🎉 Release v0.22.19
📦 Docker Images
# Docker Hub
docker pull agigante80/actual-mcp-server:0.22.19
# GitHub Container Registry
docker pull ghcr.io/agigante80/actual-mcp-server:0.22.19⚠️ Upgrade note
actual_rules_update, actual_rules_create_or_update and actual_payees_update (its category field) now refuse a category, payee or account id that does not exist, as actual_rules_create has since v0.22.17. Only ids the call introduces are checked, so a rule that already holds a dangling id can still be edited. actual_payees_update refuses before changing anything, including the name. actual_rules_update on an unknown rule id now returns a typed not-found error. link-schedule values and category_group conditions are still not checked. (#522)
actual_transactions_update_batch now stops at the first infrastructure error (for example a dropped connection) instead of recording it as a per-item failure, and reports which ids were applied, which failed, which one has an unknown outcome and how many were not attempted. (#521)
📝 Changelog
- chore(release): bump version to 0.22.19 (ef52961)
- test(dotenv): pin every dotenv option at the runner and direct-sync callers, tighten the harness (#505) (b438247)
- fix(adapter): extend the rule reference guard to every rule write (#522) (f9051c6)
- test(guards): harden the toolsets side-effect scan, single-dispatch check and dotenv guard (#533) (6a39f8c)
- test(http): harden the batch-cap source guards against comment and substring matches (#503) (dbb975f)
- fix(adapter): updateTransactionBatch aborts on infrastructure errors (#521) (a4b7fa1)
- test(rules): pin batch result order, relabel rate-limit check, reconcile manual-prompt counts (#524) (f2b46f4)
- chore: #516 review follow-ups, audit note, month tests, read-once labels, E2E id, one warn (#523) (a74a457)
- refactor(toolsets): fail-closed refusal, read-only reason first, tests that can fail (#525) (2f5e7ed)
- feat(observability): log MCP transport errors via server.onerror (#504) (c2d8e88)
- test(helpers): shared comment stripper for source guards (#532) (b66d6f0)
- test(auth): add the both-lists-set boot cases for OIDC_SCOPES_SUPPORTED (#487) (3a811c3)
- test(manual): run batch_uncategorized_rules_upsert cleanup in finally (#519) (c46b8a0)
- fix(tools): apply #486 review follow-ups to budget test, query_run text, schema checks (#526) (1e28e48)
- feat(stdio): keep pre-logger console output off stdout under --stdio (#502) (4438671)
- test(docs-guard): node target check skips leading flags and -- (#499) (1f2fc67)
- docs(plans): reorder Review follow-up hardening after the phase review (bfe946a)
- docs(plans): name the transport eviction follow-up ticket (7138513)
- docs(roadmap): open the Review follow-up hardening phase (b86ee8f)
📊 What this release ships
@actual-app/apipinned at26.10.0- All 83 MCP tools registered and validated on this tag
🔒 Security
This release has been scanned for vulnerabilities. Check the Security tab for details.
Full Changelog: v0.22.18...v0.22.19