1.1.0: validated tool registry, CMR compact output and cursors, FIRMS fix, tested release pipeline - #10
Merged
Conversation
…sors, working FIRMS requests, bounded resources, and a tested release pipeline for 1.1.0
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reliability fixes and CMR improvements for 1.1.0. Baseline:
mainat 8d66b2b, npmlatest= 1.0.14. CI onmainhad been red since 1.0.13 because there were no tests.What changed
Reliability
tools/list, validation and dispatch.tools/call, the legacynasa/*methods,prompts/executeand resource templates.-32602; invalid arguments returnisErrorresults.nasa/apod,nasa/mars-rover,jpl/jd_cal, …) are explicit.nasa/mars-roverwas broken before.sourceandretrieved_at.FIRMS_MAP_KEYand the documented path/api/area/csv/KEY/SOURCE/w,s,e,n/DAYS[/DATE], withbboxas the canonical area.latitude/longitudenow needradius_kmand are converted to a bbox; polar and antimeridian cases are rejected.fetch/FormData.npm audit --omit=devreports 0 vulnerabilities (8 before).buildno longer runsnpm install.prepackguard, so tests,.envand fixtures can't ship.package.json, and stdout carries only MCP messages.CMR (
nasa_cmr)collection_concept_id, geometry, platform/instrument/project, processing level, data format, download/browse/online flags, facets and verified sort keys.bboxis translated tobounding_box(CMR rejectedbboxwith HTTP 400).status,search_type,results,returned_count,total_hitsfromCMR-Hits,next_cursor,source,retrieved_at,warnings.response_mode: "raw"returns the upstream metadata;fieldsselects fields and shapes both the structured and text output.cmr1.+ base64url JSON), versioned, capped at 8 KB and re-validated on decode.{"cursor": …}alone. Conflicting filters, sort or search type are rejected, never silently restarted.page/offsetremain as a deprecated, mutually exclusive compatibility path.JPL / other tools. Every advertised parameter was checked against the live APIs. Ones that never worked now return a migration message: Sentry
date_min/date_max; Scoutorbit_id/summary; Fireballreq_energy/req_impact_e. Scoutplot/filevalues were fixed, and Sentry/Scoutlimitis now applied locally. Other fixes:time_standardwas ignored upstream; it is now sent astime-standard.nstedAPIrejectspsand ignorestop; now uses TAP.Compatibility decisions
response_mode: "raw"alone does not restore the old raw-by-default response.FIRMS_MAP_KEYand an explicit area.global.mcp__*functions and thenasa/subscribeno-op were removed.Test evidence
npm test: 118/118 pass locally on Windows, Node 22.13.1. That is unit tests on local fixtures plus stdio and Streamable HTTP integration tests driven by the MCP SDK client against the real CLI, including a raw stdout contamination check, clean shutdown and 8 concurrent HTTP clients. The stdio integration file ran 15× in a row without a failure after fixing an ordering flake in the test.scripts/package-smoke.mjs), locally on Windows:--versionprints 1.1.0, and 5/5 transport tests pass against the installed bin.total_hitsfromCMR-Hits), cursor-only page 2 with no repeated records, and granules withfields.DEMO_KEY, SBDB, EONET, Exoplanet TAP and CAD all worked.DEMO_KEYrate limiting accurately.--mcp-configand registered all 23 tools. A full model-driven run is pending a Claude Code re-login on the maintainer's machine.FIRMS_MAP_KEYavailable). The deterministic FIRMS tests all pass.Security note
1.0.0–1.0.14 on npm shipped a hard-coded FIRMS MAP_KEY (
dist/tests/direct-api-test.js), and 1.0.0–1.0.12 shippeddist/.envcontaining a NASA API key. Cause:setupEnvironment()copied.envintodist/. Both keys must be rotated by the owner. Git history was not rewritten.Release plan
v1.1.0(annotated) and draft the GitHub Release.release.yml/ environmentnpm-release). The existing local npm tokens return 401, and the 2025NPM_TOKENsecret is not used.gh workflow run release.yml -f tag=v1.1.0 -f dist_tag=next. This re-tests the tag, packs once, runs the package gate, publishes that exact tarball undernextwith provenance, then verifies registry integrity, a fresh install, and the MCP tests on Linux and Windows.npm dist-tag add @programcomputer/nasa-mcp-server@1.1.0 latest. OIDC cannot rundist-tag.latestand a freshnpxrun, then publish the GitHub Release.See RELEASING.md for the full runbook.