arc-mcp/arc-1
SAP ABAP development with the ARC-1 MCP server and portable skills for RAP, CDS, testing, migration, clean core, and UI5. Read-only by default.
Changelog
Generated by release-please — one line per merged PR. For what each release means (impact, upgrade actions, config and tool-surface changes), read the annotated release notes (source).
1.2.0 (2026-09-03)
Features
- add experimental data-source blocklist (#740) (97560ae)
- bound data-preview response memory (#739) (e0320b3)
- identify direct-connect SAP systems in instructions (#735) (7969a9b)
Bug Fixes
- security: patch pre-authentication decoder DoS in optional BTP AppRouter (#738) (3d89008)
- read local-class methods from class includes (#744) (978c0fe)
1.1.2 (2026-08-31)
Bug Fixes
1.1.1 (2026-08-31)
Bug Fixes
- add Agent Plugins 1.0 package (#695) (03ec895)
- bind the ATC check variant SAPDiagnose claims to run (#708) (3c3e9f1)
- forward user=* when listing transports across owners (#706) (e1b9dfb)
- refresh runtime security packages before image scans (#726) (284935c)
- resolve BSP paths from response metadata (#727) (c429720)
- stop ATC polling once the worklist settles (#710) (4dcde5f)
1.1.0 (2026-08-18)
⚠ BREAKING CHANGES
- SAPGit no longer accepts the advertised but unimplemented commit action. Use abapGit push for supported commit-and-push workflows; gCTS mutations remain quarantined.
Features
- add SAPTransport action="diff" for transport review (#671) (475e6f0)
- harden ARC-1 CLI for SAP CI workflows (#703) (8c09b81)
Bug Fixes
- add opt-in gzip for WAF-blocked data-preview requests (#694) (ba3e1d9)
- correct and harden ADT source text search (#683) (33546e3)
- correct TABLE_QUERY IN value guidance (#691) (9fba0b6)
- deps: resolve npm audit advisories in transitive dependencies (#672) (c24fb13)
- never report a syntax check as clean when SAP refused to run it (#681) (a9aedeb)
- read the CSRF token and session cookie atomically (#680) (9c29f6d)
- support DDLS table functions on 7.50 (#693) (1f29817)
1.0.2 (2026-08-03)
Bug Fixes
1.0.1 (2026-08-03)
Bug Fixes
- correct CTS transport checks (#659) (70bce30)
- drop inapplicable FUNC processing metadata instead of rejecting the write (#665) (9f1ecbb)
- load extension plugins on Windows (#662) (83bf1c5)
- read FLP tiles through the Pages association instead of a $filter (#663) (7a1dee3)
1.0.0 (2026-07-31)
Features
- add experimental destination-discovered multi-target endpoints (#579) (5ec27fc)
- add procedural unit source surgery (#571) (b712616)
- advertise configurable MCP server name per deployment (#606) (0374f83)
- bound unbounded tool results, reject unknown params, compact JSON (#583) (5de5b96)
- create Remote-Enabled and update-task function modules (#634) (91dc911)
- DTDC (Dynamic Cache) read/write — generalize the server-driven engine off blue-only (#612) (dea5d0f)
- FUGR structural includes, NW 7.50 release gates, FUNC processing-type read-back (#637) (3811587)
- propagate W3C trace context to SAP and record calling-agent identity (#641) (a3d765a)
- publish CycloneDX npm SBOM with releases (#633) (542f699)
- read Launchpad App Descriptor Items (UIAD) and gate SDO types on discovery (#642) (a0d3f5c)
- remove cache warmup (#573) (525aca3)
- SAPDiagnose action=atc_variants — list ATC check variants + system default (FEAT-68) (#611) (3b0bc93)
- serve RFC 9728 protected-resource metadata in OIDC mode (#632) (ee6922f)
Bug Fixes
- abapgit: match the ADT bridge wire contract and support private repos (#635) (c60da36)
- btp: allow jwt-bearer exchange against ARC-1's XSUAA client (#605) (cc7ad92)
- don't crash startup on PP-off overrides, and harden the mta.yaml/mtaext stranding class (#582) (d7e2cb8)
- harden multi-target behavior (#628) (879376d)
- improve DDLS view-extension lint and diagnostics (#627) (871bb7e)
- lead SAPWrite with its purpose and complete the TTYP documentation (#644) (cef92d0)
- never block tools/list on startup feature discovery (#639) (c70390c)
- per-type source format for server-driven objects (DTSC write was 415) + add DSFD (#604) (543f633)
- propagate corrNr to the class-include init POST (#645) (#646) (0adb40e)
- reconcile recursive transport release with terminal SAP state (#613) (002f24d)
- reload rotated cookie file before the 401 retry (#631) (8103452)
- security: patch and monitor AppRouter dependencies (#625) (7a0a835)
- server: MCP 2026-07-28 forward-compat — CORS protocol headers, era-contract tests, ADR-0006 (#601) (dd99c17)
- walk the AUnit result structure so alerts, program name and skips survive (#648) (0025ec3)
- write: omit adtcore:responsible when it cannot be an on-prem user name (#638) (75bf274)
0.9.27 (2026-07-13)
Bug Fixes
0.9.26 (2026-07-13)
Features
Bug Fixes
- default minimal errors for HTTP (#552) (4ed0dcf)
- harden change_package object type matching (#556) (940b7c5)
- harden principal-propagation identity boundaries (d458c66)
- improve SAPQuery Open SQL guidance (#559) (636eb6c)
- make sqlite source cache explicit opt-in (#557) (7864e89)
- open browser via rundll32 on Windows to preserve & in URLs (#549) (#555) (dbf2123)
0.9.25 (2026-07-02)
Features
Bug Fixes
- default DCR client_id TTL to never-expire and warn when the signing secret is missing (#540) (dd833b8)
0.9.24 (2026-06-30)
Bug Fixes
- foolproof add_method — auto-append missing terminating period (#536) (#539) (c525c04)
- mcpb: ship the bundle unsigned so strict third-party hosts can install it (#537) (50a7948)
0.9.23 (2026-06-29)
Features
- Add labels to source diffs (#528) (bd6e520)
- cloud-correct object create on BTP ABAP Environment (G-2..G-5) (#522) (515b91f)
- create packages on the BTP ABAP Environment (cloud-correct DEVC body) (#534) (25a017b)
Bug Fixes
Tests
- btp: cover SDO create + tool-level dispatch on BTP; fix smoke read-restriction assertion (#533) (d124ead)
- btp: verify + cover SRVB update on the ABAP Environment (B3) (#532) (3a0b403)
- verify RAP-stack (BDEF/SRVD/SRVB) cloud create on BTP (#529) (8451372)
0.9.22 (2026-06-26)
Features
- add DDIC structure context (#515) (76e24dc)
- diagnose: odata_perf client-wait + debug-slow-sql field findings (#521) (ddb0ffe)
- S/4HANA Public Cloud support (#524) (bdcd330)
Bug Fixes
Tests
0.9.21 (2026-06-25)
Features
- ddic: TTYP (table type) read + create (FEAT-65) (#504) (22c49b6)
- diagnose: ABAP Unit test coverage (statement/branch/procedure) for SAPDiagnose (#503) (f6ab40e)
- diagnose: OData sap-statistics perf probe + CDS Show-SQL + ICF-inactive guard (#509) (f111216)
- diagnose: ST05 SQL-trace state control + record-viewer directory (#510) (a54a99b)
- fugr: write FUGR structural include source (#505) (0e4f522)
- manage: SAPManage set_api_state — write an object's API release contract (clean-core) (#506) (30d68fd)
- query: self-correcting "unknown column" hint for SAPQuery + TABLE_QUERY (FEAT-64) (#502) (39c119b)
- rap: create RAP behavior extensions (
extend behavior for) (#507) (209893b) - SAPQuery datapreview metrics + SAPDiagnose ABAP trace requests (#508) (b10fab9)
- transport: pre-release inactive-objects check + fix misleading K/W/T create claim (#501) (3519b1b)
- transport: surface release-check report from SAPTransport release (#514) (fd7e907)
Bug Fixes
- add minimal client-facing SAP errors (#495) (f6b7fea)
- cli: send correct arg shapes from sql/search shortcuts (#512) (b7e5325)
- create audit and cache files privately (#496) (b409672)
- default deployment descriptors to verified SAP TLS (#491) (e70eaf7)
- diagnose: correct odata_perf "app" verdict note (#513) (fe12767)
- enforce package allowlist for gCTS mutations (#490) (dfce4be)
- fail closed on principal propagation errors (#488) (8c22795)
- gate quickfix application as a write (#489) (f25dce5)
- probe UI5 BSP filestore via /objects, not the handler-less bare node (#498) (0f1676c)
- redact audit events before sink writes (#493) (f7af34e)
- require auth for HTTP transport (#487) (46c68a0)
- warn on insecure SAP TLS and encode trace paths (#494) (b67586e)
0.9.20 (2026-06-22)
Features
- add context-first KTD workflow with guarded writes (#486) (32cc3bc)
- add read-only UI console (#485) (68b3f2a)
- extensions: gated non-ADT writes via ctx.http (v2 §2.2 Path B) (#474) (4294c94)
Bug Fixes
0.9.19 (2026-06-18)
Features
- auth: use @arc-mcp/xsuaa-auth for XSUAA/OAuth + BTP principal propagation (#456) (0e4795b)
- config: reject non-3-digit SAP_CLIENT at startup (#471) (4e1b8e4)
- extensions: extension framework for Custom_* plugin tools (#454) (7425f00)
Bug Fixes
- auth: adopt @arc-mcp/xsuaa-auth hardened OIDC + constant-time api-key verifiers (#468) (2dfb512)
- extensions: close 2 policy-boundary gaps + doc sharp edges (post-merge review) (#467) (8c6bbb4)
0.9.18 (2026-06-16)
Features
- SAPRead: add action="diff" for server-side single-system version diff (#445) (7d603ef)
- SAPTransport: add summary=true headers-only mode for list (#448) (3ac3619)
Bug Fixes
0.9.17 (2026-06-15)
Features
Bug Fixes
- clearer guidance for cross-subaccount OAuth2UserTokenExchange (#436) (226c437), closes #434
- http: handle 304/204/205 null-body status on Cloud Connector proxy path (#440) (9e3906e)
0.9.16 (2026-06-12)
Bug Fixes
0.9.15 (2026-06-12)
Features
Bug Fixes
- adt: make SRVB publish/unpublish content negotiation 758-proof (#403) (909f253)
- cache: batch warmup writes in transactions (#417) (6a5ec76)
- config: empty env values fall back to defaults (fail closed, not fail open) (#427) (cd32f54)
- context: avoid SAPContext dependency convoy (#411) (f37373b)
- docker: patch OpenSSL CVE-2026-45447 and harden release CVE gate (#400) (951ca09)
- handlers: accept any maxResults number, floor+clamp at the sinks (#423) (1eb1758)
- type-check the test suite + split intent.test.ts (#405) (5cb235c)
- xml: make XML escaping single pass (#414) (df0c285)
- xml: reuse parser array tag set (#412) (2d12d3d)
Tests
- handlers: Zod↔JSON-Schema type-parity guard (#415) (0855e2c)
- isolate concurrent integration/e2e runs, add teardown janitor, fix flake (#426) (5895a75)
- rename dispatch-rate-limit test, featuresOff() sweep, strip intent.ts provenance (#410) (8a34886)
- server: de-flake auth-rate-limit (one server per test) + diagnosable transport errors (#424) (96fb89d)
Performance Improvements
0.9.14 (2026-06-11)
Bug Fixes
- enforce SRVB package gate (#394) (6b91dea)
- harden SAPRead grep regex handling (#392) (9d23287)
- ignore BTP service key files (#395) (ec7b6a9)
- isolate PP cache state (#393) (3278eb8)
- write: emit adtcore:language + masterLanguage on MSAG payloads (#397) (07f9a9c)
0.9.13 (2026-06-09)
Bug Fixes
- git: enforce package allowlist on abapGit pull/push (#389) (82cec9b)
- limits: clamp unbounded result limits to prevent resource exhaustion (#388) (9656162)
- oauth: match redirect-uri allowlist against parsed URL components (#387) (c795b53)
- transport: delete requests holding locked objects via removeLockedObjects (#386) (e64b497)
0.9.12 (2026-06-09)
Features
- diagnose: SAPDiagnose action=cds_testcases — CDS test-case scaffolding (#351) (b54ccd0)
- read: generic server-driven object read — SAPRead DESD/EVTB/DTSC/CSNM/EVTO/COTA (#356) (ce3dacc)
- write: server-driven object write — SAPWrite create/update/delete + SAPActivate (DESD/EVTB/DTSC/CSNM/EVTO/COTA) (#362) (0c7f0a6)
- xsuaa: raise default refresh-token-validity to 30 days (#383) (8e0ee71)
Bug Fixes
- handlers: harden tool-arg validation against GPT/OpenAI schema pollution (#363) (138d89c)
- security: close scope-router privilege escalation and bind OAuth state to client_id (#352) (ba0a21b)
- security: enforce allowedPackages ceiling on activation and change_package (#357) (2a1135e)
- security: XSUAA redirect-uri allowlist for the shared default client (#358) (d204eb8)
- write: emit pak:recordChanges so transportable package creation works on SAP_BASIS 816 (#375) (00e4197)
- write: thread logon user into adtcore:responsible (#380) (3f8dc12)
Tests
- close slow baseline and server coverage gaps (#367) (3968296)
- migrate SAP CI to A4H 2025 (#365) (d22392d)
- split slow SAP test profiles (#364) (c63346d)
- tighten integration skip hygiene (#353) (bdca845)
- tighten live cleanup and skip telemetry (#359) (94551af)
0.9.11 (2026-06-05)
Bug Fixes
- lint: don't block writes on parse errors beyond abaplint's grammar (8xx / SAP_BASIS 816) (#350) (79b5687)
- probe: repair broken probe CLI and validate ABAP Platform 2025 (SAP_BASIS 816) (#347) (6c307ec)
0.9.10 (2026-06-05)
Bug Fixes
0.9.9 (2026-06-04)
Features
- fugr: recursive include expansion for SAPRead(type=FUGR) — captures function module code (#341) (2f99335)
- transport: set explicit transport target (TR_TARGET) on SAPTransport.create (#339) (95d6a9c)
Bug Fixes
- atc: bind check variant via worklist so SAPDiagnose(atc) returns findings (#336) (5386465)
- deps: bump express-rate-limit to 8.5.2 and key IPv6 by /56 subnet (#330) (1bb5e31)
- fugr: non-expand SAPRead(FUGR) returns the real function-module list (objectstructure) (#342) (93b6c22)
- surface XSUAA OAuth errors on /oauth/callback + don't prefix reserved scopes (#327) (f7418ed)
- write: derive created-object master language from SAP_LANGUAGE (#344) (18672fd)
0.9.8 (2026-06-01)
Bug Fixes
0.9.7 (2026-05-30)
Features
- auto-initialise class-local includes on write (testclasses/CCAU) (#314) (2a7bdc0)
- class-section surgery for CLAS (#307) (7d17ea2)
- read: add TABLE_QUERY type for multi-column structured queries (#309) (7eb01f4)
- read: SAPRead grep — regex search within object source (#316) (0d338e2)
- safety: allowedPackages X/** subtree rule + nodestructure-backed resolver (#284) (2d34909)
Bug Fixes
- btp: per-user OAuth2UserTokenExchange Bearer token for headless BTP → ABAP (#315) (d5bb9ca)
- http: dedupe Cookie header so live session id wins over stale file copy (#293, part 1) (#310) (fdb478e)
- intent: replace 3 raw NUL bytes in source with \x00 escapes (#317) (d125142)
- release-aware 423 lock-handle guidance (#312) (9c7e021)
- write: reject mixed-case object names on update/edit_method/delete (#311) (2cff142)
Tests
- clean up transport test requests (#308) (5d643d2)
- convert pseudo skips to real skips (#304) (73437e8)
- e2e: fix ZI_ARC1_I33_PROJ fixture activation on S/4HANA 2023 (#318) (9d8ac15)
- harden e2e fixture activation (#306) (ab5eaa7)
0.9.6 (2026-05-27)
Features
- ARC-1-native pre-write hint for canonical %admin draft include (#271) (21ac60b)
- layered rate limiting (Layers 1+2+3) (#276) (1994298)
Bug Fixes
- features: fall back to syntax-configurations endpoint for abapRelease (95ce9bc)
- refuse TABL/DT writes on NW 7.50/7.51 with SE11 hint (#285) (#286) (b098140)
- route TABL/DS create to /ddic/structures (#302) (039d800)
0.9.5 (2026-05-11)
Features
- add SAPSearch tadir_lookup source modes + SAPWrite batch_create activateAtEnd (#270) (dec53b4)
- stable DCR signing key + 0/negative TTL = infinite (#267) (1b4b191)
Bug Fixes
0.9.4 (2026-05-10)
Features
- add FUNC structured-parameter support (#259) (154db0f)
- add sprint 3 diagnostics cleanup (#254) (0bb34cc)
- add TADIR lookup and batch package overrides (#256) (dc2fe3d)
- edit_method splices into class-local includes (CCDEF/CCIMP) (#261) (99ba5a1)
- SAPWrite generate_behavior_implementation action (PR-C) (#260) (5151d13)
Bug Fixes
- harden apply_quickfix payloads (#253) (a859fc5)
- retry ED064 activation and support ABAP release lint override (#255) (8cc8833)
- support class include writes and RAP skeletons (#257) (c4ac325)
0.9.3 (2026-05-09)
Bug Fixes
- add FUGR + FUNC create/update/delete (#251) (f5ed2b8)
- btp: harden CF deploy + add Viewer+SQL XSUAA role-collection (#246) (a3bfb5e)
0.9.2 (2026-05-08)
Bug Fixes
0.9.1 (2026-05-08)
Bug Fixes
- adt: align DEVC listing descriptions with object names (#242) (63cfc70)
- adt: decode XML entities in parseSearchResults description (#243) (c522866)
- docker: drop bundled npm CLI from runtime image (#240) (e480206)
0.9.0 (2026-05-08)
⚠ BREAKING CHANGES
- MSAG read enum + FTG2→FEATURE_TOGGLE rename (audit Plan B) (#224)
- callers that passed type='FUNC/FM', 'CLAS/LI', 'VIEW/V', or 'TRAN/O' will now fail Zod schema validation. Migrate to FUGR/FF, CLAS/I (if needed — currently absent), VIEW/DV, TRAN/T respectively, or use the canonical short forms FUNC/CLAS/VIEW/TRAN.
- SAPRead/SAPWrite/SAPActivate no longer accept type='STRU'. Callers must use type='TABL' for both transparent tables and DDIC structures. ARC-1 ships pre-1.0; the slash form 'STRU/DS' is preserved as a back-compat alias inside SLASH_TYPE_MAP only.
Features
- cookie hot-reload on stale 401 (#200) (23d4bfe)
- layered lock-conflict detection + MSAG transport guard (#202) (cf0a126)
- MSAG read enum + FTG2→FEATURE_TOGGLE rename (audit Plan B) (#224) (d4c0fd3)
- purge invented ADT slash aliases (issue #218 audit, Plan A) (#223) (e130b87)
- three-file sync (messages + STRU) + universal write guards (#201) (2afedf1)
Bug Fixes
- adt: tighten HTML entity decoder + tag stripper (CodeQL alerts 6, 7, 8) (#238) (3bd7dac)
- collapse STRU type into TABL (#219) (1a310e9)
- SAPTransport.create works on NW 7.50 (non-breaking, defaults DEVCLASS=$TMP) (#228) (fc29c41)
Tests
0.8.0 (2026-05-06)
⚠ BREAKING CHANGES
- make OAuth DCR registrations survive container restarts (#212)
Features
- ARC1_PUBLIC_URL env var for reverse-proxy / different-hostname deployments (#216) (6e219dd)
- HTTP security headers (helmet) + opt-in CORS for browser MCP clients (#215) (8929d21)
- make OAuth DCR registrations survive container restarts (#212) (0d78a6b)
Bug Fixes
0.7.2 (2026-04-28)
Features
Bug Fixes
0.7.1 (2026-04-27)
Bug Fixes
0.7.0 (2026-04-26)
⚠ BREAKING CHANGES
- authorization refactor (#181)
Features
- add cds crud dependency guidance for ddls workflows (#176) (f597486)
- authorization refactor (#181) (7be4ff0)
- close RAP on-prem authoring gaps with preflight and handler scaffolding (#173) (29ee0b5)
- detect sibling DDLS DDLX coverage mismatches in SAPContext impact (#177) (4f6e822)
- harden SAPDiagnose dump and gateway diagnostics (#174) (9383891)
Bug Fixes
- harden SAP data preview diagnostics and SAPManage scope behavior (#171) (6697d3e)
- SAPActivate phantom success + CLI/server alignment gaps (NW 7.50) (#179) (4f2028e)
[Unreleased] — v0.7 — Authorization Refactor (breaking change)
Complete rewrite of the authorization model. Introduces a single ACTION_POLICY matrix as the source of truth for (tool, action) → (scope, opType); replaces negated safety flags with positive opt-ins; adds per-user transports and git scopes; makes admin imply all scopes; and makes allowWrites=false truly block every mutation.
See docs_page/updating.md for the full migration guide.
Breaking — removed
- Env vars:
SAP_READ_ONLY,SAP_BLOCK_DATA,SAP_BLOCK_FREE_SQL,SAP_ENABLE_TRANSPORTS,SAP_ENABLE_GIT,SAP_ALLOWED_OPS,SAP_DISALLOWED_OPS,ARC1_PROFILE,ARC1_API_KEY(single-key mode). - CLI flags:
--read-only,--block-data,--block-free-sql,--enable-transports,--enable-git,--allowed-ops,--disallowed-ops,--profile,--api-key. - Server config fields:
readOnly,blockData,blockFreeSQL,enableTransports,enableGit,allowedOps,disallowedOps,dryRun,transportReadOnly. - Server-side profile system (
PROFILES,PROFILE_SCOPEStables).
Startup aborts with a specific migration error pointing to docs_page/updating.md if any of these are set.
Breaking — added
- New env vars:
SAP_ALLOW_WRITES,SAP_ALLOW_DATA_PREVIEW,SAP_ALLOW_FREE_SQL,SAP_ALLOW_TRANSPORT_WRITES,SAP_ALLOW_GIT_WRITES,SAP_DENY_ACTIONS. All positive opt-ins; all defaults are restrictive. - New scopes (xs-security.json +
API_KEY_PROFILES):transports,git.adminnow implies all 7 scopes at extraction time. - New role templates:
MCPDeveloperbundles[read, write, transports, git];MCPAdminlists all 7 scopes explicitly. - New API-key profile
adminin addition to existingviewer/viewer-data/viewer-sql/developer/developer-data/developer-sql.
Fixed — six scope/safety classification bugs
SAPLint.set_formatter_settings— was scopereadat tool level, but the implementation calledOperationType.Update. Now correctly classified aswrite.SAPManage.flp_list_catalogs/flp_list_groups/flp_list_tiles— were scopewrite, but the implementation calledOperationType.Read. Now correctly classified asread.SAPTransport.check— was scopewrite, but is a read operation. Now correctlyread.SAPTransport.history— was scopewrite, but is a read operation. Now correctlyread.checkTransportdid not consultreadOnly(silent security gap). Transport mutations now requireallowWrites=true && allowTransportWrites=true.checkGitdid not consultreadOnly. Git mutations now requireallowWrites=true && allowGitWrites=true.
Added — observability
- Startup
effective safetylog line with per-field source attribution (env / flag / file / default). - Contradiction warnings for useless combos (e.g.,
allowTransportWrites=truewithallowWrites=false). - New
arc-1 config showCLI subcommand (--format=json|table) that dumps the resolved effective policy without starting the server. Exits non-zero on config error. - CI validator (
npm run validate:policy) assertsACTION_POLICYmatchessrc/handlers/schemas.tsaction/type enums.
0.6.10 (2026-04-20)
Features
- add SAPGit tool with gCTS and abapGit integration (#159) (196b8a0)
- diagnostic ADT type-availability probe (#163) (6bf4365)
Bug Fixes
- DTEL v2→v1 content-type fallback + SICF-aware error hints (#169) (1b6760f)
- e2e: make E2E suite pass cleanly on NetWeaver 7.50 (#168) (750be05)
- filter empty SAP_ALLOWED_PACKAGES entries and clarify docker docs (#156) (81001da)
- integration suite passes cleanly on NW 7.50 (#167) (1bc2984)
- make extract-sap-cookies work on Windows + Edge (fix #149) (#154) (8e87600)
0.6.9 (2026-04-17)
Features
- Add CDS-specific impact analysis (#143) (0dab061)
- FEAT-43 SAPRead for AUTH, FTG2, ENHO (on-prem) (#142) (2a827a1)
- fix cookie→PP leak, gate saml2=disabled, wire cookies & verbose CLI (#149) (74111ff)
- SAPLint PrettyPrint (ADT code formatter) (#145) (af6da11)
- SAPTransport history action (object transport reverse lookup) (#146) (8cae8f2)
- Source Version / Revision History (on-prem) (#144) (92f6ef2)
Bug Fixes
Tests
0.6.8 (2026-04-16)
Features
- add change_package action for moving objects between packages (#133) (de2bc1a)
- implementation for creationg sktd objects (#134) (1e8f59c)
Bug Fixes
0.6.7 (2026-04-15)
Features
- add concurrency limiter and 503 retry (#132) (ab18e25)
- add DCLS read/write support (FEAT-37) (#129) (b4424e2)
- add proactive ADT discovery MIME negotiation (#127) (418b3d1)
- implement FEAT-16 SAP-domain error intelligence hints (#128) (ce80aea)
Bug Fixes
0.6.6 (2026-04-14)
Bug Fixes
0.6.5 (2026-04-14)
Features
- add quickfix proposals and auto-fix from ATC findings (#123) (e3c4233)
- add SAP object type auto-normalization (#122) (750c835)
- extend abaplint CDS lint support for DDLS pre-write validation (#121) (b2324cc)
Bug Fixes
- add structured DDIC diagnostics, inactive syntax check, and BDEF package handling (#119) (20c7ddb)
- CF buildpack deployment fixes and BTP write tool support (#107) (5fb05e0)
- normalize SRVB bindingType and support OData V4 bindings (#120) (6e1735c)
- skip abaplint for non-ABAP types and add per-call lintBeforeWrite (#117) (362e429)
0.6.4 (2026-04-14)
Bug Fixes
0.6.3 (2026-04-14)
Bug Fixes
0.6.2 (2026-04-14)
Features
- add 401 session timeout auto-retry and XML attribute escaping (#85) (37f8839)
- Add DOMA/DTEL write support to SAPWrite (#86) (252d048)
- add FLP launchpad management via SAPManage (#87) (8026a84)
- BTP Cloud Foundry deployment with SAP Cloud SDK and MTA support (#97) (29e6685)
- CDS write robustness and error handling improvements (#101) (c06d884)
- DEVC package create/delete via SAPManage (#110) (72478d3)
- improve activation structured responses, inactive objects, preaudit (#90) (b8d5db0)
- MSAG (message class) read/write support (#109) (9a80416)
- safe by default — read-only, no SQL, no data preview out of the box (#89) (5a46c9c)
- SRVB (Service Binding) create/update/delete via SAPWrite (#111) (3e135a8)
- TABL create/update/delete support (#104) (03f1ece)
- transport enhancements — delete, reassign, types, recursive release (FEAT-39) (#88) (0f7ac83)
- transport pre-flight check for non-$TMP package writes (#99) (36d7787)
Bug Fixes
- align ADT API patterns with reference abap-adt-api implementation (#98) (9607510)
- enforce allowedPackages on all SAPWrite operations (#81) (5de8b44)
- feature probe only treats 404 as unavailable, not all HTTP errors (#95) (5119615)
- RAP write guard, block CDS writes when RAP unavailable (#93) (dea0099)
- remove RAP write guard that blocked all CDS/DDLS writes (#96) (5ffef19)
- transport hint false positive when corrNr present in URL path (#100) (2026702)
- use HEAD instead of GET for feature probing (#94) (4a8a156)
0.6.1 (2026-04-10)
Features
- add API release state tool for clean core compliance (FEAT-02) (#77) (57e5eaf)
- add BSP types and Atom XML parsers for UI5 filestore (#61) (264af14)
- add BSP_DEPLOY type for ABAP Repository OData queries (#66) (90a2fc6)
- add class hierarchy to SAPNavigate and fix doc inaccuracies (#70) (1831808)
- add publishServiceBinding and unpublishServiceBinding to devtools (#62) (ced5639)
- add transliteration, field hints, cache indicators (#64) (0ce3347)
- transport/write compatibility — CTS media types, 406/415 retry, corrNr auto-propagation (#78) (42f0786)
Bug Fixes
- add pre-cleanup for stale E2E write object (#76) (a5aa26f)
- correct Accept headers and entity expansion limit for ADT APIs (#69) (ff96ea8)
- implement comprehensive ADT API audit reports (#65) (9f210ab)
- improve LLM guidance for SAPSearch empty results and SAPContext CDS usage (#59) (1df565a)
Tests
- reliability hardening, fixtures, skip policy, coverage, try/catch, CRUD lifecycle, telemetry (#72) (be42998)
0.6.0 (2026-04-08)
⚠ BREAKING CHANGES
- simplify write safety — default $TMP, remove allowTransportableEdits, enforce package allowlist (#56)
Features
- add class metadata types and ADT metadata parser (#55) (0b44fb7)
- simplify write safety — default $TMP, remove allowTransportableEdits, enforce package allowlist (#56) (1f6ac1d)
0.5.0 (2026-04-08)
⚠ BREAKING CHANGES
- SAPQuery now requires 'data' scope (was 'read'), SAPTransport requires 'write' (was 'admin')
Features
- add J4D skills parity plan (#47) (df7ef1f)
- add textSearch smoketest at startup and other improvments (#45) (792ff5b)
- add Zod v4 runtime input validation for all MCP tools (#52) (9eea32a)
- two-dimensional authorization model (scopes, roles, safety) (#48) (8ce07d1)
Bug Fixes
- implement OAuth security review verification report(RFC 9700) (#51) (3ef81e1)
- use standard HTTP proxy for BTP connectivity (#43) (a60dd1b)
0.4.4 (2026-04-07)
Bug Fixes
- use native arm64 runners instead of QEMU for Docker builds (b65fba4)
0.4.3 (2026-04-07)
Bug Fixes
- use separate deps stage to avoid QEMU arm64 crash in Docker build (cab08fa)
0.4.2 (2026-04-07)
Bug Fixes
- avoid QEMU emulation crash in arm64 Docker build (7ea7883)
0.4.1 (2026-04-07)
Bug Fixes
- fix npm self-upgrade in release workflow (Node 22.22.x bug) (17b6bf3)
0.4.0 (2026-04-07)
Features
- add DDIC completeness — structures, domains, data elements, transactions (#21) (9e0fa2a)
- add DDLS support to SAPContext and include=elements to SAPRead (#30) (6a2883e)
- add LLM eval harness for testing tool-call accuracy (#33) (e8c8a65)
- add object caching with on-demand + pre-warmer support (#31) (8ba2f0d)
- add runtime diagnostics (short dumps + ABAP traces) to SAPDiagnose (#24) (ab177fc)
- DDLX, SRVB read support and batch activation for RAP completeness (#22) (402c57b)
- enhanced abaplint integration with system-aware presets and pre-write validation (#37) (f17d4fa)
- method-level surgery and hyperfocused mode (#23) (dbd27b9)
- scope-based Where-Used analysis for SAPNavigate (#38) (f805441)
Bug Fixes
0.3.0 (2026-04-01)
Features
0.2.0 (2026-03-31)
Features
- E2E testing infrastructure, XML error cleanup, and CI hardening (#13) (3830ff9)
- improve tooling based on real-world LLM feedback (#14) (3bcb59e)
Bug Fixes
- correct Docker image name to arc-1 and fix GHCR link (ae58467)
0.1.4 (2026-03-31)
Bug Fixes
- add repository field for npm OIDC provenance verification (b3a55aa)
0.1.3 (2026-03-31)
Bug Fixes
- install npm 11.5+ for OIDC trusted publishing support (300f846)
0.1.2 (2026-03-31)
Bug Fixes
- restore NPM_TOKEN for publish and reorganize docs navigation (6d76b4b)
- use npm OIDC trusted publishing instead of NPM_TOKEN (ab9f50c)
0.1.1 (2026-03-31)
Initial release. Ported from oisee/vibing-steampunk.