Skip to content

chore: bump @modelcontextprotocol/sdk from 1.30.0 to 1.30.1 - #71

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/modelcontextprotocol/sdk-1.30.1
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/modelcontextprotocol/sdk-1.30.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps @modelcontextprotocol/sdk from 1.30.0 to 1.30.1.

Release notes

Sourced from @​modelcontextprotocol/sdk's releases.

1.30.1

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.0...1.30.1

Commits
  • 289ac2c chore: bump version to 1.30.1 (#2848)
  • 12b4256 fix(auth): preserve resource URI without trailing slash (#1968) (#1972)
  • a9f6eb7 [v1.x] fix(server): read HTTP request bodies with a size limit and bound JSON...
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) from 1.30.0 to 1.30.1.
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@1.30.0...1.30.1)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.30.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
@claude

claude Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Claude finished @dependabot[bot]'s task in 1m 20s —— View job


Dependency review: @modelcontextprotocol/sdk 1.30.0 → 1.30.1

  • Identify what changed and whether it crosses a major version
  • Check release notes for breaking/behaviour changes
  • Search repo for actual SDK usage (tool registration, annotations, transport)
  • Build + test on this branch — could not run locally (see caveat below); CI on this branch is green
  • Post review

Verdict: safe to merge. Patch bump, no breaking changes, and neither upstream fix touches code paths this server uses.

What changed

Patch release, no major/minor crossing. package.json already declares "@modelcontextprotocol/sdk": "^1.29.0", so the caret range covers 1.30.1 and only package-lock.json needs to move — correct, nothing missing from the diff. The lockfile change is confined to version/resolved/integrity; the SDK's own dependencies block is unchanged in the diff context (@hono/node-server range identical), so there's no transitive tree movement to audit.

The two upstream fixes, against this codebase

  1. fix(server): read HTTP request bodies with a size limit and bound JSON-RPC batch length (#2717) — hardening in the SDK's HTTP server transports (unbounded body read / unbounded batch length, i.e. resource-exhaustion shaped). Not reachable here: this server connects StdioServerTransport only (src/index.ts:2, src/index.ts:8), and tests use InMemoryTransport (test/server.test.ts:3). No HTTP transport is instantiated anywhere in src/. Still worth taking — it's a free hardening fix if an HTTP transport is ever added.
  2. fix(auth): preserve resource URI without trailing slash (#1972) — OAuth resource-URI normalisation in the SDK's auth module. Not reachable here: this server does not use the SDK's OAuth flow; it authenticates to Kosli with a bearer token assembled in src/client/kosli-client.ts from KOSLI_API_TOKEN/KOSLI_API_KEY. No behaviour change.

SDK surface this repo depends on

All unchanged in 1.30.1:

  • McpServer + server.registerTool(...) with inputSchema as a raw Zod shape — src/server.ts:33, src/server.ts:38, :64, :82
  • Tool annotations (readOnlyHint on search_actions/execute_read_action, destructiveHint on execute_write_action) — src/server.ts:44, :71, :88. This is the read/write separation the design leans on, so it's the thing most worth watching on SDK bumps; nothing in this release touches annotation handling or how clients gate on them.
  • StdioServerTransport — src/index.ts
  • Client + InMemoryTransport for the in-memory transport test — test/server.test.ts

One note on the review instructions rather than on the PR: they point at "tool registration and annotations in src/index.ts", but registration moved to createServer in src/server.ts (index.ts is now only the bin that connects stdio, per CLAUDE.md). Worth updating the prompt in .github/workflows/claude-review.yaml:78 so future dependency reviews look in the right file — I can't edit files under .github/workflows/ myself (GitHub App permissions don't allow workflow modifications). Fix this →

Caveat on verification

I could not run npm ci / npm run build / npm test in this review sandbox — dependency installation wasn't in my allowed tools, so there's no node_modules to build against. If you want these reviews to independently verify builds, add npm ci, npm run build, and npm test to the review job's --allowedTools. In the meantime I'm relying on the branch's own CI run, which passed (build + test + .mcpb smoke test): run 36383276877. That covers the compile-and-run risk for a patch bump adequately.

Follow-up checks worth doing

  • Nothing required for this PR. The in-memory transport test in test/server.test.ts already drives the real tools through the SDK, which is the right guard for this class of bump — it's what makes an SDK patch bump low-risk to auto-merge here.
  • Confirm the Dependabot commit is signature-verified before merging (required_signatures is on main). Dependabot commits via the GitHub API and is normally signed, but I couldn't query the API to confirm it on this run.
    · branch dependabot/npm_and_yarn/modelcontextprotocol/sdk-1.30.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants