Highlights: npm installs retain OAuth refresh protection, Windows daemon startup tolerates transient process-query failures, and long help flags remain readable.
-
Bundle the patched MCP client in npm releases so installed packages preserve request-correlated OAuth refresh locking; verify the installed tarball in CI and release gates.
-
Update the MCP client/server to 2.2.0, legacy SDK fixtures to 1.31.0, Hono to 4.13.10, pnpm to 10.34.6, and lint/format tooling; retain the OAuth correlation patch, Node 24 support, and the 48-hour dependency release-age policy.
-
Retry transient Windows process-query failures once before blocking daemon startup or retirement, while retaining strict ownership checks and refusing malformed observations.
-
Refresh MCP clients and fixtures, bundling and test tooling, and Hono; preserve OAuth refresh-token correlation when OAuth overrides a configured Authorization header, Node 24 support, and the 48-hour dependency release-age policy.
-
Size the top-level help's global-flag column to its longest flag, so
--log-level <debug|info|warn|error>no longer runs into its description. Thanks @KrasimirKralev.
Verification: npm, registry tarball, native assets, and browser Gatekeeper proof. npm integrity: sha512-3ajjKzPLe/39hN582XqMuOw3S9vHQfLpSBq72zVakT03xso3GDXHcht/eVLu/l2MDqulIOtLevnTKreUxymHJQ==.