Repository navigation
build(deps): consolidate Dependabot dependency updates - #186
Conversation
Combines the six open Dependabot PRs into a single change with one consistent lockfile, avoiding sequential merge-and-rebase churn: - @modelcontextprotocol/sdk ^1.25.1 -> ^1.29.0 (#181) - zod ^4.3.6 -> ^4.4.3 (#182) - @graphql-codegen/cli ^6.1.2 -> ^7.0.0 (major) (#183) - @graphql-codegen/typescript-operations ^5.1.0 -> ^6.0.0 (major) (#184) - eslint ^10.2.1 -> ^10.3.0 (#185) - actions/github-script v8 -> v9 in release.yml (#180) Verified locally: tsc build, graphql-codegen (the two major codegen bumps produce no change to existing generated output), eslint, and the full test suite (653 tests) all pass. The generated src/generated/graphql.ts was left untouched — regenerating only surfaced unrelated backend schema additions (auth/multi-tenant types), which are out of scope for a dependency bump. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Code Review — PR #186: Consolidate Dependabot dependency updatesSummary: This is a routine dependency-consolidation PR. The changes are confined to ✅ What looks good
|
There was a problem hiding this comment.
Pull request overview
This PR consolidates multiple Dependabot updates into a single dependency update set, aiming to produce a consistent package-lock.json and reduce merge churn across dependency bumps and the release workflow.
Changes:
- Bump runtime dependencies:
@modelcontextprotocol/sdkto^1.29.0andzodto^4.4.3. - Bump dev tooling:
@graphql-codegen/clito^7.0.0,@graphql-codegen/typescript-operationsto^6.0.0, andeslintto^10.3.0. - Update release workflow to use
actions/github-script@v9.
Reviewed changes
Copilot reviewed 2 out of 3 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| package.json | Updates dependency/devDependency versions to the consolidated set. |
| package-lock.json | Regenerates lockfile to reflect the consolidated dependency graph and resolved versions. |
| .github/workflows/release.yml | Bumps actions/github-script from v8 to v9 for the release job. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
The full lockfile regeneration pulled in transitive deps with advisories (fast-uri high; hono, qs, ip-address, express-rate-limit moderate) that the Security Audit CI step (npm audit --audit-level=moderate) flagged. npm audit fix patches them in the lockfile only — direct dependency versions and package.json are unchanged. Build, lint, and the full test suite (653) still pass; npm audit now reports 0 vulnerabilities. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Code Review: build(deps): consolidate Dependabot dependency updatesOverall: LGTM — well-structured consolidation with thorough verification. A few notes below. OverviewThis PR consolidates 6 open Dependabot PRs into a single branch with a coherent What's Changed
Positive Observations
Notes / Concerns1. This is the core runtime dependency for the entire MCP server. While tests pass and the TypeScript compiler is happy, minor version bumps in a fast-moving SDK can introduce behavioral changes that unit tests don't exercise (e.g., protocol framing, session lifecycle, tool call serialization). If there's any way to do a quick smoke test with an actual MCP client against the built artifact before merging, that would be ideal. Not a blocker given the test suite coverage, but worth flagging. 2. Both major bumps are dev-only and the "no output change on existing schema" check is the right gate. One mild concern: the note says regenerating surfaces new backend schema additions that are "out of scope here, so 3. Used in the "Create GitHub Release" step of 4. As noted above — the intentional omission is correctly explained and scoped. Just make sure a follow-up is tracked somewhere so the type drift doesn't silently accumulate. No Issues Found With
RecommendationApprove and merge. The consolidation approach is the right call. The major version bumps are devDependency-only and have been verified to produce no change in codegen output. Runtime deps are covered by the test suite. The PR description provides enough context for future Reviewed by Claude Code |
@graphql-codegen/cli v7 pulls listr2, which declares engines.node >=22.13. contract-tests was the only workflow still on Node 20 while it runs `npm run codegen`. It currently passes (engines is advisory without engine-strict), but bumping to Node 22 aligns it with the rest of CI (22.x/24.x) and removes the latent footgun and EBADENGINE warnings. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Code Review — PR #186: Consolidate Dependabot dependency updatesOverall: This is a well-structured consolidation PR. The verification checklist (build, codegen, lint, 653 tests) is thorough, and the PR description is clear. A few things are worth flagging before merge. ObservationsNode version inconsistency in
|
| Finding | Severity | Blocking? |
|---|---|---|
release.yml still on Node 20 |
Low | No — build path doesn't run codegen |
engines field not updated to >=22 |
Medium | No — but will confuse contributors on older Node |
| MCP SDK changelog review for 1.25.1→1.29.0 | Low | No — tests pass |
| Codegen major bump verification | ✅ Done | — |
This is safe to merge as-is, but the engines field and release.yml Node version are clean-up items worth addressing either here or in a fast follow.
🤖 Generated with Claude Code
Consolidates the six open Dependabot PRs into a single branch with one consistent
package-lock.json, so they can merge together without the sequential merge-and-rebase churn of merging each individually.Updates included
@modelcontextprotocol/sdk^1.25.1 → ^1.29.0zod^4.3.6 → ^4.4.3@graphql-codegen/cli^6.1.2 → ^7.0.0@graphql-codegen/typescript-operations^5.1.0 → ^6.0.0eslint^10.2.1 → ^10.3.0actions/github-scriptv8 → v9 (release.yml)Verification (local)
npm run build(tsc) ✅npm run codegen✅ — the two major graphql-codegen bumps produce no change to existing generated output. Regenerating only surfaced unrelated backend schema additions (auth/multi-tenant types), which are out of scope here, sosrc/generated/graphql.tsis intentionally left untouched.npm run lint(eslint 10.3.0) ✅npm test— 653 tests pass ✅Follow-up
Once this merges, the six source Dependabot PRs (#180–#185) can be closed — Dependabot will detect the dependencies are already at target versions. The recurring red
claude-review❌ on Dependabot PRs is a separate infra issue (Dependabot runs have no access toANTHROPIC_API_KEY).🤖 Generated with Claude Code