{
  "$schema": "https://verifymcp.io/schemas/changelog.json",
  "server": "com-hasdata-booking",
  "component": "hasdata-booking-mcp",
  "generated_at": "2026-09-21T06:58:42.726Z",
  "tracking_since": "2026-08-24",
  "counts": {
    "critical": 0,
    "security": 22,
    "functional": 0,
    "cosmetic": 0
  },
  "events": [
    {
      "id": "chg_01a0a869-d8f9-70c3-9bcd-8b2564d59b1d",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "fail",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "84",
        "assessed": "85",
        "resolved": "84",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-09-16",
      "occurred_at": "2026-09-16 04:11:44.157187+00",
      "observed_since": "2026-09-15",
      "source": "scan",
      "summary": "Known CVEs (fail → pass)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a0a869-d8f9-70c3-9bcd-8b2564d59b1d"
    },
    {
      "id": "chg_01a0a869-d8f9-752d-8027-2f148cedf91c",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-82417",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "medium",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-82417"
      },
      "occurred_on": "2026-09-16",
      "occurred_at": "2026-09-16 04:11:44.157187+00",
      "observed_since": "2026-09-15",
      "source": "scan",
      "summary": "CVE-2026-82417 no longer affects this package",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a0a869-d8f9-752d-8027-2f148cedf91c"
    },
    {
      "id": "chg_01a0a869-d8f7-7e66-bfd0-269332e7b2c9",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-82562",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "medium",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-82562"
      },
      "occurred_on": "2026-09-16",
      "occurred_at": "2026-09-16 04:11:44.157187+00",
      "observed_since": "2026-09-15",
      "source": "scan",
      "summary": "CVE-2026-82562 no longer affects this package",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a0a869-d8f7-7e66-bfd0-269332e7b2c9"
    },
    {
      "id": "chg_01a08983-5909-71d0-bb65-e9c7244b2df6",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "needs_declared_env",
        "status": "unreachable"
      },
      "occurred_on": "2026-09-10",
      "occurred_at": "2026-09-10 04:11:21.621206+00",
      "observed_since": "2026-09-09",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: this server's registry entry declares environment variables (an API key or similar) that our sandbox does not supply, so we have no schema to compare.)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a08983-5909-71d0-bb65-e9c7244b2df6"
    },
    {
      "id": "chg_01a08983-5907-7b8e-8c72-e3993e233e4e",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.transitive",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "mcp-remote > express > qs",
        "refs": "[\"CVE-2026-82417\",\"CVE-2026-82562\"]",
        "seen": "85",
        "package": "qs",
        "version": "6.15.3",
        "assessed": "86",
        "resolved": "85",
        "severity": "medium",
        "transitive": "1",
        "vulnerable": "[{\"name\":\"qs\",\"version\":\"6.15.3\",\"depth\":3,\"path\":[\"mcp-remote\",\"express\",\"qs\"],\"refs\":[\"CVE-2026-82417\",\"CVE-2026-82562\"]}]",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-09-10",
      "occurred_at": "2026-09-10 04:11:21.621206+00",
      "observed_since": "2026-09-09",
      "source": "scan",
      "summary": "Known CVEs (unverified → fail)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a08983-5907-7b8e-8c72-e3993e233e4e"
    },
    {
      "id": "chg_01a08983-5909-7721-911a-58af51fc2747",
      "kind": "check.reason",
      "family": "tool-safety-injection",
      "subject_kind": "check",
      "subject": "tool-safety-injection",
      "subject_child": "",
      "from_code": "toolsafety.sandbox_pending",
      "to_code": "toolsafety.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "needs_declared_env",
        "status": "unreachable"
      },
      "occurred_on": "2026-09-10",
      "occurred_at": "2026-09-10 04:11:21.621206+00",
      "observed_since": "2026-09-09",
      "source": "scan",
      "summary": "Tool safety (Tool safety not yet verified: this server's registry entry declares environment variables (an API key or similar) that our sandbox does not supply, so we have no tool text to scan.)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a08983-5909-7721-911a-58af51fc2747"
    },
    {
      "id": "chg_01a085a6-24b0-7d56-a4a4-6ca5f9b38c9e",
      "kind": "check.unverifiable",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.inconclusive",
      "from_value": "fail",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "root_version_missing"
      },
      "occurred_on": "2026-09-09",
      "occurred_at": "2026-09-09 10:10:53.211494+00",
      "observed_since": "2026-09-08",
      "source": "scan",
      "summary": "Known CVEs (fail → unverified)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a085a6-24b0-7d56-a4a4-6ca5f9b38c9e"
    },
    {
      "id": "chg_01a085a6-24b1-7f17-8a93-2242145f2606",
      "kind": "check.reason",
      "family": "tool-safety-injection",
      "subject_kind": "check",
      "subject": "tool-safety-injection",
      "subject_child": "",
      "from_code": "toolsafety.sandbox_failed",
      "to_code": "toolsafety.sandbox_pending",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "version_superseded"
      },
      "occurred_on": "2026-09-09",
      "occurred_at": "2026-09-09 10:10:53.211494+00",
      "observed_since": "2026-09-08",
      "source": "scan",
      "summary": "Tool safety (Tool safety not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet.)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a085a6-24b1-7f17-8a93-2242145f2606"
    },
    {
      "id": "chg_01a085a6-24b2-76fb-8a69-3e1726097427",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_failed",
      "to_code": "stability.sandbox_pending",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "version_superseded"
      },
      "occurred_on": "2026-09-09",
      "occurred_at": "2026-09-09 10:10:53.211494+00",
      "observed_since": "2026-09-08",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a085a6-24b2-76fb-8a69-3e1726097427"
    },
    {
      "id": "chg_01a06577-6267-7c8d-9721-1fcfbce510de",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-82417",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-82417",
        "severity": "medium"
      },
      "occurred_on": "2026-09-03",
      "occurred_at": "2026-09-03 04:11:57.851086+00",
      "observed_since": "2026-09-02",
      "source": "scan",
      "summary": "CVE-2026-82417 affects this package (medium)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a06577-6267-7c8d-9721-1fcfbce510de"
    },
    {
      "id": "chg_01a06577-6268-76e4-8036-c2b20b2cd0ed",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-82562",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-82562",
        "severity": "medium"
      },
      "occurred_on": "2026-09-03",
      "occurred_at": "2026-09-03 04:11:57.851086+00",
      "observed_since": "2026-09-02",
      "source": "scan",
      "summary": "CVE-2026-82562 affects this package (medium)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a06577-6268-76e4-8036-c2b20b2cd0ed"
    },
    {
      "id": "chg_01a06577-6268-7bda-9b19-2cc143a5cbc0",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.none",
      "to_code": "cve.transitive",
      "from_value": "pass",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "mcp-remote > express > qs",
        "refs": "[\"CVE-2026-82417\",\"CVE-2026-82562\"]",
        "seen": "84",
        "package": "qs",
        "version": "6.15.3",
        "assessed": "85",
        "resolved": "84",
        "severity": "medium",
        "transitive": "1",
        "vulnerable": "[{\"name\":\"qs\",\"version\":\"6.15.3\",\"depth\":3,\"path\":[\"mcp-remote\",\"express\",\"qs\"],\"refs\":[\"CVE-2026-82417\",\"CVE-2026-82562\"]}]",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-09-03",
      "occurred_at": "2026-09-03 04:11:57.851086+00",
      "observed_since": "2026-09-02",
      "source": "scan",
      "summary": "Known CVEs (pass → fail)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a06577-6268-7bda-9b19-2cc143a5cbc0"
    },
    {
      "id": "chg_01a04690-6e5b-7b00-bb85-cb07383727eb",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.none",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "84",
        "assessed": "85",
        "resolved": "84",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-08-28",
      "occurred_at": "2026-08-28 04:11:05.585912+00",
      "observed_since": "2026-08-27",
      "source": "scan",
      "summary": "Known CVEs (unverified → pass)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a04690-6e5b-7b00-bb85-cb07383727eb"
    },
    {
      "id": "chg_01a0427c-16dd-7513-9e02-9be937bb32f3",
      "kind": "provenance.repo_changed",
      "family": "build-provenance",
      "subject_kind": "package",
      "subject": "repo",
      "subject_child": "",
      "from_code": "provenance.none",
      "to_code": "provenance.verified",
      "from_value": null,
      "to_value": "HasData/booking-mcp",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "to": "HasData/booking-mcp",
        "from": ""
      },
      "occurred_on": "2026-08-27",
      "occurred_at": "2026-08-27 09:10:23.667562+00",
      "observed_since": "2026-08-26",
      "source": "scan",
      "summary": "The attested source repository moved (HasData/booking-mcp)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a0427c-16dd-7513-9e02-9be937bb32f3"
    },
    {
      "id": "chg_01a0427c-16da-7798-a54f-1d0701447df3",
      "kind": "check.verdict",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.none",
      "to_code": "provenance.verified",
      "from_value": "fail",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "repo": "HasData/booking-mcp"
      },
      "occurred_on": "2026-08-27",
      "occurred_at": "2026-08-27 09:10:23.667562+00",
      "observed_since": "2026-08-26",
      "source": "scan",
      "summary": "Provenance (fail → pass)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a0427c-16da-7798-a54f-1d0701447df3"
    },
    {
      "id": "chg_01a04169-a8cc-7731-a8ad-78932aa2af8c",
      "kind": "check.reason",
      "family": "tool-safety-injection",
      "subject_kind": "check",
      "subject": "tool-safety-injection",
      "subject_child": "",
      "from_code": "toolsafety.sandbox_pending",
      "to_code": "toolsafety.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "needs_declared_env",
        "status": "unreachable"
      },
      "occurred_on": "2026-08-27",
      "occurred_at": "2026-08-27 04:10:38.626703+00",
      "observed_since": "2026-08-26",
      "source": "scan",
      "summary": "Tool safety (Tool safety not yet verified: this server's registry entry declares environment variables (an API key or similar) that our sandbox does not supply, so we have no tool text to scan.)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a04169-a8cc-7731-a8ad-78932aa2af8c"
    },
    {
      "id": "chg_01a04169-a8cc-712a-a6a5-e2f2beadf435",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "needs_declared_env",
        "status": "unreachable"
      },
      "occurred_on": "2026-08-27",
      "occurred_at": "2026-08-27 04:10:38.626703+00",
      "observed_since": "2026-08-26",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: this server's registry entry declares environment variables (an API key or similar) that our sandbox does not supply, so we have no schema to compare.)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a04169-a8cc-712a-a6a5-e2f2beadf435"
    },
    {
      "id": "chg_01a04169-a8c9-7719-a7b0-d00bd99452fa",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.none",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "84",
        "assessed": "85",
        "resolved": "84",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-08-27",
      "occurred_at": "2026-08-27 04:10:38.626703+00",
      "observed_since": "2026-08-26",
      "source": "scan",
      "summary": "Known CVEs (unverified → pass)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a04169-a8c9-7719-a7b0-d00bd99452fa"
    },
    {
      "id": "chg_01a03ce7-c190-7d10-9199-a30e39c80e35",
      "kind": "check.unverifiable",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.none",
      "to_code": "cve.inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "root_version_missing"
      },
      "occurred_on": "2026-08-26",
      "occurred_at": "2026-08-26 07:10:16.203679+00",
      "observed_since": "2026-08-25",
      "source": "scan",
      "summary": "Known CVEs (pass → unverified)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a03ce7-c190-7d10-9199-a30e39c80e35"
    },
    {
      "id": "chg_01a03ce7-c192-72d3-a76a-469fcf97ea4c",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_failed",
      "to_code": "stability.sandbox_pending",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "version_superseded"
      },
      "occurred_on": "2026-08-26",
      "occurred_at": "2026-08-26 07:10:16.203679+00",
      "observed_since": "2026-08-25",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a03ce7-c192-72d3-a76a-469fcf97ea4c"
    },
    {
      "id": "chg_01a03ce7-c191-7e3a-814b-d9e544309f28",
      "kind": "check.appeared",
      "family": "tool-safety-injection",
      "subject_kind": "check",
      "subject": "tool-safety-injection",
      "subject_child": "",
      "from_code": null,
      "to_code": "toolsafety.sandbox_pending",
      "from_value": null,
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "version_superseded"
      },
      "occurred_on": "2026-08-26",
      "occurred_at": "2026-08-26 07:10:16.203679+00",
      "observed_since": "2026-08-25",
      "source": "scan",
      "summary": "First check of Tool safety (unverified)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a03ce7-c191-7e3a-814b-d9e544309f28"
    },
    {
      "id": "chg_01a0371c-e090-7c1e-95de-7a24f5fd480b",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-25",
      "occurred_at": "2026-08-25 04:10:34.403515+00",
      "observed_since": "2026-08-24",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/com-hasdata-booking/hasdata-booking-mcp#chg-chg_01a0371c-e090-7c1e-95de-7a24f5fd480b"
    }
  ],
  "days": [
    {
      "date": "2026-09-16",
      "total": 49,
      "delta": 2,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 3
    },
    {
      "date": "2026-09-10",
      "total": 47,
      "delta": 9,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 7
    },
    {
      "date": "2026-09-09",
      "total": 38,
      "delta": -9,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 8
    },
    {
      "date": "2026-09-04",
      "total": 47,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-03",
      "total": 47,
      "delta": -2,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 4
    },
    {
      "date": "2026-09-02",
      "total": 49,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-01",
      "total": 49,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-08-28",
      "total": 49,
      "delta": 11,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 2
    }
  ]
}