# Positive fixture for CVE-2026-55096 (#853): the last release before the fix.
# The Telegram MCP server's attachment guard compares the literal hostname with a
# denylist and never resolves it, so a name that resolves to loopback passes.
fast-mcp-telegram==0.30.0
