Repository navigation
deps(deps): bump @modelcontextprotocol/sdk from 1.26.0 to 1.29.0 - #181
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) from 1.26.0 to 1.29.0. - [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases) - [Commits](modelcontextprotocol/typescript-sdk@v1.26.0...v1.29.0) --- updated-dependencies: - dependency-name: "@modelcontextprotocol/sdk" dependency-version: 1.29.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
* build(deps): consolidate Dependabot dependency updates Combines the six open Dependabot PRs into a single change with one consistent lockfile, avoiding sequential merge-and-rebase churn: - @modelcontextprotocol/sdk ^1.25.1 -> ^1.29.0 (#181) - zod ^4.3.6 -> ^4.4.3 (#182) - @graphql-codegen/cli ^6.1.2 -> ^7.0.0 (major) (#183) - @graphql-codegen/typescript-operations ^5.1.0 -> ^6.0.0 (major) (#184) - eslint ^10.2.1 -> ^10.3.0 (#185) - actions/github-script v8 -> v9 in release.yml (#180) Verified locally: tsc build, graphql-codegen (the two major codegen bumps produce no change to existing generated output), eslint, and the full test suite (653 tests) all pass. The generated src/generated/graphql.ts was left untouched — regenerating only surfaced unrelated backend schema additions (auth/multi-tenant types), which are out of scope for a dependency bump. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * build(deps): npm audit fix for transitive advisories The full lockfile regeneration pulled in transitive deps with advisories (fast-uri high; hono, qs, ip-address, express-rate-limit moderate) that the Security Audit CI step (npm audit --audit-level=moderate) flagged. npm audit fix patches them in the lockfile only — direct dependency versions and package.json are unchanged. Build, lint, and the full test suite (653) still pass; npm audit now reports 0 vulnerabilities. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ci: run contract-tests on Node 22 to match codegen toolchain engines @graphql-codegen/cli v7 pulls listr2, which declares engines.node >=22.13. contract-tests was the only workflow still on Node 20 while it runs `npm run codegen`. It currently passes (engines is advisory without engine-strict), but bumping to Node 22 aligns it with the rest of CI (22.x/24.x) and removes the latent footgun and EBADENGINE warnings. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Superseded by #186, which consolidated all six open Dependabot updates (sdk, zod, @graphql-codegen/cli, @graphql-codegen/typescript-operations, eslint, actions/github-script) into a single squash-merged change. The dependency is now at its target version on main, so this PR is obsolete. Closing. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps @modelcontextprotocol/sdk from 1.26.0 to 1.29.0.
Release notes
Sourced from @modelcontextprotocol/sdk's releases.
... (truncated)
Commits
e12cbd7chore: bump version to 1.29.0 (#1820)3913fd4fix(stdio): always set windowsHide on Windows, not just in Electron (#1640)5608e78[v1.x backport] Allow servers / clients to advertise extensions in the capabi...7213816v1.x #1623 follow up -add missing types to package.json (#1773)364f38cv1.x npm audit fix (#1780)c95cc09Add typings exports (#1623)ddadaa6[v1.x] fix: add missing size field to ResourceSchema (#1575)2a15851[v1.x] fix: disallow null (infinite) requested TTL (#1339)13e30f1fix: treat v1.x as primary branch for npm latest tag (backport #1577) (#1749)a056569chore: bump version to 1.28.0 (#1746)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)