Skip to content

build(deps): bump the typescript group across 1 directory with 5 updates - #17

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/typescript/typescript-9a9319b02d
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/typescript/typescript-9a9319b02d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown

Bumps the typescript group with 5 updates in the /typescript directory:

Package From To
@modelcontextprotocol/server 2.1.0 2.3.0
@types/node 24.13.6 24.19.1
@vitest/coverage-v8 5.0.1 5.0.3
oxlint 1.85.0 1.86.0
vitest 5.0.1 5.0.3

Updates @modelcontextprotocol/server from 2.1.0 to 2.3.0

Release notes

Sourced from @​modelcontextprotocol/server's releases.

@​modelcontextprotocol/server-legacy@​2.3.0

Patch Changes

  • #2908 633dd3e Thanks @​claude! - The license field of the package manifests is now Apache-2.0; the LICENSE file shipped in each package carries the full terms, including the MIT text for earlier contributions. No code change.

  • Updated dependencies [633dd3e]:

    • @​modelcontextprotocol/core@​2.3.0

@​modelcontextprotocol/server@​2.3.0

Minor Changes

  • #2929 40f8f4e Thanks @​claude! - requireBearerAuth and verifyBearerToken take a new optional expectedResource, which makes them accept only tokens issued for this resource (the token's audience). Set it to the value your authorization server puts into tokens meant for this server, usually the server's URL. When it is set, a token is accepted only if the verifier reports that value in AuthInfo.resource; the two are compared as strings, ignoring a fragment and one trailing slash. A token reported for another value, or for none, is answered 401 invalid_token with the usual WWW-Authenticate challenge. When it is not set, nothing changes. To use it, pass expectedResource and have verifyAccessToken fill AuthInfo.resource, for example from the aud claim. The option is declared on a new exported type, VerifyBearerTokenOptions, which extends BearerAuthOptions; BearerAuthOptions itself is unchanged. The Express requireBearerAuth passes the option through. With Express, @modelcontextprotocol/express has to be upgraded to this release as well: 2.0.1 does not pass the option on, so nothing is compared. Its options type does not have the option, so TypeScript reports an expectedResource written in a call to the 2.0.1 requireBearerAuth as an error.

  • #2926 6d8dbc6 Thanks @​claude! - McpServer now accepts a maxToolInputElements option that limits the number of elements in tool-call arguments: the largest combined number of array elements and object members a single tools/call arguments payload may contain. It is off by default, so behavior is unchanged unless you set it. When it is set and a call exceeds it, that call is answered with an isError: true tool result that names the limit, before the input schema runs, and the server keeps serving. Set it above the largest arguments your tools legitimately accept; maxRequestBodySize remains the primary limit on request size. The value must be a number of at least 1, or Infinity for no limit; any other value is rejected at construction. The options type is exported as McpServerOptions.

  • #2918 84804c2 Thanks @​claude! - A Server or McpServer now serves one connection at a time, and a Streamable HTTP server transport without sessions (sessionIdGenerator: undefined) serves one request. An app that uses one server object, or one stateless transport, for every HTTP request fails on the second request after this upgrade. Build the server and the transport per request instead.

    What keeps working without a change:

    • createMcpHandler(buildServer) and serveStdio(buildServer), where buildServer returns a new server on every call.
    • A handler that builds a new server and a new stateless transport for each request.
    • One server and one transport per session (a transport with a sessionIdGenerator).
    • Connecting a server again after close().
    • Client.

    What fails now, how it shows, and what to change:

    • One server object with a new stateless transport per request (const server = new McpServer(...) outside the handler, await server.connect(transport) inside it): the second HTTP request the process receives fails, and so does every later one. connect() rejects with an SdkError of code ALREADY_CONNECTED. If the handler closes the transport when the response ends, requests that arrive one after the other still work and a request that overlaps another one fails. Change: move new McpServer(...) and its registrations into the handler.
    • One stateless transport for every request (a transport built once with sessionIdGenerator: undefined): the second HTTP request fails. WebStandardStreamableHTTPServerTransport.handleRequest() rejects with Stateless transport cannot be reused across requests. Create a new transport per request., and NodeStreamableHTTPServerTransport.handleRequest() answers 500. Change: build the server and the transport inside the handler and connect them there.
    • createMcpHandler(() => server) with a server built once: a request that arrives after the previous response has been read to its end still works. A request that arrives while another one is being served is answered 500 with the JSON-RPC error -32603 (Internal server error); the reason is reported only through the onerror option. Change: pass a function that builds the server, as in createMcpHandler(buildServer).
    • One server object for every session: the initialize request of the second session fails with ALREADY_CONNECTED. Change: build a server per session.

    What the caller sees when connect() or handleRequest() rejects depends on the host. Express 5, Fastify and Hono answer 500. A plain node:http listener without its own error handling gets an unhandled rejection, which ends the process.

    The README examples of @modelcontextprotocol/express, @modelcontextprotocol/fastify, @modelcontextprotocol/hono and @modelcontextprotocol/node, and the handler examples in the JSDoc of WebStandardStreamableHTTPServerTransport and NodeStreamableHTTPServerTransport, now build a server and a transport per request.

  • #2907 e55f9ac Thanks @​claude! - allowedOrigins and validateOriginHeader accept lowercase entries of the form <scheme>://*, such as moz-extension://* or chrome-extension://*, which admit every origin of that scheme. This lets a server admit MCP clients that run as a browser extension when the extension ID cannot be listed, as on Firefox, where it differs on every install. http://* and https://* are not honoured, and the defaults are unchanged.

Patch Changes

  • #2599 5238fba Thanks @​freya0926! - A server can now serve, and a client can now call, tasks/get and tasks/cancel of the Tasks extension (SEP-2663) on a 2026-07-28 connection, when the handler is registered and the request is sent with an explicit schema. Every other method that a protocol revision removed is still refused. If one server factory serves both eras and such a handler is meant for 2025-era clients only, register it only when ctx.era === 'legacy'.

  • #2107 2fc49ea Thanks @​pragnyanramtha! - prompts/get without arguments no longer fails with "Invalid arguments" when every argument of the prompt is optional. A missing arguments is now validated as {}, as it already is for tools/call, so a top-level .optional() or .default(...) on argsSchema no longer sees undefined.

  • #2889 4d94e7b Thanks @​claude! - registerTool no longer converts tool schemas up front, so a server built per request stops converting every tool on every request. The warning about an invalid x-mcp-header declaration now appears each time tools are listed, not when the tool is registered.

  • #2908 633dd3e Thanks @​claude! - The license field of the package manifests is now Apache-2.0; the LICENSE file shipped in each package carries the full terms, including the MIT text for earlier contributions. No code change.

  • #2841 2237555 Thanks @​sharziki! - McpServer.registerPrompt() now types the callback correctly when no argsSchema is given: its one parameter is the server context. Before, reading ctx.mcpReq there was a type error although it worked at runtime. Prompts registered with an argsSchema are unchanged.

  • Updated dependencies [633dd3e]:

    • @​modelcontextprotocol/core@​2.3.0

... (truncated)

Commits
  • a202a36 Version Packages (#2896)
  • 2d731fa fix(client): refresh again when an SSE retry failed for a reason other than 4...
  • b6e5c55 test(e2e): cover prompts/get without arguments for prompts with a schema (#2928)
  • 40f8f4e feat(server): add expectedResource to the bearer-token check (#2929)
  • 6d8dbc6 feat(server): add maxToolInputElements option to limit the number of elements...
  • 2fc49ea fix(server): accept prompts/get requests that omit arguments (#2107)
  • 63c0fca fix(client): update eventsource-parser for large SSE responses (#2846)
  • 84804c2 fix(server): refuse a second connect and stateless transport reuse (#2918)
  • e16d277 docs: close idle sessions and cap the session map in the sessions guide and e...
  • 433eb41 fix(client): follow redirects only within the origin of the request (#2901)
  • Additional commits viewable in compare view

Updates @types/node from 24.13.6 to 24.19.1

Commits

Updates @vitest/coverage-v8 from 5.0.1 to 5.0.3

Release notes

Sourced from @​vitest/coverage-v8's releases.

v5.0.3

   🐞 Bug Fixes

    View changes on GitHub

v5.0.2

   🐞 Bug Fixes

... (truncated)

Commits

Updates oxlint from 1.85.0 to 1.86.0

Release notes

Sourced from oxlint's releases.

oxlint v1.86.0

🚀 Features

  • 9d80eed linter/react/only-export-components: Support allowCompoundComponents (#27117) (Kuroda Kayn)
  • e05b155 linter: Add typescript/no-generated-empty-object-type (#26958) (camc314)

🐛 Bug Fixes

  • 8306aa4 linter/typescript/no-unnecessary-parameter-property-assignment: Account for parameter property reassignment (#26955) (camc314)
  • 42dfbb5 linter/eslint/one-var: Keep declare when splitting declarations (#27081) (Cheolhee Lee)
  • 2ba7e33 linter/eslint/require-await: Count await using as an await (#27080) (Cheolhee Lee)
  • 611e4ed linter/plugins: Include executing selectors in JS plugin rule timings (#27111) (overlookmotel)
  • 2cac66f react-compiler: Handle recursive function expressions (#26796) (Brennan Butler)
  • e996e6c react-compiler: Treat zero-argument new Date as impure (#26894) (Boshen)
  • 571cfa3 oxlint: Skip type-aware lint rules in type-check-only mode (#27076) (camc314)
  • d0b2462 oxlint: Skip undefined children in CFG walker (#27075) (camc314)
  • 5186328 parser: Handle HTML comment values (#22933) (Boshen)
  • 0b630e8 linter/typescript/unified-signatures: Align rule with upstream (#26956) (camc314)
  • ebb22f1 linter/node/no-exports-assign: Change category from style to suspicious (#26555) (Bartok)
  • cce28a0 linter/import/no-duplicates: Distinguish import attributes (#26936) (camc314)
  • feb733b linter/unicorn/prefer-spread: Stop checking string split calls (#26935) (camc314)
  • 929e154 linter/eslint/no-unused-vars: Honor ignore patterns inside array rest bindings (#26923) (camc314)
  • 5bdb9b8 linter/eslint/no-unused-vars: Recognize consumed update expressions (#26782) (camc314)
  • 5c05bef linter/eslint/prefer-const: Ignore embedded assignments (#26920) (camc314)

⚡ Performance

  • ded4c29 linter/eslint/no-unused-vars: Skip sequence checks when absent (#26921) (camc314)
Changelog

Sourced from oxlint's changelog.

[1.86.0] - 2026-09-28

🚀 Features

  • 9d80eed linter/react/only-export-components: Support allowCompoundComponents (#27117) (Kuroda Kayn)
  • e05b155 linter: Add typescript/no-generated-empty-object-type (#26958) (camc314)

[1.82.0] - 2026-09-07

🚀 Features

  • 6a0e19c linter/eslint/no-unmodified-loop-condition: Support checkConditionalExpressions option (#26249) (camc314)

[1.81.0] - 2026-08-31

📚 Documentation

  • d5be037 linter/typescript/switch-exhaustiveness-check: Clarify default case comment pattern (#26100) (camc314)

[1.79.0] - 2026-08-18

💥 BREAKING CHANGES

  • 8c4552d linter: [BREAKING] Split react/react-compiler into per-category rules (#25500) (Boshen)

🐛 Bug Fixes

  • 228e8e0 linter: Resolve inactive React compiler rules (#25830) (Boshen)
  • aa49d86 linter: Allow spread rule options in config types (#25675) (ch3rry)
  • 36f8451 linter/eslint/no-eval: Align indirect default with ESLint (#25656) (camc314)
  • beb724d linter/eslint/no-unused-vars: Report bare underscore parameters (#25663) (camc314)
  • 4004c10 linter/eslint/no-irregular-whitespace: Check comments by default (#25660) (camc314)
  • 285820e linter/no-large-snapshots: Precompile and document allowed snapshot matchers (#25611) (Mikhail Baev)
  • 4df5835 linter: Allow capitalized built-in calls (#25516) (Boshen)

[1.78.0] - 2026-08-10

🚀 Features

  • ccb8fe8 linter/jsdoc: Implement no-blank-blocks rule (#25207) (Mikhail Baev)
  • d4a897c linter/eslint: Implement one-var rule (#24470) (Cole Ellison)
  • 5ab9340 linter/jsx-a11y/anchor-has-content: Add options to match eslint (#24571) (Cole Ellison)

🐛 Bug Fixes

  • 9573937 linter/typescript: Validate ban-ts-comment description_format (#25320) (Mikhail Baev)

[1.77.0] - 2026-08-03

🐛 Bug Fixes

... (truncated)

Commits
  • 2ae2939 release(apps): oxlint v1.86.0 && oxfmt v0.71.0 (#27132)
  • 9d80eed feat(linter/react/only-export-components): support allowCompoundComponents ...
  • e05b155 feat(linter): add typescript/no-generated-empty-object-type (#26958)
  • 88a0096 chore(oxlint): require tsgolint 7.0.2003 (#27021)
  • See full diff in compare view

Updates vitest from 5.0.1 to 5.0.3

Release notes

Sourced from vitest's releases.

v5.0.3

   🐞 Bug Fixes

    View changes on GitHub

v5.0.2

   🐞 Bug Fixes

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the typescript group with 5 updates in the /typescript directory:

| Package | From | To |
| --- | --- | --- |
| [@modelcontextprotocol/server](https://github.com/modelcontextprotocol/typescript-sdk) | `2.1.0` | `2.3.0` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `24.13.6` | `24.19.1` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `5.0.1` | `5.0.3` |
| [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) | `1.85.0` | `1.86.0` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.1` | `5.0.3` |



Updates `@modelcontextprotocol/server` from 2.1.0 to 2.3.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/server@2.1.0...@modelcontextprotocol/server@2.3.0)

Updates `@types/node` from 24.13.6 to 24.19.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@vitest/coverage-v8` from 5.0.1 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/coverage-v8)

Updates `oxlint` from 1.85.0 to 1.86.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.86.0/npm/oxlint)

Updates `vitest` from 5.0.1 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/server"
  dependency-version: 2.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: typescript
- dependency-name: "@types/node"
  dependency-version: 24.19.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: typescript
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: typescript
- dependency-name: oxlint
  dependency-version: 1.86.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: typescript
- dependency-name: vitest
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: typescript
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants