github openai/tunnel-client v0.0.16

4 hours ago

v0.0.16 adds MCP response timing and optional trace context forwarding, and updates OpenTelemetry dependencies.

What's changed

  • MCP response timing: Reports optional resp_timing metadata for measured terminal MCP results and errors over stdio and Streamable HTTP. The duration includes downstream transport, MCP server work, SDK processing, and stream backpressure; it does not isolate server execution time. Existing end-to-end latency remains available.
  • Opt-in distributed tracing: Adds --mcp.forward-trace-context, MCP_FORWARD_TRACE_CONTEXT, and mcp.forward_trace_context. Valid W3C traceparent and tracestate are forwarded in MCP request params._meta over stdio and Streamable HTTP. Forwarding defaults to false in all three runtime flavors, preserves caller-owned trace context, adds no baggage, and does not inject HTTP headers.
  • Dependency security update: Updates the stable OpenTelemetry modules from 1.41.0 to 1.43.0, the patched SDK version for CVE-2026-39883 / GHSA-hfvc-g4fc-pqhx. This advisory concerns local PATH hijacking in BSD/Solaris host-ID detection. Matching SPDX baselines and license reports are updated.

Upgrade notes

Timing requires no customer MCP server changes. Legacy clients can continue omitting timing.

Trace forwarding remains opt-in, and the MCP server must consume request metadata to connect its traces. Before downgrading to a client that lacks this option, remove its YAML key and CLI flag; older clients reject unknown configuration keys and flags. See the configuration and compatibility guidance.

Downloads

The release includes tunnel-client, tunnel-client-runtime, and tunnel-client-runtime-cloudflared ZIP bundles for Linux, macOS, and Windows on amd64 and arm64, with matching SPDX documents and license reports. Use SHA256SUMS.txt and tunnel-client-v0.0.16-provenance.sigstore.json to verify downloaded artifacts; the release also includes source exports and vulnerability evidence. See the release verification instructions.

Full Changelog: v0.0.15...v0.0.16

Don't miss a new tunnel-client release

NewReleases is sending notifications on new releases.