chore(deps): bump @modelcontextprotocol/sdk from 1.29.0 to 1.30.0 - #863
chore(deps): bump @modelcontextprotocol/sdk from 1.29.0 to 1.30.0#863dependabot[bot] wants to merge 2 commits into
Conversation
Bumps [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) from 1.29.0 to 1.30.0. - [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases) - [Commits](modelcontextprotocol/typescript-sdk@v1.29.0...1.30.0) --- updated-dependencies: - dependency-name: "@modelcontextprotocol/sdk" dependency-version: 1.30.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
CommitLore — record lintTrailers: clean — 2 commits in Active constraints for the paths this PR touchesLimits (293)
Ruled out (466)
Truncated: 525 lines omitted — the comment hit GitHub's 65000 character limit. Trailer violations fail this check. Active constraints are informational — they are what the repository already decided, not a verdict on this PR. |
Dependabot bumped @modelcontextprotocol/sdk 1.29.0 -> 1.30.0 and CI's `check` failed with "source checksum does not match this checkout", the same contract clause r-cdebmanifest describes: `package-lock.json` is a source input. Unlike a dev-only bump this one is a runtime dependency, so the canonical build was the only way to learn what `dist/` becomes. It moved: `dist/commitlore.mjs` grew 1378376 -> 1378660 bytes and the artifact digest is 71622373f47857591fa72c34a07b2b940f9553ceb34c8e70d4a040854e8ca080 rather than e8183a8f... . Both the rebuilt bundle and the regenerated manifest are committed here, because a manifest recording a dist nobody committed would verify on the machine that built it and nowhere else. Record-Id: r-sdkbundlemoves Follows: r-cdebmanifest Provenance: authored Certainty: firm Blast: module Undo: easy Ruled-out: committing the manifest without the rebuilt dist/commitlore.mjs | the manifest records the artifact's checksum, so the pair only verifies together; splitting them would leave main verifying against bytes it does not contain Limit: says nothing about whether 1.30.0 changes MCP behaviour at runtime; the suite covers this repository's use of the SDK and not the SDK itself Verified: the pinned linux/amd64 build produced the committed dist; artifact:verify exits 0 on the committed pair; typecheck, check-engines and 3157 tests pass on this branch Unverified: npm audit --omit=dev still reports fast-uri and qs advisories here, but it reports them on main too and 1.30.0 changes neither; that is fixed on a separate branch
60c19a2 to
09aaee9
Compare
|
Superseded by #869 (
This change is carried there, rebased onto the current |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps @modelcontextprotocol/sdk from 1.29.0 to 1.30.0.
Release notes
Sourced from @modelcontextprotocol/sdk's releases.
Commits
2d889f2chore: bump version to 1.30.0 (#2563)e3f3daaFix SSE keep-alive timer lifecycle in Streamable HTTP server transport (v1.x)...bb5a718fix(deps): widen@hono/node-serverpast GHSA-frvp-7c67-39w9 (#2549)1dad263fix: send SSE keep-alive comment frames from Streamable HTTP server transport...69749aaValidate Content-Type by parsed media type instead of substring match (v1.x) ...369513dfix: support Zod 3.25 method literals (#2368)e7ee57cv1 stdio buffer limit (#2239)c36e1efAdd end-to-end test suite (#2167)bf1e022chore(ci): switch publish to OIDC trusted publishing (#1839)9edbab7fix(server): prioritize zod issues and format them (#1503)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@modelcontextprotocol/sdksince your current version.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)