Repository navigation
docs: credit the #13 and #14 security reports #25
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -22,12 +22,14 @@ Thank you to everyone who builds, tests, reports problems, and shares real print | |
| | [Remco Veldkamp (remcoder)](https://github.com/remcoder) | Reports that a large OctoPrint file list (324 files, about 500 KB of JSON) overflows a model's context window in [#4](https://github.com/DMontgomery40/mcp-3D-printer-server/issues/4). The full list is still returned; this is documented as a limitation. | | ||
| | [Jose Martinez (josemartinezbli)](https://github.com/josemartinezbli) | Reports that `SLICER_PROFILE` was ambiguous for PrusaSlicer and OrcaSlicer, with slicer error output, in [#7](https://github.com/DMontgomery40/mcp-3D-printer-server/issues/7). The slicing guide now documents profiles per slicer. | | ||
| | [Gioele Molinari (gioelemo)](https://github.com/gioelemo) | Shares a Prusa Connect configuration in [#9](https://github.com/DMontgomery40/mcp-3D-printer-server/issues/9). The Prusa adapter now normalizes `connect.prusa3d.com` to HTTPS; cloud access has not been confirmed on hardware. | | ||
| | [BruceJin (BruceJqs)](https://github.com/BruceJqs) | Reports that a per-call `bridge_command` in `blender_mcp_edit_model` could launch an arbitrary local executable (CWE-78) in [#14](https://github.com/DMontgomery40/mcp-3D-printer-server/issues/14). Per-call executable selectors now require the server-side `MCP_ALLOW_EXECUTABLE_ARG=1` opt-in ([#20](https://github.com/DMontgomery40/mcp-3D-printer-server/pull/20), [#21](https://github.com/DMontgomery40/mcp-3D-printer-server/pull/21)). | | ||
| | [0xBrandon (0x4272616E646F6E)](https://github.com/0x4272616E646F6E) | Asks for network (SSE) serving in [#6](https://github.com/DMontgomery40/mcp-3D-printer-server/issues/6). The server now provides a streamable HTTP transport. | | ||
|
|
||
| ## Requests and proposals not yet merged | ||
|
|
||
| | Contributor | Contribution | | ||
| | --- | --- | | ||
| | [Raza Sharif (razashariff)](https://github.com/razashariff) | Proposes cryptographic signing, replay protection, and agent identity checks before print commands in [#13](https://github.com/DMontgomery40/mcp-3D-printer-server/issues/13). Signing is not implemented; since 1.2.10, every print start and positive heating command requires human confirmation through MCP elicitation, and printed files are inspected before dispatch. | | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
In headless configurations with AGENTS.md reference: AGENTS.md:L37-L37 Useful? React with 👍 / 👎. |
||
| | [DarkCraven (sweidinger)](https://github.com/sweidinger) | Requests Klipper print-job status (progress, file, times) beyond Moonraker's `/printer/info` in [#12](https://github.com/DMontgomery40/mcp-3D-printer-server/issues/12). Not yet implemented. | | ||
| | [Hex (hexatriene)](https://github.com/hexatriene) | Proposes migrating Bambu support to `bambu-js` v3 for H2D support and FTP operations in [#10](https://github.com/DMontgomery40/mcp-3D-printer-server/pull/10). Closed without merging; the server keeps `bambu-node` for MQTT and uses `basic-ftp` directly for uploads. | | ||
| | [Jean-Laurent de Morlhon (jeanlaurent)](https://github.com/jeanlaurent) | Proposes Docker support in [#2](https://github.com/DMontgomery40/mcp-3D-printer-server/pull/2). Closed without merging; the repository's Docker setup was later fixed in #3. | | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
When this commit is integrated into
main, both package manifests remain at 1.2.10, so the required npm publication cannot represent this update and attempting to republish the existing version will fail. Include thenpm version patchchanges topackage.jsonandpackage-lock.jsonin this integration.AGENTS.md reference: AGENTS.md:L7-L7
Useful? React with 👍 / 👎.