{
  "$schema": "https://verifymcp.io/schemas/changelog.json",
  "server": "toolstem-toolstem-sec-mcp-server",
  "component": "toolstem-sec-mcp-server",
  "generated_at": "2026-09-24T04:08:04.323Z",
  "tracking_since": "2026-07-27",
  "counts": {
    "critical": 0,
    "security": 17,
    "functional": 0,
    "cosmetic": 0
  },
  "events": [
    {
      "id": "chg_01a0acbc-173b-76ef-bcdb-92c97898aca0",
      "kind": "check.verdict",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.stable",
      "from_value": "0.97",
      "to_value": "pass",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-17",
      "occurred_at": "2026-09-17 00:20:02.801418+00",
      "observed_since": "2026-09-16",
      "source": "scan",
      "summary": "Stability (0.97 → pass)",
      "link": "https://verifymcp.io/servers/toolstem-toolstem-sec-mcp-server/toolstem-sec-mcp-server#chg-chg_01a0acbc-173b-76ef-bcdb-92c97898aca0"
    },
    {
      "id": "chg_01a088a4-4d99-7baa-b23a-6739c7ba8771",
      "kind": "check.verdict",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.stable",
      "from_value": "0.97",
      "to_value": "pass",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-10",
      "occurred_at": "2026-09-10 00:07:44.190489+00",
      "observed_since": "2026-09-09",
      "source": "scan",
      "summary": "Stability (0.97 → pass)",
      "link": "https://verifymcp.io/servers/toolstem-toolstem-sec-mcp-server/toolstem-sec-mcp-server#chg-chg_01a088a4-4d99-7baa-b23a-6739c7ba8771"
    },
    {
      "id": "chg_01a069c1-3cf9-7dc9-9e24-addec33bbc7d",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-71429",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-71429",
        "severity": "medium"
      },
      "occurred_on": "2026-09-04",
      "occurred_at": "2026-09-04 00:11:06.818389+00",
      "observed_since": "2026-09-03",
      "source": "scan",
      "summary": "CVE-2026-71429 affects this package (medium)",
      "link": "https://verifymcp.io/servers/toolstem-toolstem-sec-mcp-server/toolstem-sec-mcp-server#chg-chg_01a069c1-3cf9-7dc9-9e24-addec33bbc7d"
    },
    {
      "id": "chg_01a069c1-3cfb-7345-b5fe-e6aaf3dfadd9",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.none",
      "to_code": "cve.transitive",
      "from_value": "pass",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "apify > @crawlee/core > stream-json",
        "refs": "[\"CVE-2026-71429\"]",
        "seen": "263",
        "package": "stream-json",
        "version": "1.9.1",
        "assessed": "264",
        "resolved": "263",
        "severity": "medium",
        "transitive": "1",
        "vulnerable": "[{\"name\":\"stream-json\",\"version\":\"1.9.1\",\"depth\":3,\"path\":[\"apify\",\"@crawlee/core\",\"stream-json\"],\"refs\":[\"CVE-2026-71429\"]}]",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-09-04",
      "occurred_at": "2026-09-04 00:11:06.818389+00",
      "observed_since": "2026-09-03",
      "source": "scan",
      "summary": "Known CVEs (pass → fail)",
      "link": "https://verifymcp.io/servers/toolstem-toolstem-sec-mcp-server/toolstem-sec-mcp-server#chg-chg_01a069c1-3cfb-7345-b5fe-e6aaf3dfadd9"
    },
    {
      "id": "chg_01a069c1-3cfc-749f-aa71-ae63a9c592f6",
      "kind": "check.verdict",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.stable",
      "from_value": "0.97",
      "to_value": "pass",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-04",
      "occurred_at": "2026-09-04 00:11:06.818389+00",
      "observed_since": "2026-09-03",
      "source": "scan",
      "summary": "Stability (0.97 → pass)",
      "link": "https://verifymcp.io/servers/toolstem-toolstem-sec-mcp-server/toolstem-sec-mcp-server#chg-chg_01a069c1-3cfc-749f-aa71-ae63a9c592f6"
    },
    {
      "id": "chg_019fd992-d128-74d6-b2d3-94f3cef7a10e",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.tree_partial",
      "to_code": "cve.none",
      "from_value": "partial",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "263",
        "assessed": "264",
        "resolved": "263",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-08-07",
      "occurred_at": "2026-08-07 00:15:05.470735+00",
      "observed_since": "2026-08-06",
      "source": "scan",
      "summary": "Known CVEs (partial → pass)",
      "link": "https://verifymcp.io/servers/toolstem-toolstem-sec-mcp-server/toolstem-sec-mcp-server#chg-chg_019fd992-d128-74d6-b2d3-94f3cef7a10e"
    },
    {
      "id": "chg_019fd470-0bcf-7eb3-85f7-3726ea7156de",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_failed",
      "to_code": "stability.insufficient_history",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-06",
      "occurred_at": "2026-08-06 00:19:00.649307+00",
      "observed_since": "2026-08-05",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: not enough scan history yet (needs a 30-day window).)",
      "link": "https://verifymcp.io/servers/toolstem-toolstem-sec-mcp-server/toolstem-sec-mcp-server#chg-chg_019fd470-0bcf-7eb3-85f7-3726ea7156de"
    },
    {
      "id": "chg_019fcf49-ab32-7d66-be07-95ff02f5749b",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-69207",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.tree_partial",
      "from_value": "medium",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-69207"
      },
      "occurred_on": "2026-08-05",
      "occurred_at": "2026-08-05 00:18:59.482802+00",
      "observed_since": "2026-08-04",
      "source": "scan",
      "summary": "CVE-2026-69207 no longer affects this package",
      "link": "https://verifymcp.io/servers/toolstem-toolstem-sec-mcp-server/toolstem-sec-mcp-server#chg-chg_019fcf49-ab32-7d66-be07-95ff02f5749b"
    },
    {
      "id": "chg_019fcf49-ab34-70ef-be9a-18834699b814",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.tree_partial",
      "from_value": "fail",
      "to_value": "partial",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "267",
        "assessed": "251",
        "resolved": "250",
        "unresolved": "17",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-05",
      "occurred_at": "2026-08-05 00:18:59.482802+00",
      "observed_since": "2026-08-04",
      "source": "scan",
      "summary": "Known CVEs (fail → partial)",
      "link": "https://verifymcp.io/servers/toolstem-toolstem-sec-mcp-server/toolstem-sec-mcp-server#chg-chg_019fcf49-ab34-70ef-be9a-18834699b814"
    },
    {
      "id": "chg_019fca22-4df0-773a-b75a-1106062df346",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-69207",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-69207",
        "severity": "medium"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 00:17:53.620634+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "CVE-2026-69207 affects this package (medium)",
      "link": "https://verifymcp.io/servers/toolstem-toolstem-sec-mcp-server/toolstem-sec-mcp-server#chg-chg_019fca22-4df0-773a-b75a-1106062df346"
    },
    {
      "id": "chg_019fca22-4df1-71fc-944f-41606442aec0",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.tree_partial",
      "to_code": "cve.transitive",
      "from_value": "partial",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "@modelcontextprotocol/sdk > hono",
        "refs": "[\"CVE-2026-69207\"]",
        "seen": "264",
        "package": "hono",
        "version": "4.12.33",
        "assessed": "251",
        "resolved": "250",
        "severity": "medium",
        "transitive": "1",
        "unresolved": "14",
        "vulnerable": "[{\"name\":\"hono\",\"version\":\"4.12.33\",\"depth\":2,\"path\":[\"@modelcontextprotocol/sdk\",\"hono\"],\"refs\":[\"CVE-2026-69207\"]}]",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 00:17:53.620634+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "Known CVEs (partial → fail)",
      "link": "https://verifymcp.io/servers/toolstem-toolstem-sec-mcp-server/toolstem-sec-mcp-server#chg-chg_019fca22-4df1-71fc-944f-41606442aec0"
    },
    {
      "id": "chg_019fc4e4-4b8c-7bf7-b47f-ed24ca37ee42",
      "kind": "check.reverified",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.none",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:52:03.707219+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Provenance (unverified → fail)",
      "link": "https://verifymcp.io/servers/toolstem-toolstem-sec-mcp-server/toolstem-sec-mcp-server#chg-chg_019fc4e4-4b8c-7bf7-b47f-ed24ca37ee42"
    },
    {
      "id": "chg_019fc4e4-4b8e-76d2-b0a1-dc9a4e4abcd1",
      "kind": "check.reverified",
      "family": "install-scripts",
      "subject_kind": "check",
      "subject": "install-scripts",
      "subject_child": "",
      "from_code": "installscript.inconclusive",
      "to_code": "installscript.none",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "tier": "none"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:52:03.707219+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Install scripts (unverified → pass)",
      "link": "https://verifymcp.io/servers/toolstem-toolstem-sec-mcp-server/toolstem-sec-mcp-server#chg-chg_019fc4e4-4b8e-76d2-b0a1-dc9a4e4abcd1"
    },
    {
      "id": "chg_019fc4e4-4b8f-7a7a-b798-c4f0f679b7ea",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.tree_partial",
      "from_value": "unverified",
      "to_value": "partial",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "264",
        "assessed": "251",
        "resolved": "250",
        "unresolved": "14",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:52:03.707219+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Known CVEs (unverified → partial)",
      "link": "https://verifymcp.io/servers/toolstem-toolstem-sec-mcp-server/toolstem-sec-mcp-server#chg-chg_019fc4e4-4b8f-7a7a-b798-c4f0f679b7ea"
    },
    {
      "id": "chg_019fc1aa-5f91-7a87-acf3-2553e4730423",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 08:49:56.100896+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/toolstem-toolstem-sec-mcp-server/toolstem-sec-mcp-server#chg-chg_019fc1aa-5f91-7a87-acf3-2553e4730423"
    },
    {
      "id": "chg_019fbcc7-ac10-7607-a00f-dfd98fed29e6",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "status": "failed"
      },
      "occurred_on": "2026-08-01",
      "occurred_at": "2026-08-01 10:03:50.147294+00",
      "observed_since": "2026-07-31",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: our sandbox run of this package did not complete, so we have no schema to compare.)",
      "link": "https://verifymcp.io/servers/toolstem-toolstem-sec-mcp-server/toolstem-sec-mcp-server#chg-chg_019fbcc7-ac10-7607-a00f-dfd98fed29e6"
    },
    {
      "id": "chg_019fb17f-7430-7c4f-b127-ff10a608dac5",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 05:29:07.878502+00",
      "observed_since": "2026-07-28",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/toolstem-toolstem-sec-mcp-server/toolstem-sec-mcp-server#chg-chg_019fb17f-7430-7c4f-b127-ff10a608dac5"
    }
  ],
  "days": [
    {
      "date": "2026-09-24",
      "total": 82,
      "delta": 1,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 93,
        "to": 97,
        "delta": 4,
        "others": [],
        "accrual": {
          "code": "stability.building_history",
          "from_days": 28,
          "to_days": 29
        },
        "partial": false,
        "compared_to": "2026-09-23",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes."
      },
      "event_count": 0
    },
    {
      "date": "2026-09-21",
      "total": 81,
      "delta": 1,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 83,
        "to": 87,
        "delta": 4,
        "others": [],
        "accrual": {
          "code": "stability.building_history",
          "from_days": 25,
          "to_days": 26
        },
        "partial": false,
        "compared_to": "2026-09-20",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes."
      },
      "event_count": 0
    },
    {
      "date": "2026-09-19",
      "total": 80,
      "delta": 1,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 77,
        "to": 80,
        "delta": 3,
        "others": [],
        "accrual": {
          "code": "stability.building_history",
          "from_days": 23,
          "to_days": 24
        },
        "partial": false,
        "compared_to": "2026-09-18",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes."
      },
      "event_count": 0
    },
    {
      "date": "2026-09-18",
      "total": 79,
      "delta": -3,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-17",
      "total": 82,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-16",
      "total": 82,
      "delta": 1,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 93,
        "to": 97,
        "delta": 4,
        "others": [],
        "accrual": {
          "code": "stability.building_history",
          "from_days": 28,
          "to_days": 29
        },
        "partial": false,
        "compared_to": "2026-09-15",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes."
      },
      "event_count": 0
    },
    {
      "date": "2026-09-13",
      "total": 81,
      "delta": 1,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 83,
        "to": 87,
        "delta": 4,
        "others": [],
        "accrual": {
          "code": "stability.building_history",
          "from_days": 25,
          "to_days": 26
        },
        "partial": false,
        "compared_to": "2026-09-12",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes."
      },
      "event_count": 0
    },
    {
      "date": "2026-09-11",
      "total": 80,
      "delta": -2,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    }
  ]
}