deps: bump @modelcontextprotocol/sdk from 1.25.3 to 1.27.1 in the production-dependencies group - #53
Conversation
Bumps the production-dependencies group with 1 update: [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk). Updates `@modelcontextprotocol/sdk` from 1.25.3 to 1.27.1 - [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases) - [Commits](modelcontextprotocol/typescript-sdk@v1.25.3...v1.27.1) --- updated-dependencies: - dependency-name: "@modelcontextprotocol/sdk" dependency-version: 1.27.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
Independent verification of PR #53 (execution-based review)Verified at head Checks / tests at head
Advisory delta (npm audit: base 19 → head 20)
Delivered vs title: title says 1 update; delivered = SDK 1.25.3→1.27.1 plus in-subtree transitive changes (express-rate-limit 7.5.1→8.2.1, qs 6.14.1→6.15.0, new ip-address 10.0.1, jose and zod-to-json-schema range bumps, Failing check Staleness: branch created 2026-03-02 (~7 months old). Main still pins SDK 1.25.3 in the lockfile, so this PR is not superseded and no newer SDK PR exists; however 5 other open dependabot PRs (#65, #66, #68, #69, #70) touch the same lockfile, so merge order matters. Verdict: FIX-FIRST (rebase), then merge. The code-level change is green and fixes GHSA-345p-7cg4-v4c7, but as-committed the lockfile drags in 2 new high advisories; a |
|
Independent cross-model review (grok headless review, execution re-verified): FIX-FIRST The bump removes the SDK's own advisory (GHSA-345p-7cg4-v4c7, row gone from head audit) but net-adds high advisories to the dependency tree.
Findings (reproduced against the registry advisory DB):
Verified NOT broken (checked; do not re-hunt): Suggested resolution: |
Bumps the production-dependencies group with 1 update: @modelcontextprotocol/sdk.
Updates
@modelcontextprotocol/sdkfrom 1.25.3 to 1.27.1Release notes
Sourced from
@modelcontextprotocol/sdk's releases.Commits
4faa8c8chore: bump version to 1.27.1 (#1581)09a85a8fix: call onerror for silently swallowed transport errors (#1580)e79d14afix: prevent command injection in example URL opening (v1.x backport) (#1579)342ea39docs: comprehensive feature documentation for SEP-1730 Tier 1 (#1548)2084a22docs: add governance documentation for SEP-1730 (#1547)f2d2145feat: implement auth/pre-registration conformance scenario (#1545)8cbc658chore: bump version for v1.27.0 (#1541)5c16ae3[v1.x] feat(tasks): add streaming methods for elicitation and sampling (#1528)97ab379feat: add url property to RequestInfo interface (#1353)825e9abfeat: backport discoverOAuthServerInfo() and discovery caching to v1.x (#1533)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions