[Snyk] Security upgrade @modelcontextprotocol/sdk from 1.15.0 to 1.26.0#52
[Snyk] Security upgrade @modelcontextprotocol/sdk from 1.15.0 to 1.26.0#52Krosebrook wants to merge 2 commits intomainfrom
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-MODELCONTEXTPROTOCOLSDK-15208843
|
Note Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported. |
There was a problem hiding this comment.
Copilot wasn't able to review any files in this pull request.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
Important Review skippedIgnore keyword(s) in the title. Please check the settings in the CodeRabbit UI or the You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-MODELCONTEXTPROTOCOLSDK-15208843
Snyk has created this PR to fix 1 vulnerabilities in the pnpm dependencies of this project.
Snyk changed the following file(s):
js/plugins/mcp/package.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-MODELCONTEXTPROTOCOLSDK-15208843
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Race Condition
Note
Low Risk
Dependency-only change; main risk is subtle runtime/typing differences in
@modelcontextprotocol/sdkwithout an updated lockfile to ensure consistent installs.Overview
Updates the
js/plugins/mcpplugin to use a newer@modelcontextprotocol/sdkversion to address a reported race-condition vulnerability.The PR does not include an updated
pnpm-lock.yaml(per the PR note), so reviewers should ensure the lockfile is regenerated/validated before merge to keep dependency resolution consistent.Written by Cursor Bugbot for commit eb677d6. This will update automatically on new commits. Configure here.
Summary by cubic
Upgraded @modelcontextprotocol/sdk from 1.15.0 to 1.26.0 in js/plugins/mcp/package.json to fix a high‑severity race condition. Dependency-only change; no source code edits.
Dependencies
Migration
Written for commit 09277ab. Summary will update on new commits.