Skip to content

chore(deps): bump mppx from 0.4.12 to 0.8.2 in /web - #325

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/web/mppx-0.8.2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/web/mppx-0.8.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 22, 2026

Copy link
Copy Markdown
Contributor

Bumps mppx from 0.4.12 to 0.8.2.

Release notes

Sourced from mppx's releases.

mppx@0.8.2

Patch Changes

  • 80ed268: Added CLI selection of payable Tempo charge challenges and a currency override.
  • 24ddf52: Filtered unsupported x402 accepts during HTTP client challenge extraction.
  • 24ddcca: Rejected non-canonical fee-payer calldata and client-supplied access lists before sponsorship.
  • 685f698: Fixed MCP payment-aware fetch retries for tool results with payment-required metadata.
  • 8305a05: Added configurable incremental payment challenge retries for client fetch, defaulting to three.

mppx@0.8.1

Patch Changes

  • 2c4086f: Disabled automatic CLI configuration discovery from local directories.
  • 2158a40: Enforced sponsor fee policies before hosted fee-payer signing.
  • ca8687b: Validated session open deposit and voucher amounts before sponsored broadcast.

mppx@0.8.0

Minor Changes

  • daab9b8: Breaking: Collapsed McpClient.wrap and the in-place wrapClient variant into a single McpClient.wrap API on the mppx/mcp/client entrypoint.

    McpClient.wrap now adds payment handling to an MCP SDK client in place: the client is mutated and the same reference is returned, so surfaces that keep using the original client become payment-aware (e.g. when another SDK owns the client reference, like Cloudflare Agents). The MCP SDK callTool(params, resultSchema?, options?) signature is preserved, payment challenges are handled whether they arrive as payment-required errors or as tool results carrying org.paymentauth/payment-required metadata, and the config accepts orderChallenges and paymentPreferences alongside methods and onPaymentRequired. Calling wrap on the same client again replaces its payment configuration.

    Migration: move per-call options from the second argument to the third — mcp.callTool(params, undefined, { context, timeout }) — and replace the approval-first overload mcp.callTool(onPaymentRequired, params, options) with the onPaymentRequired option: mcp.callTool(params, undefined, { onPaymentRequired }) (pass null to bypass a configured hook). The MCP entrypoints moved to mppx/mcp/client and mppx/mcp/server; the mppx/mcp-sdk/* specifiers remain as aliases.

  • e755222: Settled MCP-over-HTTP payment challenges in the same payment-aware fetch as HTTP 402s, so Transport.http() can extract JSON-RPC -32042 challenges and retry with credentials in MCP metadata.

  • 18b57cc: Added a pluggable channelStore for persisting reusable payer session channels and removed the client-side authorizedSigner override so voucher authority is derived from the selected account.

Patch Changes

  • 4c79a78: Rejected empty Payment challenge IDs during construction and deserialization.
  • 7c38c17: Deprecated uppercase asset and chain aliases in favor of lowercase exports.
  • 0e88d07: Corrected PaymentRequest documentation examples to use the exported namespace name.
  • 8da60b5: Documented explicit server secret key configuration in README examples.
  • 7ab4e00: Fixed legacy session manager close amounts when receipts reported per-request spent deltas.
  • b5d8657: Updated Hono dependencies to patched versions.
  • 5e27ef2: Fixed SSE session accounting so voucher management posts no longer consumed stream charges.
  • ec1ad50: Hardened server secret-key validation and capped oversized WWW-Authenticate request parameters.
  • 11db0bd: Removed now-unused wallet_authorizeChallenge support.
  • a1199b0: Added credential-required Tempo subscription reuse and signed-source lookup support so active subscriptions could be bound to the recovered payer instead of request metadata alone.
  • e80feeb: The Tempo fee-payer (sponsor) pre-broadcast simulation now simulates the co-signed transaction the sponsor actually broadcasts — with the concrete fee payer and chosen fee token — instead of the pre-cosign 0x78 envelope, for both local and hosted (feePayerUrl) fee payers. This catches reverts in the exact transaction the sponsor pays gas for, and fails closed (no broadcast) when the simulation reverts.
  • c2611f6: Added tempo.common() as an explicit alias for the Tempo charge and session method bundle.
  • b84cc06: Added generic Tempo account resolution for charge/session credentials and primitive session voucher signatures.
  • 034315e: Updated proxy route examples to use current route handler APIs.
  • 4e5abf4: Hardened confirmed Tempo subscription settlement against T6 (TIP-1028) receive policies. Activation and renewal payments that wait for confirmation now verify that a TIP-20 TransferWithMemo log credits the intended recipient for the expected amount with the generated settlement memo, instead of trusting transaction success alone. Transfers held by a receiver's receive policy (redirected to ReceivePolicyGuard) are now rejected rather than treated as paid, and the memo binding excludes unrelated transfer effects in the same receipt. Documented that the optimistic waitForConfirmation: false mode cannot prove recipient credit under T6.
  • c15be54: Added wallet_authorizeChallenge support. JSON-RPC accounts now delegate Tempo charge and session challenges to wallets that advertise MPP support via wallet_getCapabilities, falling back to local signing otherwise.
  • d14d933: Bound Tempo zero-amount proof credentials to the payer wallet. The EIP-712 Proof typed-data now includes an account field (domain version bumped to 3), so a proof signature commits to a specific payer address and can no longer be replayed against a different account — including across an access key authorized for multiple accounts. Exposed the canonical proof contract via tempo.Proof (types, domain, primaryType, message, typedData, hash) and added deterministic conformance vectors covering the wallet-binding property.

mppx@0.7.0

Minor Changes

... (truncated)

Changelog

Sourced from mppx's changelog.

0.8.2

Patch Changes

  • 80ed268: Added CLI selection of payable Tempo charge challenges and a currency override.
  • 24ddf52: Filtered unsupported x402 accepts during HTTP client challenge extraction.
  • 24ddcca: Rejected non-canonical fee-payer calldata and client-supplied access lists before sponsorship.
  • 685f698: Fixed MCP payment-aware fetch retries for tool results with payment-required metadata.
  • 8305a05: Added configurable incremental payment challenge retries for client fetch, defaulting to three.

0.8.1

Patch Changes

  • 2c4086f: Disabled automatic CLI configuration discovery from local directories.
  • 2158a40: Enforced sponsor fee policies before hosted fee-payer signing.
  • ca8687b: Validated session open deposit and voucher amounts before sponsored broadcast.

0.8.0

Minor Changes

  • daab9b8: Breaking: Collapsed McpClient.wrap and the in-place wrapClient variant into a single McpClient.wrap API on the mppx/mcp/client entrypoint.

    McpClient.wrap now adds payment handling to an MCP SDK client in place: the client is mutated and the same reference is returned, so surfaces that keep using the original client become payment-aware (e.g. when another SDK owns the client reference, like Cloudflare Agents). The MCP SDK callTool(params, resultSchema?, options?) signature is preserved, payment challenges are handled whether they arrive as payment-required errors or as tool results carrying org.paymentauth/payment-required metadata, and the config accepts orderChallenges and paymentPreferences alongside methods and onPaymentRequired. Calling wrap on the same client again replaces its payment configuration.

    Migration: move per-call options from the second argument to the third — mcp.callTool(params, undefined, { context, timeout }) — and replace the approval-first overload mcp.callTool(onPaymentRequired, params, options) with the onPaymentRequired option: mcp.callTool(params, undefined, { onPaymentRequired }) (pass null to bypass a configured hook). The MCP entrypoints moved to mppx/mcp/client and mppx/mcp/server; the mppx/mcp-sdk/* specifiers remain as aliases.

  • e755222: Settled MCP-over-HTTP payment challenges in the same payment-aware fetch as HTTP 402s, so Transport.http() can extract JSON-RPC -32042 challenges and retry with credentials in MCP metadata.

  • 18b57cc: Added a pluggable channelStore for persisting reusable payer session channels and removed the client-side authorizedSigner override so voucher authority is derived from the selected account.

Patch Changes

  • 4c79a78: Rejected empty Payment challenge IDs during construction and deserialization.
  • 7c38c17: Deprecated uppercase asset and chain aliases in favor of lowercase exports.
  • 0e88d07: Corrected PaymentRequest documentation examples to use the exported namespace name.
  • 8da60b5: Documented explicit server secret key configuration in README examples.
  • 7ab4e00: Fixed legacy session manager close amounts when receipts reported per-request spent deltas.
  • b5d8657: Updated Hono dependencies to patched versions.
  • 5e27ef2: Fixed SSE session accounting so voucher management posts no longer consumed stream charges.
  • ec1ad50: Hardened server secret-key validation and capped oversized WWW-Authenticate request parameters.
  • 11db0bd: Removed now-unused wallet_authorizeChallenge support.
  • a1199b0: Added credential-required Tempo subscription reuse and signed-source lookup support so active subscriptions could be bound to the recovered payer instead of request metadata alone.
  • e80feeb: The Tempo fee-payer (sponsor) pre-broadcast simulation now simulates the co-signed transaction the sponsor actually broadcasts — with the concrete fee payer and chosen fee token — instead of the pre-cosign 0x78 envelope, for both local and hosted (feePayerUrl) fee payers. This catches reverts in the exact transaction the sponsor pays gas for, and fails closed (no broadcast) when the simulation reverts.
  • c2611f6: Added tempo.common() as an explicit alias for the Tempo charge and session method bundle.
  • b84cc06: Added generic Tempo account resolution for charge/session credentials and primitive session voucher signatures.
  • 034315e: Updated proxy route examples to use current route handler APIs.
  • 4e5abf4: Hardened confirmed Tempo subscription settlement against T6 (TIP-1028) receive policies. Activation and renewal payments that wait for confirmation now verify that a TIP-20 TransferWithMemo log credits the intended recipient for the expected amount with the generated settlement memo, instead of trusting transaction success alone. Transfers held by a receiver's receive policy (redirected to ReceivePolicyGuard) are now rejected rather than treated as paid, and the memo binding excludes unrelated transfer effects in the same receipt. Documented that the optimistic waitForConfirmation: false mode cannot prove recipient credit under T6.
  • c15be54: Added wallet_authorizeChallenge support. JSON-RPC accounts now delegate Tempo charge and session challenges to wallets that advertise MPP support via wallet_getCapabilities, falling back to local signing otherwise.
  • d14d933: Bound Tempo zero-amount proof credentials to the payer wallet. The EIP-712 Proof typed-data now includes an account field (domain version bumped to 3), so a proof signature commits to a specific payer address and can no longer be replayed against a different account — including across an access key authorized for multiple accounts. Exposed the canonical proof contract via tempo.Proof (types, domain, primaryType, message, typedData, hash) and added deterministic conformance vectors covering the wallet-binding property.

... (truncated)

Commits
  • 831dd0a chore: version packages (#587)
  • 24ddcca fix: reject non-canonical fee-payer transactions (#602)
  • 9d98ec8 feat: add hint field to PaymentError problem details (#600)
  • 2344442 chore(deps): bump the npm-production group across 1 directory with 6 updates ...
  • 5c026a6 chore(deps): bump the github-actions group with 3 updates (#590)
  • 80ed268 fix: select payable tempo cli challenges (#599)
  • 8305a05 feat: add configurable payment challenge retries (#594)
  • 91068d1 chore(deps-dev): bump the npm-development group with 7 updates (#592)
  • 685f698 fix: handle MCP payment result metadata (#588)
  • 24ddf52 fix: filter unsupported x402 accepts (#586)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [mppx](https://github.com/wevm/mppx) from 0.4.12 to 0.8.2.
- [Release notes](https://github.com/wevm/mppx/releases)
- [Changelog](https://github.com/wevm/mppx/blob/main/CHANGELOG.md)
- [Commits](https://github.com/wevm/mppx/compare/mppx@0.4.12...mppx@0.8.2)

---
updated-dependencies:
- dependency-name: mppx
  dependency-version: 0.8.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 22, 2026
@ecc-tools

ecc-tools Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

ECC Tools / Security Evidence

Commit: 072fe04d0f882a01206a2d5390e1bcfa610626e3

Security evidence gate passed (success)

No security-sensitive scanner-evidence gap detected.

Mode: enforce

Scanned 2 changed file(s). No missing scanner-evidence signal was detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

ECC Tools / PR Risk Taxonomy

Commit: 072fe04d0f882a01206a2d5390e1bcfa610626e3

PR taxonomy review recommended (neutral)

Detected 2 PR taxonomy bucket(s): Install Manifest Integrity, CI/CD Recommendation.

Scanned 2 changed file(s).

Roadmap taxonomy buckets:

Install Manifest Integrity

Install manifests, plugin metadata, and shipped skills should stay synchronized with user-facing setup guidance.

Signals:

  • 1 install or manifest path(s) changed

Paths:

  • web/package-lock.json

CI/CD Recommendation

CI, dependency, coverage, and contract signals should be routed into follow-up checks or verification work.

Signals:

  • 1 CI or workflow path(s) changed

Paths:

  • web/package-lock.json

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

ECC Tools / Reference Set Readiness

Commit: 072fe04d0f882a01206a2d5390e1bcfa610626e3

Reference set readiness gaps detected (neutral)

Reference evidence present for 0/7 areas (0%) across 2 changed file(s).

This check is based on files changed in this PR. Repository-level readiness is still reported by /ecc-tools analyze comments and generated manifests.

Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Missing Add cross-harness, adapter-compliance, or harness-audit evidence for Claude, Codex, OpenCode, Zed, dmux, and agent surfaces.
Security evidence Missing Attach security evidence such as SBOMs, SARIF, audit reports, or AgentShield evidence packs.
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@coderabbitai

coderabbitai Bot commented Sep 22, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: a2ab60e1-f19a-42b3-b0d7-217c28a6afe6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@ecc-tools

ecc-tools Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

ECC Tools / Hosted Promotion Readiness

Commit: 072fe04d0f882a01206a2d5390e1bcfa610626e3

Hosted promotion readiness passed (success)

No hosted promotion evidence gaps detected across 2 changed file(s); 0 corpus scenarios had matching evidence.

This check compares PR file changes against the evaluator/RAG promotion corpus in src/analyzers/fixtures/evaluator-rag-corpus.ts.
Hosted output scoring inspected 0 completed cached hosted job results.

No evaluator corpus scenarios matched this PR.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants