Skip to content

arc-mcp/arc-1

v1.2.0MIT

SAP ABAP development with the ARC-1 MCP server and portable skills for RAP, CDS, testing, migration, clean core, and UI5. Read-only by default.

Changelog

Generated by release-please — one line per merged PR. For what each release means (impact, upgrade actions, config and tool-surface changes), read the annotated release notes (source).

1.2.0 (2026-09-03)

Features

  • add experimental data-source blocklist (#740) (97560ae)
  • bound data-preview response memory (#739) (e0320b3)
  • identify direct-connect SAP systems in instructions (#735) (7969a9b)

Bug Fixes

  • security: patch pre-authentication decoder DoS in optional BTP AppRouter (#738) (3d89008)
  • read local-class methods from class includes (#744) (978c0fe)

1.1.2 (2026-08-31)

Bug Fixes

1.1.1 (2026-08-31)

Bug Fixes

  • add Agent Plugins 1.0 package (#695) (03ec895)
  • bind the ATC check variant SAPDiagnose claims to run (#708) (3c3e9f1)
  • forward user=* when listing transports across owners (#706) (e1b9dfb)
  • refresh runtime security packages before image scans (#726) (284935c)
  • resolve BSP paths from response metadata (#727) (c429720)
  • stop ATC polling once the worklist settles (#710) (4dcde5f)

1.1.0 (2026-08-18)

⚠ BREAKING CHANGES

  • SAPGit no longer accepts the advertised but unimplemented commit action. Use abapGit push for supported commit-and-push workflows; gCTS mutations remain quarantined.

Features

  • add SAPTransport action="diff" for transport review (#671) (475e6f0)
  • harden ARC-1 CLI for SAP CI workflows (#703) (8c09b81)

Bug Fixes

  • add opt-in gzip for WAF-blocked data-preview requests (#694) (ba3e1d9)
  • correct and harden ADT source text search (#683) (33546e3)
  • correct TABLE_QUERY IN value guidance (#691) (9fba0b6)
  • deps: resolve npm audit advisories in transitive dependencies (#672) (c24fb13)
  • never report a syntax check as clean when SAP refused to run it (#681) (a9aedeb)
  • read the CSRF token and session cookie atomically (#680) (9c29f6d)
  • support DDLS table functions on 7.50 (#693) (1f29817)

1.0.2 (2026-08-03)

Bug Fixes

  • restore the release gate that ran publish jobs on every push (#669) (d6d56f4)

1.0.1 (2026-08-03)

Bug Fixes

  • correct CTS transport checks (#659) (70bce30)
  • drop inapplicable FUNC processing metadata instead of rejecting the write (#665) (9f1ecbb)
  • load extension plugins on Windows (#662) (83bf1c5)
  • read FLP tiles through the Pages association instead of a $filter (#663) (7a1dee3)

1.0.0 (2026-07-31)

Features

  • add experimental destination-discovered multi-target endpoints (#579) (5ec27fc)
  • add procedural unit source surgery (#571) (b712616)
  • advertise configurable MCP server name per deployment (#606) (0374f83)
  • bound unbounded tool results, reject unknown params, compact JSON (#583) (5de5b96)
  • create Remote-Enabled and update-task function modules (#634) (91dc911)
  • DTDC (Dynamic Cache) read/write — generalize the server-driven engine off blue-only (#612) (dea5d0f)
  • FUGR structural includes, NW 7.50 release gates, FUNC processing-type read-back (#637) (3811587)
  • propagate W3C trace context to SAP and record calling-agent identity (#641) (a3d765a)
  • publish CycloneDX npm SBOM with releases (#633) (542f699)
  • read Launchpad App Descriptor Items (UIAD) and gate SDO types on discovery (#642) (a0d3f5c)
  • remove cache warmup (#573) (525aca3)
  • SAPDiagnose action=atc_variants — list ATC check variants + system default (FEAT-68) (#611) (3b0bc93)
  • serve RFC 9728 protected-resource metadata in OIDC mode (#632) (ee6922f)

Bug Fixes

  • abapgit: match the ADT bridge wire contract and support private repos (#635) (c60da36)
  • btp: allow jwt-bearer exchange against ARC-1's XSUAA client (#605) (cc7ad92)
  • don't crash startup on PP-off overrides, and harden the mta.yaml/mtaext stranding class (#582) (d7e2cb8)
  • harden multi-target behavior (#628) (879376d)
  • improve DDLS view-extension lint and diagnostics (#627) (871bb7e)
  • lead SAPWrite with its purpose and complete the TTYP documentation (#644) (cef92d0)
  • never block tools/list on startup feature discovery (#639) (c70390c)
  • per-type source format for server-driven objects (DTSC write was 415) + add DSFD (#604) (543f633)
  • propagate corrNr to the class-include init POST (#645) (#646) (0adb40e)
  • reconcile recursive transport release with terminal SAP state (#613) (002f24d)
  • reload rotated cookie file before the 401 retry (#631) (8103452)
  • security: patch and monitor AppRouter dependencies (#625) (7a0a835)
  • server: MCP 2026-07-28 forward-compat — CORS protocol headers, era-contract tests, ADR-0006 (#601) (dd99c17)
  • walk the AUnit result structure so alerts, program name and skips survive (#648) (0025ec3)
  • write: omit adtcore:responsible when it cannot be an on-prem user name (#638) (75bf274)

0.9.27 (2026-07-13)

Bug Fixes

  • pin release npm to 11.x so npm ci builds better-sqlite3 (#568) (d38eee2)

0.9.26 (2026-07-13)

Features

Bug Fixes

  • default minimal errors for HTTP (#552) (4ed0dcf)
  • harden change_package object type matching (#556) (940b7c5)
  • harden principal-propagation identity boundaries (d458c66)
  • improve SAPQuery Open SQL guidance (#559) (636eb6c)
  • make sqlite source cache explicit opt-in (#557) (7864e89)
  • open browser via rundll32 on Windows to preserve & in URLs (#549) (#555) (dbf2123)

0.9.25 (2026-07-02)

Features

  • read + write class text symbols via ADT textelements service (#541) (f7ac732)

Bug Fixes

  • default DCR client_id TTL to never-expire and warn when the signing secret is missing (#540) (dd833b8)

0.9.24 (2026-06-30)

Bug Fixes

  • foolproof add_method — auto-append missing terminating period (#536) (#539) (c525c04)
  • mcpb: ship the bundle unsigned so strict third-party hosts can install it (#537) (50a7948)

0.9.23 (2026-06-29)

Features

  • Add labels to source diffs (#528) (bd6e520)
  • cloud-correct object create on BTP ABAP Environment (G-2..G-5) (#522) (515b91f)
  • create packages on the BTP ABAP Environment (cloud-correct DEVC body) (#534) (25a017b)

Bug Fixes

  • serve just-activated source on next read without force_refresh (#530) (c7535d3)

Tests

  • btp: cover SDO create + tool-level dispatch on BTP; fix smoke read-restriction assertion (#533) (d124ead)
  • btp: verify + cover SRVB update on the ABAP Environment (B3) (#532) (3a0b403)
  • verify RAP-stack (BDEF/SRVD/SRVB) cloud create on BTP (#529) (8451372)

0.9.22 (2026-06-26)

Features

  • add DDIC structure context (#515) (76e24dc)
  • diagnose: odata_perf client-wait + debug-slow-sql field findings (#521) (ddb0ffe)
  • S/4HANA Public Cloud support (#524) (bdcd330)

Bug Fixes

  • make nullable SAPWrite schemas opt-in (#526) (992ce76)

Tests

  • cover per-user Cloud Connector proxy selection (#525) (d755ff9)

0.9.21 (2026-06-25)

Features

  • ddic: TTYP (table type) read + create (FEAT-65) (#504) (22c49b6)
  • diagnose: ABAP Unit test coverage (statement/branch/procedure) for SAPDiagnose (#503) (f6ab40e)
  • diagnose: OData sap-statistics perf probe + CDS Show-SQL + ICF-inactive guard (#509) (f111216)
  • diagnose: ST05 SQL-trace state control + record-viewer directory (#510) (a54a99b)
  • fugr: write FUGR structural include source (#505) (0e4f522)
  • manage: SAPManage set_api_state — write an object's API release contract (clean-core) (#506) (30d68fd)
  • query: self-correcting "unknown column" hint for SAPQuery + TABLE_QUERY (FEAT-64) (#502) (39c119b)
  • rap: create RAP behavior extensions (extend behavior for) (#507) (209893b)
  • SAPQuery datapreview metrics + SAPDiagnose ABAP trace requests (#508) (b10fab9)
  • transport: pre-release inactive-objects check + fix misleading K/W/T create claim (#501) (3519b1b)
  • transport: surface release-check report from SAPTransport release (#514) (fd7e907)

Bug Fixes

  • add minimal client-facing SAP errors (#495) (f6b7fea)
  • cli: send correct arg shapes from sql/search shortcuts (#512) (b7e5325)
  • create audit and cache files privately (#496) (b409672)
  • default deployment descriptors to verified SAP TLS (#491) (e70eaf7)
  • diagnose: correct odata_perf "app" verdict note (#513) (fe12767)
  • enforce package allowlist for gCTS mutations (#490) (dfce4be)
  • fail closed on principal propagation errors (#488) (8c22795)
  • gate quickfix application as a write (#489) (f25dce5)
  • probe UI5 BSP filestore via /objects, not the handler-less bare node (#498) (0f1676c)
  • redact audit events before sink writes (#493) (f7af34e)
  • require auth for HTTP transport (#487) (46c68a0)
  • warn on insecure SAP TLS and encode trace paths (#494) (b67586e)

0.9.20 (2026-06-22)

Features

  • add context-first KTD workflow with guarded writes (#486) (32cc3bc)
  • add read-only UI console (#485) (68b3f2a)
  • extensions: gated non-ADT writes via ctx.http (v2 §2.2 Path B) (#474) (4294c94)

Bug Fixes

  • avoid regex backtracking in ADT error parsing (#476) (48b32bc)

0.9.19 (2026-06-18)

Features

  • auth: use @arc-mcp/xsuaa-auth for XSUAA/OAuth + BTP principal propagation (#456) (0e4795b)
  • config: reject non-3-digit SAP_CLIENT at startup (#471) (4e1b8e4)
  • extensions: extension framework for Custom_* plugin tools (#454) (7425f00)

Bug Fixes

  • auth: adopt @arc-mcp/xsuaa-auth hardened OIDC + constant-time api-key verifiers (#468) (2dfb512)
  • extensions: close 2 policy-boundary gaps + doc sharp edges (post-merge review) (#467) (8c6bbb4)

0.9.18 (2026-06-16)

Features

  • SAPRead: add action="diff" for server-side single-system version diff (#445) (7d603ef)
  • SAPTransport: add summary=true headers-only mode for list (#448) (3ac3619)

Bug Fixes

  • startup: quiet expected feature-probe log noise + deployment/onboarding docs (#444) (951cb38)

0.9.17 (2026-06-15)

Features

  • transport: add SAPTransport remove_object to clean an object out of a request (#432) (fc4e7d4)

Bug Fixes

  • clearer guidance for cross-subaccount OAuth2UserTokenExchange (#436) (226c437), closes #434
  • http: handle 304/204/205 null-body status on Cloud Connector proxy path (#440) (9e3906e)

0.9.16 (2026-06-12)

Bug Fixes

  • initialise class test include surgery (#429) (f076a67)

0.9.15 (2026-06-12)

Features

  • one-step "Install in Claude" — Claude Code plugin, MCPB bundle, tool annotations (#425) (48013b7)

Bug Fixes

  • adt: make SRVB publish/unpublish content negotiation 758-proof (#403) (909f253)
  • cache: batch warmup writes in transactions (#417) (6a5ec76)
  • config: empty env values fall back to defaults (fail closed, not fail open) (#427) (cd32f54)
  • context: avoid SAPContext dependency convoy (#411) (f37373b)
  • docker: patch OpenSSL CVE-2026-45447 and harden release CVE gate (#400) (951ca09)
  • handlers: accept any maxResults number, floor+clamp at the sinks (#423) (1eb1758)
  • type-check the test suite + split intent.test.ts (#405) (5cb235c)
  • xml: make XML escaping single pass (#414) (df0c285)
  • xml: reuse parser array tag set (#412) (2d12d3d)

Tests

  • handlers: Zod↔JSON-Schema type-parity guard (#415) (0855e2c)
  • isolate concurrent integration/e2e runs, add teardown janitor, fix flake (#426) (5895a75)
  • rename dispatch-rate-limit test, featuresOff() sweep, strip intent.ts provenance (#410) (8a34886)
  • server: de-flake auth-rate-limit (one server per test) + diagnosable transport errors (#424) (96fb89d)

Performance Improvements

  • lint: memoize abaplint default configs (#413) (1e78acb)

0.9.14 (2026-06-11)

Bug Fixes

0.9.13 (2026-06-09)

Bug Fixes

  • git: enforce package allowlist on abapGit pull/push (#389) (82cec9b)
  • limits: clamp unbounded result limits to prevent resource exhaustion (#388) (9656162)
  • oauth: match redirect-uri allowlist against parsed URL components (#387) (c795b53)
  • transport: delete requests holding locked objects via removeLockedObjects (#386) (e64b497)

0.9.12 (2026-06-09)

Features

  • diagnose: SAPDiagnose action=cds_testcases — CDS test-case scaffolding (#351) (b54ccd0)
  • read: generic server-driven object read — SAPRead DESD/EVTB/DTSC/CSNM/EVTO/COTA (#356) (ce3dacc)
  • write: server-driven object write — SAPWrite create/update/delete + SAPActivate (DESD/EVTB/DTSC/CSNM/EVTO/COTA) (#362) (0c7f0a6)
  • xsuaa: raise default refresh-token-validity to 30 days (#383) (8e0ee71)

Bug Fixes

  • handlers: harden tool-arg validation against GPT/OpenAI schema pollution (#363) (138d89c)
  • security: close scope-router privilege escalation and bind OAuth state to client_id (#352) (ba0a21b)
  • security: enforce allowedPackages ceiling on activation and change_package (#357) (2a1135e)
  • security: XSUAA redirect-uri allowlist for the shared default client (#358) (d204eb8)
  • write: emit pak:recordChanges so transportable package creation works on SAP_BASIS 816 (#375) (00e4197)
  • write: thread logon user into adtcore:responsible (#380) (3f8dc12)

Tests

0.9.11 (2026-06-05)

Bug Fixes

  • lint: don't block writes on parse errors beyond abaplint's grammar (8xx / SAP_BASIS 816) (#350) (79b5687)
  • probe: repair broken probe CLI and validate ABAP Platform 2025 (SAP_BASIS 816) (#347) (6c307ec)

0.9.10 (2026-06-05)

Bug Fixes

  • adt/client: copy tablWriteUrlCache in withSafety() clone (#335) (dbcd8a1)

0.9.9 (2026-06-04)

Features

  • fugr: recursive include expansion for SAPRead(type=FUGR) — captures function module code (#341) (2f99335)
  • transport: set explicit transport target (TR_TARGET) on SAPTransport.create (#339) (95d6a9c)

Bug Fixes

  • atc: bind check variant via worklist so SAPDiagnose(atc) returns findings (#336) (5386465)
  • deps: bump express-rate-limit to 8.5.2 and key IPv6 by /56 subnet (#330) (1bb5e31)
  • fugr: non-expand SAPRead(FUGR) returns the real function-module list (objectstructure) (#342) (93b6c22)
  • surface XSUAA OAuth errors on /oauth/callback + don't prefix reserved scopes (#327) (f7418ed)
  • write: derive created-object master language from SAP_LANGUAGE (#344) (18672fd)

0.9.8 (2026-06-01)

Bug Fixes

  • callback proxy for XSUAA OAuth state — fixes "State does not match" from VS Code (#325) (c41ed97)

0.9.7 (2026-05-30)

Features

  • auto-initialise class-local includes on write (testclasses/CCAU) (#314) (2a7bdc0)
  • class-section surgery for CLAS (#307) (7d17ea2)
  • read: add TABLE_QUERY type for multi-column structured queries (#309) (7eb01f4)
  • read: SAPRead grep — regex search within object source (#316) (0d338e2)
  • safety: allowedPackages X/** subtree rule + nodestructure-backed resolver (#284) (2d34909)

Bug Fixes

  • btp: per-user OAuth2UserTokenExchange Bearer token for headless BTP → ABAP (#315) (d5bb9ca)
  • http: dedupe Cookie header so live session id wins over stale file copy (#293, part 1) (#310) (fdb478e)
  • intent: replace 3 raw NUL bytes in source with \x00 escapes (#317) (d125142)
  • release-aware 423 lock-handle guidance (#312) (9c7e021)
  • write: reject mixed-case object names on update/edit_method/delete (#311) (2cff142)

Tests

  • clean up transport test requests (#308) (5d643d2)
  • convert pseudo skips to real skips (#304) (73437e8)
  • e2e: fix ZI_ARC1_I33_PROJ fixture activation on S/4HANA 2023 (#318) (9d8ac15)
  • harden e2e fixture activation (#306) (ab5eaa7)

0.9.6 (2026-05-27)

Features

  • ARC-1-native pre-write hint for canonical %admin draft include (#271) (21ac60b)
  • layered rate limiting (Layers 1+2+3) (#276) (1994298)

Bug Fixes

  • features: fall back to syntax-configurations endpoint for abapRelease (95ce9bc)
  • refuse TABL/DT writes on NW 7.50/7.51 with SE11 hint (#285) (#286) (b098140)
  • route TABL/DS create to /ddic/structures (#302) (039d800)

0.9.5 (2026-05-11)

Features

  • add SAPSearch tadir_lookup source modes + SAPWrite batch_create activateAtEnd (#270) (dec53b4)
  • stable DCR signing key + 0/negative TTL = infinite (#267) (1b4b191)

Bug Fixes

  • rap: write handler skeletons to CCIMP, not CCDEF (#263) (60773f6)

0.9.4 (2026-05-10)

Features

  • add FUNC structured-parameter support (#259) (154db0f)
  • add sprint 3 diagnostics cleanup (#254) (0bb34cc)
  • add TADIR lookup and batch package overrides (#256) (dc2fe3d)
  • edit_method splices into class-local includes (CCDEF/CCIMP) (#261) (99ba5a1)
  • SAPWrite generate_behavior_implementation action (PR-C) (#260) (5151d13)

Bug Fixes

  • harden apply_quickfix payloads (#253) (a859fc5)
  • retry ED064 activation and support ABAP release lint override (#255) (8cc8833)
  • support class include writes and RAP skeletons (#257) (c4ac325)

0.9.3 (2026-05-09)

Bug Fixes

  • add FUGR + FUNC create/update/delete (#251) (f5ed2b8)
  • btp: harden CF deploy + add Viewer+SQL XSUAA role-collection (#246) (a3bfb5e)

0.9.2 (2026-05-08)

Bug Fixes

  • ci: re-trigger release after #244 chore-merge (6345625)

0.9.1 (2026-05-08)

Bug Fixes

  • adt: align DEVC listing descriptions with object names (#242) (63cfc70)
  • adt: decode XML entities in parseSearchResults description (#243) (c522866)
  • docker: drop bundled npm CLI from runtime image (#240) (e480206)

0.9.0 (2026-05-08)

⚠ BREAKING CHANGES

  • MSAG read enum + FTG2→FEATURE_TOGGLE rename (audit Plan B) (#224)
  • callers that passed type='FUNC/FM', 'CLAS/LI', 'VIEW/V', or 'TRAN/O' will now fail Zod schema validation. Migrate to FUGR/FF, CLAS/I (if needed — currently absent), VIEW/DV, TRAN/T respectively, or use the canonical short forms FUNC/CLAS/VIEW/TRAN.
  • SAPRead/SAPWrite/SAPActivate no longer accept type='STRU'. Callers must use type='TABL' for both transparent tables and DDIC structures. ARC-1 ships pre-1.0; the slash form 'STRU/DS' is preserved as a back-compat alias inside SLASH_TYPE_MAP only.

Features

  • cookie hot-reload on stale 401 (#200) (23d4bfe)
  • layered lock-conflict detection + MSAG transport guard (#202) (cf0a126)
  • MSAG read enum + FTG2→FEATURE_TOGGLE rename (audit Plan B) (#224) (d4c0fd3)
  • purge invented ADT slash aliases (issue #218 audit, Plan A) (#223) (e130b87)
  • three-file sync (messages + STRU) + universal write guards (#201) (2afedf1)

Bug Fixes

  • adt: tighten HTML entity decoder + tag stripper (CodeQL alerts 6, 7, 8) (#238) (3bd7dac)
  • collapse STRU type into TABL (#219) (1a310e9)
  • SAPTransport.create works on NW 7.50 (non-breaking, defaults DEVCLASS=$TMP) (#228) (fc29c41)

Tests

  • add SAPLint PrettyPrint and revision eval scenarios (#151) (283b744)

0.8.0 (2026-05-06)

⚠ BREAKING CHANGES

  • make OAuth DCR registrations survive container restarts (#212)

Features

  • ARC1_PUBLIC_URL env var for reverse-proxy / different-hostname deployments (#216) (6e219dd)
  • HTTP security headers (helmet) + opt-in CORS for browser MCP clients (#215) (8929d21)
  • make OAuth DCR registrations survive container restarts (#212) (0d78a6b)

Bug Fixes

  • defensive dumpId encoding + endpoint-aware 403 hints (#206) (9046fa7)

0.7.2 (2026-04-28)

Features

  • ETag-validated source cache + active/inactive SAPRead version parameter (#186) (70bed22)

Bug Fixes

  • detect HANA via S4CORE/HDB components (#182) (87ec553)

0.7.1 (2026-04-27)

Bug Fixes

0.7.0 (2026-04-26)

⚠ BREAKING CHANGES

  • authorization refactor (#181)

Features

  • add cds crud dependency guidance for ddls workflows (#176) (f597486)
  • authorization refactor (#181) (7be4ff0)
  • close RAP on-prem authoring gaps with preflight and handler scaffolding (#173) (29ee0b5)
  • detect sibling DDLS DDLX coverage mismatches in SAPContext impact (#177) (4f6e822)
  • harden SAPDiagnose dump and gateway diagnostics (#174) (9383891)

Bug Fixes

  • harden SAP data preview diagnostics and SAPManage scope behavior (#171) (6697d3e)
  • SAPActivate phantom success + CLI/server alignment gaps (NW 7.50) (#179) (4f2028e)

[Unreleased] — v0.7 — Authorization Refactor (breaking change)

Complete rewrite of the authorization model. Introduces a single ACTION_POLICY matrix as the source of truth for (tool, action) → (scope, opType); replaces negated safety flags with positive opt-ins; adds per-user transports and git scopes; makes admin imply all scopes; and makes allowWrites=false truly block every mutation.

See docs_page/updating.md for the full migration guide.

Breaking — removed

  • Env vars: SAP_READ_ONLY, SAP_BLOCK_DATA, SAP_BLOCK_FREE_SQL, SAP_ENABLE_TRANSPORTS, SAP_ENABLE_GIT, SAP_ALLOWED_OPS, SAP_DISALLOWED_OPS, ARC1_PROFILE, ARC1_API_KEY (single-key mode).
  • CLI flags: --read-only, --block-data, --block-free-sql, --enable-transports, --enable-git, --allowed-ops, --disallowed-ops, --profile, --api-key.
  • Server config fields: readOnly, blockData, blockFreeSQL, enableTransports, enableGit, allowedOps, disallowedOps, dryRun, transportReadOnly.
  • Server-side profile system (PROFILES, PROFILE_SCOPES tables).

Startup aborts with a specific migration error pointing to docs_page/updating.md if any of these are set.

Breaking — added

  • New env vars: SAP_ALLOW_WRITES, SAP_ALLOW_DATA_PREVIEW, SAP_ALLOW_FREE_SQL, SAP_ALLOW_TRANSPORT_WRITES, SAP_ALLOW_GIT_WRITES, SAP_DENY_ACTIONS. All positive opt-ins; all defaults are restrictive.
  • New scopes (xs-security.json + API_KEY_PROFILES): transports, git. admin now implies all 7 scopes at extraction time.
  • New role templates: MCPDeveloper bundles [read, write, transports, git]; MCPAdmin lists all 7 scopes explicitly.
  • New API-key profile admin in addition to existing viewer/viewer-data/viewer-sql/developer/developer-data/developer-sql.

Fixed — six scope/safety classification bugs

  1. SAPLint.set_formatter_settings — was scope read at tool level, but the implementation called OperationType.Update. Now correctly classified as write.
  2. SAPManage.flp_list_catalogs / flp_list_groups / flp_list_tiles — were scope write, but the implementation called OperationType.Read. Now correctly classified as read.
  3. SAPTransport.check — was scope write, but is a read operation. Now correctly read.
  4. SAPTransport.history — was scope write, but is a read operation. Now correctly read.
  5. checkTransport did not consult readOnly (silent security gap). Transport mutations now require allowWrites=true && allowTransportWrites=true.
  6. checkGit did not consult readOnly. Git mutations now require allowWrites=true && allowGitWrites=true.

Added — observability

  • Startup effective safety log line with per-field source attribution (env / flag / file / default).
  • Contradiction warnings for useless combos (e.g., allowTransportWrites=true with allowWrites=false).
  • New arc-1 config show CLI subcommand (--format=json|table) that dumps the resolved effective policy without starting the server. Exits non-zero on config error.
  • CI validator (npm run validate:policy) asserts ACTION_POLICY matches src/handlers/schemas.ts action/type enums.

0.6.10 (2026-04-20)

Features

  • add SAPGit tool with gCTS and abapGit integration (#159) (196b8a0)
  • diagnostic ADT type-availability probe (#163) (6bf4365)

Bug Fixes

  • DTEL v2→v1 content-type fallback + SICF-aware error hints (#169) (1b6760f)
  • e2e: make E2E suite pass cleanly on NetWeaver 7.50 (#168) (750be05)
  • filter empty SAP_ALLOWED_PACKAGES entries and clarify docker docs (#156) (81001da)
  • integration suite passes cleanly on NW 7.50 (#167) (1bc2984)
  • make extract-sap-cookies work on Windows + Edge (fix #149) (#154) (8e87600)

0.6.9 (2026-04-17)

Features

  • Add CDS-specific impact analysis (#143) (0dab061)
  • FEAT-43 SAPRead for AUTH, FTG2, ENHO (on-prem) (#142) (2a827a1)
  • fix cookie→PP leak, gate saml2=disabled, wire cookies & verbose CLI (#149) (74111ff)
  • SAPLint PrettyPrint (ADT code formatter) (#145) (af6da11)
  • SAPTransport history action (object transport reverse lookup) (#146) (8cae8f2)
  • Source Version / Revision History (on-prem) (#144) (92f6ef2)

Bug Fixes

  • modificationSupport guard + CSRF HEAD→GET fallback for S/4HANA Public Cloud (#140) (9fcd4aa)

Tests

  • restructure LLM evals by feature bucket + live MCP backend (#147) (27f4f51)

0.6.8 (2026-04-16)

Features

  • add change_package action for moving objects between packages (#133) (de2bc1a)
  • implementation for creationg sktd objects (#134) (1e8f59c)

Bug Fixes

  • retry all HTTP methods on 503 and add CSRF token retry (#135) (39e3529)

0.6.7 (2026-04-15)

Features

  • add concurrency limiter and 503 retry (#132) (ab18e25)
  • add DCLS read/write support (FEAT-37) (#129) (b4424e2)
  • add proactive ADT discovery MIME negotiation (#127) (418b3d1)
  • implement FEAT-16 SAP-domain error intelligence hints (#128) (ce80aea)

Bug Fixes

  • route SRVB publish/unpublish to correct OData version endpoint (#130) (9b0601c)

0.6.6 (2026-04-14)

Bug Fixes

  • wait for Docker image before publishing to MCP Registry (#125) (cab65bc)

0.6.5 (2026-04-14)

Features

  • add quickfix proposals and auto-fix from ATC findings (#123) (e3c4233)
  • add SAP object type auto-normalization (#122) (750c835)
  • extend abaplint CDS lint support for DDLS pre-write validation (#121) (b2324cc)

Bug Fixes

  • add structured DDIC diagnostics, inactive syntax check, and BDEF package handling (#119) (20c7ddb)
  • CF buildpack deployment fixes and BTP write tool support (#107) (5fb05e0)
  • normalize SRVB bindingType and support OData V4 bindings (#120) (6e1735c)
  • skip abaplint for non-ABAP types and add per-call lintBeforeWrite (#117) (362e429)

0.6.4 (2026-04-14)

Bug Fixes

  • add MCP Registry OCI annotation to Dockerfile (#115) (15c4354)

0.6.3 (2026-04-14)

Bug Fixes

  • add mcpName for MCP Registry publishing (#113) (bd346c5)

0.6.2 (2026-04-14)

Features

  • add 401 session timeout auto-retry and XML attribute escaping (#85) (37f8839)
  • Add DOMA/DTEL write support to SAPWrite (#86) (252d048)
  • add FLP launchpad management via SAPManage (#87) (8026a84)
  • BTP Cloud Foundry deployment with SAP Cloud SDK and MTA support (#97) (29e6685)
  • CDS write robustness and error handling improvements (#101) (c06d884)
  • DEVC package create/delete via SAPManage (#110) (72478d3)
  • improve activation structured responses, inactive objects, preaudit (#90) (b8d5db0)
  • MSAG (message class) read/write support (#109) (9a80416)
  • safe by default — read-only, no SQL, no data preview out of the box (#89) (5a46c9c)
  • SRVB (Service Binding) create/update/delete via SAPWrite (#111) (3e135a8)
  • TABL create/update/delete support (#104) (03f1ece)
  • transport enhancements — delete, reassign, types, recursive release (FEAT-39) (#88) (0f7ac83)
  • transport pre-flight check for non-$TMP package writes (#99) (36d7787)

Bug Fixes

  • align ADT API patterns with reference abap-adt-api implementation (#98) (9607510)
  • enforce allowedPackages on all SAPWrite operations (#81) (5de8b44)
  • feature probe only treats 404 as unavailable, not all HTTP errors (#95) (5119615)
  • RAP write guard, block CDS writes when RAP unavailable (#93) (dea0099)
  • remove RAP write guard that blocked all CDS/DDLS writes (#96) (5ffef19)
  • transport hint false positive when corrNr present in URL path (#100) (2026702)
  • use HEAD instead of GET for feature probing (#94) (4a8a156)

0.6.1 (2026-04-10)

Features

  • add API release state tool for clean core compliance (FEAT-02) (#77) (57e5eaf)
  • add BSP types and Atom XML parsers for UI5 filestore (#61) (264af14)
  • add BSP_DEPLOY type for ABAP Repository OData queries (#66) (90a2fc6)
  • add class hierarchy to SAPNavigate and fix doc inaccuracies (#70) (1831808)
  • add publishServiceBinding and unpublishServiceBinding to devtools (#62) (ced5639)
  • add transliteration, field hints, cache indicators (#64) (0ce3347)
  • transport/write compatibility — CTS media types, 406/415 retry, corrNr auto-propagation (#78) (42f0786)

Bug Fixes

  • add pre-cleanup for stale E2E write object (#76) (a5aa26f)
  • correct Accept headers and entity expansion limit for ADT APIs (#69) (ff96ea8)
  • implement comprehensive ADT API audit reports (#65) (9f210ab)
  • improve LLM guidance for SAPSearch empty results and SAPContext CDS usage (#59) (1df565a)

Tests

  • reliability hardening, fixtures, skip policy, coverage, try/catch, CRUD lifecycle, telemetry (#72) (be42998)

0.6.0 (2026-04-08)

⚠ BREAKING CHANGES

  • simplify write safety — default $TMP, remove allowTransportableEdits, enforce package allowlist (#56)

Features

  • add class metadata types and ADT metadata parser (#55) (0b44fb7)
  • simplify write safety — default $TMP, remove allowTransportableEdits, enforce package allowlist (#56) (1f6ac1d)

0.5.0 (2026-04-08)

⚠ BREAKING CHANGES

  • SAPQuery now requires 'data' scope (was 'read'), SAPTransport requires 'write' (was 'admin')

Features

  • add J4D skills parity plan (#47) (df7ef1f)
  • add textSearch smoketest at startup and other improvments (#45) (792ff5b)
  • add Zod v4 runtime input validation for all MCP tools (#52) (9eea32a)
  • two-dimensional authorization model (scopes, roles, safety) (#48) (8ce07d1)

Bug Fixes

  • implement OAuth security review verification report(RFC 9700) (#51) (3ef81e1)
  • use standard HTTP proxy for BTP connectivity (#43) (a60dd1b)

0.4.4 (2026-04-07)

Bug Fixes

  • use native arm64 runners instead of QEMU for Docker builds (b65fba4)

0.4.3 (2026-04-07)

Bug Fixes

  • use separate deps stage to avoid QEMU arm64 crash in Docker build (cab08fa)

0.4.2 (2026-04-07)

Bug Fixes

  • avoid QEMU emulation crash in arm64 Docker build (7ea7883)

0.4.1 (2026-04-07)

Bug Fixes

  • fix npm self-upgrade in release workflow (Node 22.22.x bug) (17b6bf3)

0.4.0 (2026-04-07)

Features

  • add DDIC completeness — structures, domains, data elements, transactions (#21) (9e0fa2a)
  • add DDLS support to SAPContext and include=elements to SAPRead (#30) (6a2883e)
  • add LLM eval harness for testing tool-call accuracy (#33) (e8c8a65)
  • add object caching with on-demand + pre-warmer support (#31) (8ba2f0d)
  • add runtime diagnostics (short dumps + ABAP traces) to SAPDiagnose (#24) (ab177fc)
  • DDLX, SRVB read support and batch activation for RAP completeness (#22) (402c57b)
  • enhanced abaplint integration with system-aware presets and pre-write validation (#37) (f17d4fa)
  • method-level surgery and hyperfocused mode (#23) (dbd27b9)
  • scope-based Where-Used analysis for SAPNavigate (#38) (f805441)

Bug Fixes

  • post-merge consistency — SAPLint schema cleanup and objectUrlForType completeness (#26) (214ebec)

0.3.0 (2026-04-01)

Features

  • direct BTP ABAP Environment connectivity via OAuth 2.0 (#18) (b1cf86c)

0.2.0 (2026-03-31)

Features

  • E2E testing infrastructure, XML error cleanup, and CI hardening (#13) (3830ff9)
  • improve tooling based on real-world LLM feedback (#14) (3bcb59e)

Bug Fixes

  • correct Docker image name to arc-1 and fix GHCR link (ae58467)

0.1.4 (2026-03-31)

Bug Fixes

  • add repository field for npm OIDC provenance verification (b3a55aa)

0.1.3 (2026-03-31)

Bug Fixes

  • install npm 11.5+ for OIDC trusted publishing support (300f846)

0.1.2 (2026-03-31)

Bug Fixes

  • restore NPM_TOKEN for publish and reorganize docs navigation (6d76b4b)
  • use npm OIDC trusted publishing instead of NPM_TOKEN (ab9f50c)

0.1.1 (2026-03-31)

Initial release. Ported from oisee/vibing-steampunk.