What changed.
Every release, including every change to the rules that decide tiers.
Unreleased
Changed
- Discovery moves to a nightly Claude Code agent (docs/agents/nightly-discovery.md) that submits through the API; the website's scheduled jobs now only keep known tools current. New refresh-known job checks each tool's own source for new releases, least-recently-updated first.
- The nightly discovery agent now looks for new tools in X build-in-public threads, then adds new Official MCP Registry entries for an hour; npm, PyPI and GitHub are used to validate finds, not to search. Each run logs its numbers to a discovery log doc (D-027).
- Only API keys we issue (API_KEYS, DISCOVERY_AGENT_KEY) raise rate limits; made-up keys count as anonymous.
Fixed
- Local dev now reads .env.local at the repo root, and Google sign-in accepts GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRET.
- Postgres store didn't save check results on upsert; results are now appended, and a shared store contract test (FileStore always, PgStore with TEST_DATABASE_URL) guards it.
- Re-check job now pages through every tool in a stable order, and stops re-checking tools with a skipped LLM check until an Anthropic key is set.
- Crawler reuses a known version's tool list instead of probing the server again.
Added
- Production on mcpvetted.com with Neon Postgres; migrations run on production builds; the first registry import is live.
- Manual crawl options on the cron endpoint: full, limit, probe.
- First Vercel deployment: project mcpvetted, live at mcpvetted.vercel.app on demo data; mcpvetted.com attached, pending DNS at Namecheap.
- Sign in with Google (verified emails only) alongside GitHub. Google accounts claim tools by DNS; GitHub accounts can also claim by repo ownership. Privacy policy, terms and security page updated.
Changed
- Header **Search tools** button on every page; pressing / opens search from anywhere. It replaces the home page's "or search it yourself" link.
- Removed eyebrow labels and the pill above the home headline across the site; remaining small labels are sentence case.
- Renamed to **MCP Vetted** (mcpvetted.com). Package scope is now @mcpvetted/*, env vars MCPVETTED_*, DNS proof records _mcpvetted / mcpvetted-verify=, registry _meta key com.mcpvetted/trust, and the install key for our own server mcpvetted.
0.1.0
2026-09-29
Added
- Monorepo (pnpm workspaces, Turborepo) with one Next.js 16 app and ten packages, built from the doc's Launch build spec.
- Trust tiers (Indexed, Scanned, Verified, Proven) computed from checks, publisher claims and agent outcome reports. Rules version 2026-09-29.1.
- Discovery adapters for the Official MCP Registry (v0.1 API), npm and GitHub code search.
- Vetting pipeline: qualify, static scan (10 rules), LLM claims check with Claude Haiku 4.5, automatic revocation of failing releases of installed tools.
- Crawler reads each remote server's tool list with a read-only handshake, since registry entries don't include tools.
- Quick submit by URL, domain, GitHub repo or npm/PyPI package, with an SSRF guard and a read-only MCP handshake that never calls tools.
- MCP server at /api/mcp with nine tools, all with titles, annotations and output schemas.
- REST API at /api/v1, OpenAPI spec at /openapi.json, MCP Registry-compatible API at /api/registry/v0.1.
- Install output for VS Code, Cursor, Claude Code, Claude Desktop and claude.ai, pinned to the checked version.
- Website: "ask your AI" home page, search with information-rich cards, trust pages with Markdown twins, submit, revocations, methodology, agent docs, API reference, publishers, pricing, about, security, contact, changelog, terms, privacy, acceptable use and publisher terms.
- Light and dark themes, CSS-first motion, pointer spotlight cards, no popups.
- Publisher sign-in with GitHub (optional), tool claims by GitHub ownership or DNS TXT, dashboard.
- Publisher sync test: directory list, consent, Stripe checkout with a two-offer price test, webhook that queues sync jobs.
- Live SVG trust badge, llms.txt, security.txt, sitemap, robots, Open Graph image.
- Synthetic look-alike test set (9 samples) that CI runs on every scanner change.
- Rate limits per IP or API key (Upstash when configured, in-memory otherwise).
- CLAUDE.md, STYLEGUIDE.md, docs/ (architecture, decisions, scanner, deploy, roadmap), .env.example, CI workflow and an American English spelling check.
Fixed
- Exfiltration rule missed verb forms such as "uploads"; the test set caught it before release.
- Search matched short words as prefixes ("no" matching "notes").