- **fix(cli): redact doctor credentials, honour global -c/-d, print errors once, explain locked set_profile (Spec fix-usertest-cli) (#1472)** (a828c54)
- **fix(review): honest scan banner and approved-state review screen (Spec fix-review-screen) (#1470)** (7b96899)
- **fix(catalog): search ranks the real server first against the live registry (Spec fix-catalog-rank) (#1469)** (33a9607)
- **fix: Home estimate label, Get started card, Activity conflict clear and status-coloured health (Spec fix-ux-residuals) (#1467)** (10463f8)
- **fix(security): keep implicit quarantine across server restarts and config writes (Spec fix-quarantine-restart) (#1463)** (d7efa80)
- **fix: demo UX findings across catalog, settings, palette and profiles (Spec demo-ux-fixes) (#1464)** (fea45c4)
- **fix(runtime): reconcile profile search indexes on every profile change (Spec fix-1458) (#1459)** (355f523)
- **fix(profiles): close post-merge review gaps in connect rotation, offline guard, preview, attribution and CLI hints (Spec 108-retro-go) (#1454)** (e2da459)
- **fix(runtime): make quarantined capture replacement tests deterministic (Spec fix-1453) (#1455)** (542143f)
- **fix(macos): forget outcome, Try it on new profiles, reload, assign mode, settings edits, upgrade preview, toolbar add (Spec 108-retro-mac) (#1452)** (3ad5a87)
- **fix(mcp): declare call_tool_* args and code_execution input/options as open objects (#1434)** (c8fd39e)
- **fix(ux): close Spec 109 leftovers (labels, review links, help cross-refs, presence tests) (Spec 109-leftovers) (#1428)** (d7fb022)
- **fix(catalog): preserve catalog identity and reject unsupported filters (Spec 109-j) (#1425)** (08e1685)
- **fix(tray): drop stale out-of-order attention refreshes and harden tray tests (#1422)** (0bae8ff)
- **fix(catalog): address Spec 109-j review follow-ups (#1424)** (5173b13)
- **fix(catalog): emit added_server_name from CLI and retire legacy AddServerModal (#1416)** (4d00f89)
- **fix(health): carry health through legacy servers fallback, tighten vocabulary tests (#1423)** (5f7ac3c)
- **fix(registries): keep bbolt eviction off the popularity mutex and close test gaps (#1418)** (83e7906)
- **fix(profile): make glob '*' match newlines so deny rules cannot fail open (#1420)** (eede497)
- **fix(connect): resolve remaining low findings from #1377 review (#1421)** (27d935d)
- **fix(storage): correct client-credential stage error and make forget atomic (#1419)** (e196a0d)
- **fix(web): keep shell mounted and dedupe loads during auth recovery (#1417)** (ad9fbc2)
- **fix(review): backend review queue and guarded approvals (Spec 109-f) (#1412)** (2c7220f)
- **fix(ui): preserve Activity session filter in exports (Spec 109-k) (#1409)** (0c5976e)
- **fix(catalog): restore catalog add and open flows (Spec 109-j) (#1400)** (4e32ac3)
- **fix(catalog,cli): MCP secret_like parity + upstream add --config flag (#1397)** (565408e)
- **fix(web): resolve authentication before loading the UI (Spec 107/109) (#1399)** (a93be0a)
- **fix(web-ui): offer Login on quarantined servers that need OAuth sign-in (#1366)** (01ccfdf)
- **fix(ui,import): skip self-referencing import candidates; refresh server tools after approval (#1365)** (aa1f772)
- **fix(tray,doctor): offer sign-in for quarantined OAuth servers (#1367)** (8b17d0f)
- **fix(release): attach Sparkle enclosures in retry-sign-release (#1363)** (638fa80)

### Tests
- **test(parity): cross-surface parity, traceability and docs (Spec 109-m) (#1461)** (b3191a0)
- **test(profiles): parity, acceptance checks, docs and release notes (Spec 108-l) (#1456)** (bbf8016)
- **test(profile): close enforcement test gaps in merged 108-a/b/d (Spec 108-bd-tests) (#1429)** (6a25a92)
- **test(scope): guard the /api/v1 GET surface against unscoped routes (#1178) (#1351)** (cec19dd)
- **test(mcp): add search_servers secret:false negative control (#1415)** (4ddd29e)

### Docs
- **docs(specs): Spec 108 Profiles v3 and Spec 109 UX navigation and consistency (#1379)** (b685b2d)

### Chore
- **chore(deps): bump @types/node from 26.6.2 to 26.6.3 in /e2e/playwright in the e2e-playwright-dependencies group (#1478)** (d46b159)
- **chore(deps-fixtures): bump @modelcontextprotocol/sdk from 1.30.0 to 1.31.0 in /tests/malicious-mcp-server in the malicious-mcp-fixture-dependencies group (#1480)** (08c2758)
- **chore(ci): bump the codeql-action group with 4 updates (#1475)** (0a86a0e)
- **chore(deps): bump the frontend-dependencies group in /frontend with 9 updates (#1474)** (94d9d43)
- **chore(deps-fixtures): bump @modelcontextprotocol/sdk from 1.30.0 to 1.31.0 in /tests/echo-rugpull-server in the echo-rugpull-fixture-dependencies group (#1479)** (a1f413f)
- **chore(ci): bump cloudflare/wrangler-action from 4.0.0 to 4.1.3 (#1476)** (4a682e7)
- **chore(ci): bump orhun/git-cliff-action from 4.9.0 to 4.9.1 (#1374)** (065d8f3)
- **chore(ci): bump codecov/codecov-action from 7.0.0 to 7.1.1 (#1372)** (dde1432)
- **chore(ci): bump the codeql-action group with 4 updates (#1371)** (a97ff0c)
- **chore(ci): bump astral-sh/setup-uv from 10.1.0 to 10.2.0 (#1373)** (cb96844)
- **chore(deps): bump the frontend-dependencies group (#1370)** (81227a8)
- **chore(deps): bump @types/node (#1369)** (83c11d0)
- **ci(release): add post-release jobs + notice prepend to retry-sign-release (#1361)** (f1a30f7)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/smart-mcp-proxy/mcpproxy-go?utm_source=github-action)._