RoselineMCP
Releases

Every version, its notes, and its downloads.

Pulled straight from GitHub Releases at build time. Grab the .mcpb for a one-click Claude Desktop install, or the .nupkg to pin a version.

  1. v3.1.1latest
    Sep 21, 2026

    3.1.1 (2026-09-21)

    Fixed

    • services: stop an unresolved analyzer reference from aborting the relationship tools (#242) (#244) (144f3f4)
    • tools: refuse a non-absolute project on writes into a checkout with linked worktrees (#245) (#247) (5709bc6)
    • tools: refuse an omitted-project write into a checkout with linked worktrees (#240) (#243) (4573421)
  2. Aug 27, 2026

    3.1.0 (2026-08-27)

    Added

    • ci: enforce Conventional Commit PR titles (#164) (#211) (217d34c)
    • tools: state limitations and show an example in every tool description (#179) (#193) (7c11f69)

    Fixed

    • confirm: end every write prompt on the resolved target (#173) (#202) (de33948)
    • confirm: name the project in the csproj apply_fixes prompt (#203) (#214) (7c9df1d)
    • docs: sync the published median token figure with the generated benchmark data (#182) (#195) (1f4770a)
    • fixes: enforce and report ApplyFixes' single-project scope (#156) (#185) (b39dc6e)
    • fixes: only rewrite files whose diff actually changed (#175) (#209) (2e498ba)
    • loader: fall back to a standalone project load for an explicit .csproj hitting an ambiguous ancestor (#213) (#218) (684c332)
    • loader: ignore AppleDouble shadow files in auto-discovery and refuse ambiguous solution walks (#172) (#192) (0941603)
    • services: anchor verification error paths to the response's resolvedPath (#199) (#201) (e9a682b)
    • services: distrust a stat-only fingerprint match captured while a tracked file was still racy (#235) (#236) (21fb4cf)
    • services: fail fast on an already-cancelled token before the git clone (#215) (#222) (6ccaace)
    • services: name analyzer references that load nothing and register their fixers (#183) (#188) (fd7b6d8)
    • services: relativize paths against resolvedPath, not Solution.FilePath (#181) (#194) (fe5e56c)
    • services: signal ambiguous-solution-walk precisely instead of catching ArgumentException (#226) (#229) (754c653)
    • tests: give ElicitationTests' confirmation-timeout wait a generous, diagnostic ceiling (#224) (#225) (8b28266)
    • tests: give GuardServiceTests' Entered wait a generous, diagnostic timeout (#219) (#221) (7783673)
    • tests: remove GuardServiceTests' Entered stamp-collision race (#233) (#234) (1bcede2)
    • tests: run the environment-mutating configuration tests in one sequential collection (#189) (#200) (4610bba)
    • website: align the per-file and per-suite benchmark figures with the generated data (#196) (#205) (d89c53a)
    • website: derive the per-kind tool counts and analyzerLoad tools from tools.ts (#207) (#216) (3db07af)
    • website: derive the site's tool count from tools.ts (#197) (#206) (9e3ce39)
    • website: redraw the index.astro Program.cs showcase illustration (#212) (#227) (5eae929)
    • website: regenerate package-lock.json and gate npm ci (#190) (#223) (98da5c4)
    • website: restore missing spaces at astro line-wrap boundaries (#217) (#231) (69aae04)
  3. Aug 22, 2026

    3.0.0 (2026-08-21)

    ⚠ BREAKING CHANGES

    • verify: a previewOnly: false call may now decline to write. The call still succeeds (ok: true), but applied comes back false and the response carries the diff and the introduced errors instead. Callers that assumed the write happened must read applied. apply_fixes had no applied field before this release — without it a refusal was indistinguishable from a success, since the response still carries previewOnly: false, a patch and a fixedCount. Pass allowIntroducedErrors: true to restore the previous write-anyway behaviour.

    Added

    • guard: report the compile verdict after every file write (#168) (#171) (57bb097)
    • verify: verify edits against the compiler before writing, add check_compilation (#133) (#145) (eb19739)

    Fixed

    • confirm: do not ask a human to approve a write that changes nothing (#162) (#174) (0ab3433)
    • confirm: render write-confirmation prompts centrally and escape caller input (#161) (#170) (587080f)
    • confirm: say EditMember writes one file, not the whole solution (#154) (#157) (7a62090)
    • confirm: say which scope ApplyFixes writes when the target is a solution (#149) (#152) (a32e5a7)
    • loader: report the resolved solution path in every project-loading response (#139) (#143) (1cd7943)
    • loader: resolvedPath reports the file actually opened (#151) (#177) (36a340d)
    • report permission failures as AnalysisError and skip unreadable directories (#150) (#153) (d68791f)
    • services: skip unreadable directories during auto-discovery (#158) (#169) (52d1417)
    • tests: make the option-binding tests independent of ambient ROSELINE_ variables (#132) (#140) (bd03629)
    • tests: neutralize every casing of ROSELINE_ in the option-binding tests (#141) (#144) (e82f842)
    • tools: name the resolved checkout on the failure envelope (#139) (#176) (7a36010)
    • tools: name the resolved project in the write-confirmation prompt (#138) (#142) (4cad859)

    Changed

    • cut releases with release-please instead of a hand-pushed tag (#159) (#160) (505c3c5)
    • test: run tests on Microsoft.Testing.Platform, update xunit.v3 to v4 (#147) (#155) (c97a218)
  4. Aug 19, 2026

    Added

    • RoselineMCP:ConfirmDestructiveWritesTimeout (default 300000 ms, 5 minutes) — bounds how long the write-confirmation elicitation waits for the client's answer. Set it via appsettings.json or ROSELINE_RoselineMCP__ConfirmDestructiveWritesTimeout=<ms>; 0 or less removes the bound and restores the previous, indefinite wait. This changes default behavior: a client that advertises elicitation support, accepts the confirmation request and then never answers — a CI job, a headless agent, a human who walked away — used to block apply_fixes / edit_member / rename_symbol forever, because RoselineMCP:DefaultTimeout is an analysis budget and by construction does not apply to the human round-trip. The server now stops waiting after the timeout — note that a client whose elicitation handler never returns may still not read the response, since the SDK's client dispatches server-initiated requests on its read loop; the bound is on RoselineMCP's side of the wire. It returns a preview, not a write: silence is not consent, so previewOnly comes back true and notes[] explains that the confirmation timed out. Writing without a human remains an explicit operator decision (ConfirmDestructiveWrites=false), so the security posture is no weaker than before — only the hang is gone. The clock is deliberately separate from DefaultTimeout: a human reading a real diff may legitimately exceed an analysis budget.
    • RoselineMCP:ConfirmDestructiveWrites (default true) — an operator switch that turns off the write-confirmation elicitation. The write tools (ApplyFixes, EditMember, RenameSymbol) ask the connected client to confirm before writing when the caller passed previewOnly: false; on an unattended host that prompt is not a second guard but a stop, because MCP elicitation is a separate channel from tool permissions and no client-side setting can pre-answer it — so claude -p runs, CI jobs and overnight agent loops blocked on a human keypress. Set it via appsettings.json or ROSELINE_RoselineMCP__ConfirmDestructiveWrites=false and no elicitation is sent at all (rather than one being auto-accepted); the explicit previewOnly: false opt-in then stands as the only guard before a write — see SECURITY.md. Interactive installs are unaffected: leave it at its default and behavior is unchanged. The server logs a warning at startup when the switch is off, so a gate-off deployment is identifiable from its stderr rather than being indistinguishable from a confirmed one.

    Fixed

    • A write confirmation that times out can no longer be read as consent when the SDK reports the abandoned prompt as something other than a cancellation. The confirmation gate downgraded to a preview only on OperationCanceledException; every other exception fell through to a catch-all meaning "this client cannot elicit — honor the explicit opt-in" and returned proceed. Cancelling an in-flight JSON-RPC request is not guaranteed to surface as an OCE, so a transport or protocol exception raised by our own deadline would have written to disk on a confirmation nobody answered — the exact inversion of the gate. The timeout branch now filters on the deadline rather than on the exception type, so any failure caused by it downgrades to a preview; genuine caller cancellations and broken sessions still propagate unchanged.
    • The RoselineMCP:DefaultTimeout clock no longer runs while a human is being asked to confirm a write. It was armed before the confirmation elicitation, so its 120 s budget was spent on think-time — the very thing the confirmation's separate clock exists to prevent. Two consequences, both gone: a human who approved a previewOnly: false call more than 120 s after it started got {"ok": false, "error": {"type": "TimeoutError"}} instead of the write they had just authorized; and with the new ConfirmDestructiveWritesTimeout default (300 s) exceeding DefaultTimeout, the timeout path could never have delivered the documented preview-and-note either. The analysis budget now starts once the confirmation resolves, so DefaultTimeout measures analysis — as documented — rather than analysis plus however long the human took.
    • The EditMember write-confirmation prompt no longer asks the human to approve a write in '' when project was omitted (the documented auto-discovery default) — it now names "the auto-discovered project", matching ApplyFixes. RenameSymbol's prompt likewise names the project it resolved, instead of describing a solution-wide rename without saying which solution.

    Changed

    • Upgraded the MCP SDK from ModelContextProtocol 1.4.1 to 2.2.0, which negotiates protocol revision 2026-07-28 by default. No tool's wire shape, parameters, or response envelope changes.
    • Client-side log forwarding is now inert for clients on protocol 2026-07-28 or later. SEP-2577 deprecated the MCP Logging feature in that revision: logging/setLevel is rejected, and a server must not emit notifications/message for a request that did not carry an io.modelcontextprotocol/logLevel _meta field — which the SDK's own McpClient provides no way to set (on such a session it injects per-request _meta and strips that key). So the tool-failure log notifications RoselineMCP sends via AsClientLoggerProvider() are delivered only to clients that negotiate 2025-11-25 or earlier; the code is kept for them and stays a no-op otherwise. Nothing is lost for anyone: the correlation ID that those notifications carried is still in every error envelope (error.correlationId) and in the server's own stderr log, which is exactly what SEP-2577 names as the replacement. Deprecated features remain in the spec for at least twelve months.
    • Releases now publish to NuGet.org via Trusted Publishing instead of a long-lived NUGET_API_KEY secret: publish-nuget.yml exchanges the GitHub OIDC token for a key valid ~1 hour, the same way the registry publish already proved this repo's identity. The only remaining secret is NUGET_USER, the nuget.org profile name. Both prerequisites are in place as of 2026-07-27: the Trusted Publishing policy is registered on nuget.org (package owner phmatray, naming this repository and publish-nuget.yml) and NUGET_USER is set. The long-lived NUGET_API_KEY repository secret is deliberately kept until one real release has been published and verified — see PUBLISH.md.
    • The write-confirmation gate now lives in one place. apply_fixes, edit_member and rename_symbol each carried their own copy of the block deciding whether to ask, what a declined or unanswered prompt means for the call, what to log, and which note to attach — one policy with three edit sites. All three now call a single ToolExecutionHelper.ResolveWriteModeAsync, and the one part of the prompt that had drifted — how the target project is named — is single-sourced through ToolExecutionHelper.DescribeWriteTarget. No behavior change: no tool's parameters, response shape, prompt wording or notes text differ. This removes the cause of the three divergent confirmation messages already fixed under Fixed above, rather than fixing them again; ElicitationTests now pins all three prompts (and edit_member's decline path, which had no end-to-end cover) so the same divergence cannot re-form.

    Documentation

    • RoselineMCP:RunAnalyzers = false no longer claims to stop all analyzer-assembly execution — source generators run regardless, and the docs now say so. SECURITY.md promised the switch "disables all analyzer execution (bundled and project-referenced alike)", and CLAUDE.md and README.md repeated it. Source generators ship through the same AnalyzerReferences and are equally arbitrary in-process code from the analyzed repository, but they run as part of building any compilation rather than as part of the diagnostics pass — which RunAnalyzers is the only thing gating. Every semantic path therefore executes them: all seven navigation tools (via SymbolResolver), ApplyFixes (via CodeFixService) and AnalyzeSolution (via SolutionAnalyzerService). Verified on Roslyn 5.6.0 / .NET SDK 10.0.302 — a project whose only content is a [GeneratedRegex] partial method compiles through MSBuildWorkspace with the generated implementation bound and zero errors, which is only possible if the generator ran. The consequence for an operator is the point: someone who set RunAnalyzers=false before pointing RoselineMCP at an untrusted repository believed they had closed a code-execution surface that was still fully open. Suppressing generators is not offered because it would not be honest — stripping AnalyzerReferences removes the generated types too, so every symbol resolving through generated code would be reported as a compile error. The switch narrows the surface; isolation, not configuration, is the mitigation, and the operator recommendations now lead with that. No behavior changed — only the guarantee the documentation advertised.
    • RoselineMCP:WorkspaceCache = false is documented as what it is: an isolation/debugging switch, never a way to save memory. The docs described it only as "loads a fresh workspace on every call", which reads as the memory-frugal option; measured, it is the opposite — disposing the workspace after every call costs +26 % resident memory (~374 MB vs ~296 MB after two calls) and ~45× second-call latency (0.92 s vs 0.02 s), because a disposed workspace's memory is never returned to the OS and the reload allocates on top of it. An operator who set it to reduce a server's footprint was getting a regression.
    • docs/ARCHITECTURE.md gains the measured memory profile behind that correction (~78 MB before any workspace exists — runtime plus the Roslyn/MSBuild/Roslynator assembly set, not the cache; ~300 MB once real work has been served; disposal plus a forced compacting GC moves the working set 276 MB → 276 MB), so the cache's 4-entry LRU bound is visible as the only lever that affects it. Releasing cached workspaces on idle was evaluated against these numbers and rejected.
    • docs/ARCHITECTURE.md now states that the stdio transport, not UseConsoleLifetime, is what stops the host when a client closes stdin, with the four measured EOF paths (after handshake, before handshake, mid-tool-call, and stdin held open). UseConsoleLifetime handles only SIGINT/SIGTERM, and reading it as the whole lifetime story suggests a stranded-server bug that does not exist.
    • Dependency versions asserted in prose corrected against RoselineMCP.csproj, which the README already names as the source of truth: ModelContextProtocol 1.4.0 → 1.4.1 (README tech stack and tool-annotations section, CLAUDE.md), MSBuild 18.7.1 → 18.8.2, and Microsoft.Extensions.Hosting 10.0.9 → 10.0.10.
  5. Jul 4, 2026

    Fixed

    • The token-savings benchmark (RoselineMCP.TokenBenchmark) now measures the model-visible MCP wire text: each tool payload is wrapped in the ToolResult<T> envelope and serialized with the MCP SDK's own serializer (McpJsonUtilities.DefaultOptions — minified camelCase, default JSON escaping), verified byte-identical to the text content block the real server emits over stdio. Previous figures measured each tool's bare, un-enveloped DTO with an indented serializer the SDK never uses. Re-measured headline: median 85% → 89%, pooled (size-weighted) 88% → 93% (568 tasks; on identical code the methodology correction alone moves the median 86% → 89% — minification outweighs the envelope + escaping overhead). All published numbers (README, site, OG card, manifest, docs) are synced. The benchmark also no longer depends on its working directory: tool-emitted relative paths resolve against the loaded solution's root, and a failed baseline file read now skips that task with a message instead of crashing the run.
    • Solution/project auto-discovery is now nearest-level-first: the working directory wins when it has exactly one candidate, then each parent directory (up to 3) in order, then immediate subdirectories — so a solution in the cwd is no longer reported as "ambiguous" just because an ancestor directory (e.g. the main checkout above a git worktree) also has one; only a single level with multiple candidates of its own is an ambiguity.
    • serverInfo.version in the MCP initialize handshake now reports the real package semver (the assembly's InformationalVersion minus any +buildmetadata suffix) instead of the MinVer-pinned {Major}.0.0.0 AssemblyVersion — a released 2.1.0 build introduced itself as 2.0.0.0.
    • Social/Open Graph card (og.png) refreshed: the baked-in token-savings figure is now the median (85% at the time; since re-measured to 89%, see above — was the stale pooled 81%), and the card is regenerable from a checked-in template (website/og-card.html) instead of existing only as a rendered PNG; og:image:alt updated to match.
  6. Jul 4, 2026

    Added

    • New get_symbol_at_position navigation tool: resolves a file:line(:column) position (from a diagnostic, stack trace, grep hit, or find_references result) to the symbol living there — returning its name, fullName, kind, signature, definition location, and whether the position is the symbol's own declaration — so agents no longer have to read the file to guess a symbol name. Line-only queries prefer declarations on the line over referenced symbols.
    • Analyzer diagnostics are real: the diagnostics tools now run Roslyn analyzers, and Roslynator fixes actually work. Previously every diagnostics path used compilation.GetDiagnostics() (compiler-only), so RCS*/custom-analyzer diagnostics could never appear in analyze_solution/list_diagnostics and apply_fixes could never see them — and the Roslynator packages are analyzer-asset-only (no lib/), so their fix providers never even loaded. Now the Roslynator analyzer/fixer assemblies are bundled with RoselineMCP (an analyzers/ folder next to RoselineMCP.dll, shipped in the dotnet tool and Docker image), loaded at runtime (AnalyzerCatalog), and executed via CompilationWithAnalyzers together with the target project's own analyzer references (deduped by analyzer type) in one shared pass (DiagnosticComputationService) behind all three diagnostics tools. Roslynator's ~440 fixable rules are discovered as code fix providers, so list_diagnostics suggests RCS IDs as fixable and apply_fixes genuinely fixes them. A broken analyzer is logged and skipped — never failing the tool call. New RoselineMCP:RunAnalyzers setting (default true); set to false for the old, faster compiler-only behavior. Note that running a target project's own analyzers executes third-party code at analysis time — see the new SECURITY.md section.

    Fixed

    • list_diagnostics/apply_fixes no longer select a project by substring match against project file paths (asking for Foo could analyze FooBar) — project selection inside a solution now matches the exact (case-insensitive) name, via the shared ProjectLoader.
    • Docs drift found in the v2.0.0 audit: corrected the README's Roslyn version (5.3.0 → 5.6.0), repaired the changelog reference links (stale [Unreleased] compare, missing 1.3.x–2.0.0 definitions), reframed the benchmark headlines around the robust median (85%, pooled 88% kept as a labeled secondary figure) and labeled the agent benchmark's ~50% as the forced-use ceiling (~13% realistic, n=1), refreshed the NuGet package Description to the v2 positioning, and added the missing max parameter to the README getTypeHierarchy snippet.
    • ApplyFixes no longer reports ok: true with an Error: … note when the operation itself fails (e.g. project not found) — such failures now return the documented classified error envelope (ok: false with e.g. NotFoundError), like every other tool.
    • ApplyFixes, EditMember, and RenameSymbol now write changed files back with their original encoding (BOM included) instead of silently re-encoding everything as BOM-less UTF-8.
    • Symbol search and resolution now span every project in the loaded solution — previously only the anchor project was searched, so symbols declared in a sibling project it doesn't reference (e.g. the Tests project) were invisible to search_symbols (including the file outline) and made get_symbol_info, find_references, find_implementations, get_call_graph, get_type_hierarchy, edit_member, and rename_symbol fail with "Symbol not found".
    • analyze_solution reports honest numbers. diagnosticSummary now counts every diagnostic passing the filters — previously each project's diagnostics were capped at maxDiagnostics before counting, undercounting any project with more. topDiagnostics is now the true solution-wide top-N by severity — previously it kept the first N diagnostics encountered in project order, so warnings from an early project could crowd out errors from a later one.
    • Configuration (appsettings.json / appsettings.{Environment}.json) now loads from the install directory (AppContext.BaseDirectory) instead of the process working directory — a target repository's own appsettings.json can no longer reconfigure the server, the settings packaged with the dotnet tool are actually found, and the needless reload-on-change file watchers are gone. Removed the dead RoselineMCP:MaxDiagnostics key from appsettings.json.
    • MSBuild registration now picks the newest installed SDK instead of whatever MSBuildLocator enumerates first, and CreateWorkspace fails fast with an actionable error when no MSBuild/.NET SDK instance could be registered (instead of surfacing a confusing workspace load failure later).
    • Whitespace-only changes are no longer silently dropped from diffs (the diff engine ignored whitespace unconditionally): a whitespace-only edit_member no longer reports "No changes were produced" and skips the write even with previewOnly: false, apply_fixes patches no longer omit whitespace-only changes that were written to disk, and create_patch's ignoreWhitespace parameter now actually controls the behavior (default false); create_patch line counts also no longer miss content lines that themselves start with ++/--.
    • Docs /releases page could miss the just-published release. The page is generated from the GitHub Releases listing API at build time and is rebuilt immediately after the publish workflow, but that listing endpoint can trail /releases/latest by a few minutes — so a new release could be absent from the page until a manual re-deploy (as happened for v2.0.0). The build now cross-checks /releases/latest, retries the listing until it includes that tag (bounded so the build never hangs), and merges the latest release in directly as a fallback.

    Changed

    • apply_fixes, edit_member, and rename_symbol now emit changedFiles and patch-header paths relative to the solution root with forward slashes (falling back to the project directory when no .sln is loaded), aligning them with the base the navigation tools have used since 2.0.0 — previously they were relative to the project directory. If a client resolved these paths against the project directory, resolve against the solution root instead.
    • list_diagnostics and apply_fixes now load their project through the shared IProjectLoader (same as the navigation/edit tools): project is now optional (auto-discovered from the working directory when omitted), .sln paths are accepted, and the loaded workspace is cached across calls.
    • ApplyFixes now fixes all occurrences of a diagnostic ID in a single FixAll (batch) pass when the provider supports it, instead of re-compiling the project after every individual fix; providers without FixAll support keep the per-occurrence path, and the response shape is unchanged.
    • Docker image: now published ReadyToRun against the per-arch musl RID, precompiling IL to native code so the first tool call no longer pays most of the JIT cost.

    Performance

    • The navigation/edit tools now cache the MSBuild workspace across calls (~590 ms reload saved per call after the first), invalidated by a cheap on-disk fingerprint (mtime + size of the .sln, every .csproj, and every document) so any file change — including RoselineMCP's own edits — triggers a fresh reload; disable with RoselineMCP:WorkspaceCache = false.
    • analyze_solution analyzes projects in parallel (bounded by the processor count) instead of one at a time; results are merged deterministically and progress values still strictly increase.
  7. Jul 3, 2026

    Added

    • Server-level tool guidance to drive adoption. The server now sends MCP instructions — a decision policy telling the model to prefer these structural tools over reading whole files (especially on large codebases) — and each read-only tool's description is rewritten as a decision rule ("prefer over Read/Grep to answer 'where is this used'") rather than a feature list. In end-to-end testing this flipped the agent from never calling the tools to using them unprompted on large solutions. See docs/AGENT-BENCHMARK.md.
    • project is now optional on the Roslyn-backed tools (search_symbols, get_symbol_info, find_references, find_implementations, get_call_graph, get_type_hierarchy, edit_member, rename_symbol) — when omitted it is auto-discovered from the working directory (searching the cwd, a few parent directories, and immediate subdirectories) — and a .sln path is now accepted wherever project is passed. Reduces the friction that made agents fail calls guessing the project (they naturally tried the .sln, which used to fail).

    Changed

    • BREAKING: leaner response shapes for the read-only navigation tools and get_symbol_info — a token-efficiency pass trimmed redundant and always-present fields from the JSON these tools return (tool names and input parameters are unchanged). Concretely:

      • Relative file paths. Every file/definitionFile is now solution-root-relative with forward slashes (e.g. RoselineMCP/Services/Foo.cs) instead of an absolute path — across search_symbols, get_symbol_info, find_references, find_implementations, get_call_graph, and get_type_hierarchy.
      • truncated is omitted when false. Its absence now means "not truncated" — for search_symbols, find_references, find_implementations, every get_call_graph node, and get_type_hierarchy's derivedTypesTruncated.
      • find_references drops the column field from each reference (now just file, line, snippet).
      • get_call_graph drops each node's signature; the node fullName now renders parameter types as simple names (e.g. RoselineMCP.Services.Foo.Bar(string, CancellationToken)), still parameter-qualified so overloads stay distinct — call get_symbol_info for a method's full signature.
      • Redundant fields dropped from symbol summaries and get_symbol_info. accessibility is gone (it is already inside signature) from get_symbol_info and the project-wide summaries; containingType is gone from the full summaries (it is already the prefix of fullName). The single-file outline of search_symbols still emits containingType, but now as the simple, unqualified type name.
      • get_symbol_info now omits modifiers, baseTypes, interfaces, documentation, and source when they are empty/absent, so a minimal symbol collapses to name, fullName, kind, and signature.

      Net effect: tool output is ~35% smaller, lifting the benchmark headline savings from a pooled 81% to 88% (median per task 76% → 85%) on RoselineMCP's own source. These are breaking changes to the read-only tools' response wire shapes; update any client that parsed the removed fields or relied on absolute paths.

    • deploy-docs.yml retries the GitHub Pages deploy up to 3× — it intermittently returns "Deployment failed, try again later" (a Pages backend hiccup, not a build failure) that clears on re-run. The first two attempts tolerate failure, so a transient miss no longer fails the job.

    Documentation

    • End-to-end agent benchmark (docs/AGENT-BENCHMARK.md) — a controlled A/B (vanilla Claude Code vs. + RoselineMCP, same task, same model, quality-gated) measuring whether an agent actually consumes fewer tokens in practice. Finding: ~50% fewer tokens at equal quality on large-file codebases, break-even on tiny repos, and the model must be steered to use the tools.
    • Tools page aligned to the v1.4.0 contract. Added a response-envelope callout ({ ok, data } / { ok, error }, structuredContent/outputSchema), surfaced each tool's human Title and capability pills (progress, confirms/elicitation), gave every tool an anchor link, and dropped the stale new badges (those tools shipped in 1.3.0). The page had been showing the pre-1.4.0 flat response shape.
    • Docs site: added a GitHub "Star" button in the top bar showing the star count. Renders a build-time snapshot instantly, then a tiny client-side fetch refreshes it to the current count (falls back to the build-time value on rate-limit/error).
  8. Jul 3, 2026

    Added

    • MCP structured content + output schema — every tool now advertises an outputSchema and emits structuredContent (UseStructuredContent = true), so clients get a machine-readable, schema-validated result in addition to the JSON text.
    • Progress notifications for long-running tools — AnalyzeSolution, ApplyFixes, and RenameSymbol now report progress via MCP progress notifications.
    • Human-readable tool titles and an honest OpenWorld hint — every tool advertises a Title; OpenWorld is false for the local-only tools and true only for AnalyzeSolution (which can clone a Git URL).
    • Write confirmation via MCP elicitation — the write tools (ApplyFixes, EditMember, RenameSymbol) ask the client to confirm before writing when previewOnly: false; declining downgrades the call to a preview (nothing is written).
    • Failure logging via MCP logging notifications — tool failures are surfaced to the client's log stream through MCP logging notifications that carry the correlation ID.

    Changed

    • BREAKING: tools now return a typed ToolResult<T> envelope instead of a hand-serialized JSON string. The response wire shape changed: success payloads are now nested under data ({ "ok": true, "data": { ... } }) and failures under error ({ "ok": false, "error": { "type", "message", "hint?", "correlationId" } }). The human-readable message moved from the top-level error field to error.message; type/hint/correlationId moved under error. See docs/API.md.
    • server.json websiteUrl now points at the documentation site (https://atypical-consulting.github.io/RoselineMCP/) instead of the GitHub repo. Reaches the live MCP Registry entry on the next published version.
  9. Jul 3, 2026

    Fixed

    • MCP Registry publish 403'd on namespace casing. The registry namespace derived from GitHub OIDC is case-sensitive and matches the org's canonical login (Atypical-Consulting), but server.json's name and the README ownership marker used lowercase (io.github.atypical-consulting/...), so the first publish was Forbidden. Corrected both to io.github.Atypical-Consulting/roseline-mcp. (The lowercase GHCR image name is unrelated and stays lowercase, as Docker requires.)
    • Docs /releases page didn't refresh on new releases. The release: trigger on deploy-docs.yml never fired because the release is created by the publish workflow's GITHUB_TOKEN, and GitHub does not start workflows from token-created events. Switched to a workflow_run trigger on the Publish NuGet workflow's completion, which keys off the workflow (whose original trigger was a human tag push) and fires regardless of the publish outcome.
  10. Jul 3, 2026

    Documentation

    • Docs site: a Releases page generated from GitHub Releases at build time (notes rendered from each release, plus direct .mcpb/.nupkg download buttons), a new Claude Desktop (1-click) install tab, and a note that RoselineMCP is listed in the official MCP Registry. The Astro build fetches the Releases API (authenticated in CI to avoid rate limits) and degrades to a GitHub link-out if the fetch fails.

    Added

    • One-click install for Claude Desktop (MCPB bundle). A mcpb/manifest.json (MCPB spec 0.3) describes RoselineMCP as a dnx-launched server; the release now builds and attaches a RoselineMCP.mcpb to each GitHub Release, so users can install with a dialog instead of editing JSON config. The bundle only wraps the dnx RoselineMCP launch (the .NET 10 SDK is still required, since analysis loads projects through MSBuild), so it stays tiny and platform-agnostic.
    • Automated MCP Registry publishing. publish-nuget.yml now has a publish-registry job that, after a successful NuGet publish, waits for the version to index, then authenticates via GitHub OIDC (mcp-publisher login github-oidc, no secret) and publishes .mcp/server.json to the official registry (registry.modelcontextprotocol.io) — so the server is discoverable by any client/aggregator that reads the registry. Ownership is proven by an mcp-name: marker added to the packed README.md, which the registry cross-checks against the NuGet package. The manifest $schema was migrated from the deprecated 2025-10-17 to the current 2025-12-11 (a URL-only change; the format is unchanged for stdio package servers). Takes effect on the next tagged release.

    Security

    • Pinned Microsoft.Bcl.Memory to 10.0.9 (aligned with the net10.0 TFM) in RoselineMCP.TokenBenchmark to override the 9.0.4 that Microsoft.ML.Tokenizers 2.0.0 pulled in transitively, which was vulnerable to CVE-2026-26127 (GHSA-73j8-2gch-69rq, high severity — Base64Url out-of-bounds-read DoS). The benchmark harness is never packaged and is not referenced by the shipped RoselineMCP package, so published users were never exposed; this clears the NU1903 restore warning. Remove the pin once Microsoft.ML.Tokenizers references a patched build.
  11. Jul 3, 2026

    Changed

    • publish-nuget.yml now creates a GitHub Release and verifies the artifact before publishing. A git tag is not a GitHub Release, and nothing was creating one — so tagged versions published to NuGet without a corresponding Release (v1.3.0 had to be backfilled by hand). The release job now: (1) fails the build if the packed .nupkg is missing .mcp/server.json or its embedded version doesn't match the tag — a guard that would have caught the original dnx-fetches-1.0.0 bug at the source rather than in the wild; and (2) after a successful NuGet push, creates (or heals) the matching GitHub Release with notes extracted from this CHANGELOG and the .nupkg attached.

    Dependencies

    • Microsoft.ML.Tokenizers and Microsoft.ML.Tokenizers.Data.Cl100kBase 1.0.3 → 2.0.0 (RoselineMCP.TokenBenchmark only — not part of the shipped package) (#76)
    • Website: astro 5.x → 7.0.0 (#77) and CI Node 20 → 24 (#75)
    • actions/upload-pages-artifact action 4 → 5 (#74)
  12. Jul 3, 2026

    v1.3.0 — Code navigation & editing tools

    [1.3.0] - 2026-07-03

    Added

    • Token-efficient code navigation tools — six new read-only MCP tools that let an AI agent retrieve precise structural/semantic information via Roslyn instead of reading whole files (source code typically dominates an agent's token budget):
      • search_symbols — find symbols by wildcard/substring name pattern, or outline a single file
      • get_symbol_info — a symbol's kind, accessibility, modifiers, signature, base types, interfaces, XML docs, and definition location (optionally its source) — the compact "go to definition" payload
      • find_references — every use site of a symbol across the solution, as location + snippet
      • find_implementations — implementations of an interface/member, overrides, or derived types
      • get_call_graph — a depth-bounded caller/callee graph with cycle detection
      • get_type_hierarchy — a type's base-class chain, interfaces, and derived types
    • Surgical code-editing tools — two new write tools that emit a member-level change (not a whole-file rewrite), keeping the tokens an agent produces proportional to the change. Both default to preview mode (previewOnly: true) like ApplyFixes, so nothing is written to disk unless the caller passes previewOnly: false explicitly:
      • edit_member — replace, add, or delete a single type member
      • rename_symbol — rename a symbol and update every reference across the solution (Roslyn rename)
    • IProjectLoader/ProjectLoader service that loads a project — and its containing solution when present, so references and renames span projects — into a fresh workspace per call, plus ICodeNavigationService and ICodeEditService and their response models.
    • Token-savings benchmark (RoselineMCP.TokenBenchmark) — a reproducible harness that runs the real services against RoselineMCP's own source and measures each tool's output against the source an agent would otherwise read, tokenized with cl100k_base. Systematic sweeps; results stamped with commit + date. Reproduce with dotnet run --project RoselineMCP.TokenBenchmark -c Release.
    • Documentation site (website/, Astro) with an overview, the tool reference, and the honest benchmark (charts + methodology + limitations), deployed to GitHub Pages via .github/workflows/deploy-docs.yml. Across 477 navigation tasks the read-only tools showed a pooled 81% / median 74% token reduction versus reading the corresponding files.

    Changed

    • search_symbols file outline is now token-lean. The benchmark caught the outline costing tokens (it repeated the file path and fully-qualified name on every symbol); it now returns a lean projection (name, kind, signature, line), flipping its median from −45% to +30%. SymbolSummary also omits null fields from its JSON. Project-wide search is unchanged.

    Fixed

    • dnx-based installs pulled an ancient 1.0.0. .mcp/server.json hardcoded version/ packages[0].version at 1.0.0 — a version that was never released (releases start at 1.2.0) — so any client resolving the MCP manifest was told to fetch 1.0.0. Worse, despite PackageType=McpServer the manifest was never packed into the .nupkg (it lives at the repo root with no <None Include> wiring it in), so the McpServer package shipped without its own manifest. Fixed by: (1) correcting the manifest to the current release, (2) packing ../.mcp/server.json into the package at .mcp/server.json, and (3) stamping the version into the manifest from the release tag in publish-nuget.yml (mirroring MinVerVersionOverride) so it can never drift out of lockstep with the package version again.
  13. Jul 2, 2026

    v1.2.1 — Reference-project hardening

    First real published release of RoselineMCP: reference-project hardening covering security defaults, real Git-URL analysis, correctness fixes, CI/CD, packaging, and a full documentation accuracy pass. See CHANGELOG.md for the itemized [1.2.0]/[1.2.1] entries.

    Install

    dotnet tool install -g RoselineMCP
    

    Or via Docker:

    docker pull phmatray/roseline-mcp:1.2.1
    

    Note on versioning

    v1.2.0's tag push published Docker Hub/GHCR images successfully but hit a CI bug that blocked the NuGet.org publish (fixed in this release — see CHANGELOG). v1.2.1 republishes identical application content to both registries and is NuGet.org's first successful release.