Skip to content

Conversation

@felixweinberger
Copy link
Contributor

@felixweinberger felixweinberger commented Dec 3, 2025

Update eslint ecosystem to fix:

  • @eslint/plugin-kit ReDoS (CVE in ConfigCommentParser)
  • brace-expansion ReDoS
  • js-yaml prototype pollution in merge

Updated versions:

  • eslint: 9.13.0 → 9.39.1
  • typescript-eslint: 8.11.0 → 8.48.1

Motivation and Context

Ran npm audit and npm audit fix. This caused eslint to update to 9.39.1 which broke compatibility with typescript-eslint 8.11.0 so ran npm install typescript-eslint@latest to update that which fixed the compatibility.

How Has This Been Tested?

Ran npm i and npm test

Breaking Changes

None.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

Additional context

Update eslint ecosystem to fix:
- @eslint/plugin-kit ReDoS (CVE in ConfigCommentParser)
- brace-expansion ReDoS
- js-yaml prototype pollution in merge

Updated versions:
- eslint: 9.13.0 → 9.39.1
- typescript-eslint: 8.11.0 → 8.48.1
@pkg-pr-new
Copy link

pkg-pr-new bot commented Dec 3, 2025

Open in StackBlitz

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/sdk@1227

commit: 423f5b1

@felixweinberger felixweinberger marked this pull request as ready for review December 3, 2025 17:33
@felixweinberger felixweinberger requested a review from a team as a code owner December 3, 2025 17:33
@felixweinberger felixweinberger merged commit 545dbe1 into main Dec 3, 2025
10 checks passed
@felixweinberger felixweinberger deleted the fweinberger/npm-audit branch December 3, 2025 17:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants