v0.1.49
Published as @automattic/mcp-remote@0.1.49.
Changes
- Dependency security updates (#5): in-range
pnpm updateclearing 52pnpm auditfindings (1 critical, 15 high, 29 moderate, 7 low). Runtime: undici ^7.24.0 → ^7.29.0 (fixes 12 advisories including SOCKS5 TLS-validation bypass GHSA-vmh5-mc38-953g and cross-origin proxy-pool routing GHSA-hm92-r4w5-c3mj, both directly relevant to this proxy's SOCKS support), socks → ^2.8.9 (patched ip-address 10.3.1, SSRF via octal octet confusion), express → ^4.22.2 (patched body-parser). Dev: vitest → 3.2.7 in both the root and E2E projects (fixes critical UI-server arbitrary file read/exec GHSA-5xrq-8626-4rwp), @modelcontextprotocol/sdk → ^1.30.0 (patched hono, fast-uri, ip-address, qs). One low-severity dev-only esbuild advisory remains, pinned by tsup. Lockfiles regenerated against registry.npmjs.org with integrity-only resolutions.
No functional changes — the published dist only picks up the patched undici/socks/express versions via raised dependency floors.
Install: npx @automattic/mcp-remote@0.1.49 https://remote.mcp.server/sse