v0.0.16 adds MCP response timing and optional trace context forwarding, and updates OpenTelemetry dependencies.
What's changed
- MCP response timing: Reports optional
resp_timingmetadata for measured terminal MCP results and errors over stdio and Streamable HTTP. The duration includes downstream transport, MCP server work, SDK processing, and stream backpressure; it does not isolate server execution time. Existing end-to-end latency remains available. - Opt-in distributed tracing: Adds
--mcp.forward-trace-context,MCP_FORWARD_TRACE_CONTEXT, andmcp.forward_trace_context. Valid W3Ctraceparentandtracestateare forwarded in MCP requestparams._metaover stdio and Streamable HTTP. Forwarding defaults tofalsein all three runtime flavors, preserves caller-owned trace context, adds no baggage, and does not inject HTTP headers. - Dependency security update: Updates the stable OpenTelemetry modules from 1.41.0 to 1.43.0, the patched SDK version for CVE-2026-39883 / GHSA-hfvc-g4fc-pqhx. This advisory concerns local PATH hijacking in BSD/Solaris host-ID detection. Matching SPDX baselines and license reports are updated.
Upgrade notes
Timing requires no customer MCP server changes. Legacy clients can continue omitting timing.
Trace forwarding remains opt-in, and the MCP server must consume request metadata to connect its traces. Before downgrading to a client that lacks this option, remove its YAML key and CLI flag; older clients reject unknown configuration keys and flags. See the configuration and compatibility guidance.
Downloads
The release includes tunnel-client, tunnel-client-runtime, and tunnel-client-runtime-cloudflared ZIP bundles for Linux, macOS, and Windows on amd64 and arm64, with matching SPDX documents and license reports. Use SHA256SUMS.txt and tunnel-client-v0.0.16-provenance.sigstore.json to verify downloaded artifacts; the release also includes source exports and vulnerability evidence. See the release verification instructions.
Full Changelog: v0.0.15...v0.0.16