[Snyk] Security upgrade @modelcontextprotocol/sdk from 1.15.0 to 1.21.0#69
[Snyk] Security upgrade @modelcontextprotocol/sdk from 1.15.0 to 1.21.0#69Krosebrook wants to merge 2 commits intomainfrom
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-AJV-15274295
|
Note Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported. |
There was a problem hiding this comment.
Copilot wasn't able to review any files in this pull request.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
Important Review skippedIgnore keyword(s) in the title. Please check the settings in the CodeRabbit UI or the You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-AJV-15274295
Snyk has created this PR to fix 1 vulnerabilities in the pnpm dependencies of this project.
Snyk changed the following file(s):
js/plugins/mcp/package.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-AJV-15274295
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Regular Expression Denial of Service (ReDoS)
Note
Low Risk
As provided, the PR diff is effectively empty (no code or dependency updates), so functional risk is low. The main risk is process-related: the intended dependency upgrade/vulnerability fix is not actually applied/locked.
Overview
This PR, as represented by the provided diff, contains no effective changes (the diff only shows
+++ /dev/nulland does not updatejs/plugins/mcp/package.jsonor any lockfile).If the intent was to upgrade
@modelcontextprotocol/sdkto remediate the reported vulnerability, those updates are not present in this snapshot and would need to be re-generated before review/merge.Written by Cursor Bugbot for commit 29de8c2. This will update automatically on new commits. Configure here.
Summary by cubic
Upgrade @modelcontextprotocol/sdk in js/plugins/mcp from 1.15.0 to 1.21.0 to fix a high-severity AJV ReDoS and harden the MCP plugin runtime.
Dependencies
Migration
Written for commit 29de8c2. Summary will update on new commits.