← All posts

BLOG

What Shipped This Week: 25 New Connectors, 2 Breaking Changes, and a Gateway Security Pass, September 21, 2026

Biggest connector week yet across Conduit and the vendor-connector fleet: 25 new MCP integrations shipped, plus 2 breaking changes and a gateway-security hardening pass. Conduit is WYRE's MCP (Model Context Protocol) gateway: the layer every one of this week's releases plugs into.

Breaking changes

node-datto-rmm v2.0.0 renames ActivityLogsResponse.activityLogs, and nests QuickJobRequest's componentUid / variables under jobComponent. It also resolves the js-yaml CVE-2026-84375. External contribution: granthartley-brown.

timezest-mcp v3.0.0 lists every tool flatly instead of gating them behind navigate. timezest_navigate and timezest_back are removed (migration note included in the release).

New MCP connectors (25)

Conduit platform

Conduit v1.90.0 registers CIPP's own first-party MCP server (cipp-official).

Conduit v1.89.0 registers Keeper Secrets Manager as a read-only, admin-tier catalog vendor.

Conduit v1.88.0 adds signed audit-log checkpoints, a trusted Entra tenant for gateway migration, and OAuth device-authorization grant with agent-subjected tokens.

Conduit v1.87.0 adds long-lived agent keys, so a service account can authenticate as itself.

Security

Gateway S2S auth (closes a confused-deputy gap between sibling sidecars) rolled out to axcient-mcp, mailprotector-mcp, and salesforce-mcp.

7 client libraries patched for js-yaml CVE-2026-84375: node-atera, node-crewhu, node-halopsa, node-immybot, node-it-glue, node-ninjaone, node-superops.

node-syncro bumped vitest (CVE-2026-84373) and js-yaml (CVE-2026-84375).