Skip to content

chore(deps): bump the production-dependencies group across 1 directory with 4 updates - #55

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-8d82feee4f
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-8d82feee4f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 4 updates in the / directory: @modelcontextprotocol/sdk, commander, smol-toml and zod.

Updates @modelcontextprotocol/sdk from 1.29.0 to 1.32.0

Release notes

Sourced from @​modelcontextprotocol/sdk's releases.

1.32.0

Upgrade notes

  • Redirects: the HTTP client transports now follow a redirect only when it stays on the same origin (same scheme, host and port; http to https on the same host is allowed). A deployment whose endpoint redirects to another host or port either configures the final URL or sets redirectPolicy: 'follow' on StreamableHTTPClientTransport or SSEClientTransport. In browsers, a redirected request fails unless that option is set.
  • New options, both off unless you set them: maxToolInputElements on McpServer limits the number of array elements and object members in a tool call's arguments. expectedResource on requireBearerAuth accepts only tokens issued for this server (the token's audience).

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.31.0...1.32.0

1.31.0

Upgrade notes

  • Stored OAuth tokens and client information now include an issuer field. Storage that rejects unknown fields needs to allow it.
  • Pass expectedIssuer when constructing ClientCredentialsProvider, PrivateKeyJwtProvider or StaticPrivateKeyJwtProvider. Constructing them without it is deprecated.

What's Changed

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.1...1.31.0

1.30.1

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.0...1.30.1

1.30.0

What's Changed

... (truncated)

Commits
  • 32549b0 chore: bump version to 1.32.0 (#2935)
  • 588d51d [v1.x] test(e2e): cover tools/call and prompts/get without arguments (#2931)
  • 5a0724d [v1.x] feat(auth): add expectedResource to requireBearerAuth (#2930)
  • 0ca0b62 [v1.x] fix(server): accept tools/call and prompts/get requests that omit argu...
  • fd26801 [v1.x] feat(server): add maxToolInputElements option to limit the number of e...
  • 727075b [v1.x] fix(tasks): keep tasks of the in-memory task store within the session ...
  • 0ff6377 [v1.x] examples: close idle sessions and cap the session map (#2914)
  • c2ce003 docs: point SECURITY.md at GitHub Security Advisories (v1.x) (#2910)
  • 30bfe51 [v1.x] fix(client): follow redirects only within the endpoint's origin (#2902)
  • 4b0051f chore: bump version to 1.31.0 (#2890)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​modelcontextprotocol/sdk since your current version.


Updates commander from 14.0.3 to 15.0.0

Release notes

Sourced from commander's releases.

v15.0.0

Commander 15 is ESM only. This is expected to be seamless for ESM consumers, but some CommonJS consumers may hit issues with tooling requiring configuration for ESM-only dependencies. See Migration Tips below.

The release of Commander 15 moves Commander 14 into maintenance. Commander 14 will get security updates for 12 months (to May 2027). For more info see Release Policy.

Added

  • show excess command-arguments in error message (#2384)

Fixed

  • Breaking: only lone --no-* option sets default option value to true, default not implicitly set when define both positive and negative option in either order (#2405)
  • update example to use compatible character for MINGW64 (#2475)

Changed

  • Breaking: migrated Commander implementation from CommonJS to ESM (#2464)
  • Breaking: Commander 15 requires Node.js v22.12.0 or higher (for require(esm)).
  • dev: switch tests from Jest to node:test test runner (#2463)

Deleted

  • Breaking: removed deprecated export of commander/esm.mjs (#2464)

Migration Tips

Commander 15 is ESM only, but this does not mean you need to migrate to ESM to use it. Importing ESM from CommonJS is supported by Node.js, and Bun, and Deno. Hopefully it Just Works for you! However, you may be using a different runtime or some other part of your setup that may not yet natively support importing ESM from CommonJS, such as your testing framework or bundler.

If you have problems using Commander 15 in your environment, one option is stay on Commander 14 for now. Commander 14 will get security updates until May 2027 and things will hopefully improve for your setup in the meantime.

v15.0.0-0

Commander 15 is ESM only. This is expected to be seamless for ESM consumers, but some CommonJS consumers may hit issues with tooling requiring configuration for ESM-only dependencies. See Migration Tips below.

The release of Commander 15 in May 2026 will move Commander 14 into maintenance. Commander 14 will get security updates for 12 months (to May 2027). For more info see Release Policy.

Added

  • show excess command-arguments in error message (#2384)

Fixed

  • Breaking: only lone --no-* option sets default option value to true, default not implicitly set when define both positive and negative option in either order (#2405)
  • update example to use compatible character for MINGW64 (#2475)

... (truncated)

Changelog

Sourced from commander's changelog.

[15.0.0] (2026-05-29)

Commander 15 is ESM only. This is expected to be seamless for ESM consumers, but some CommonJS consumers may hit issues with tooling requiring configuration for ESM-only dependencies. See Migration Tips below.

The release of Commander 15 moves Commander 14 into maintenance. Commander 14 will get security updates for 12 months (to May 2027). For more info see Release Policy.

Added

  • show excess command-arguments in error message (#2384)

Fixed

  • Breaking: only lone --no-* option sets default option value to true, default not implicitly set when define both positive and negative option in either order (#2405)
  • update example to use compatible character for MINGW64 (#2475)

Changed

  • Breaking: migrated Commander implementation from CommonJS to ESM (#2464)
  • Breaking: Commander 15 requires Node.js v22.12.0 or higher (for require(esm)).
  • dev: switch tests from Jest to node:test test runner (#2463)

Deleted

  • Breaking: removed deprecated export of commander/esm.mjs (#2464)

Migration Tips

Commander 15 is ESM only, but this does not mean you need to migrate to ESM to use it. Importing ESM from CommonJS is supported by Node.js, and Bun, and Deno. Hopefully it Just Works for you! However, you may be using a different runtime or some other part of your setup that may not yet natively support importing ESM from CommonJS, such as your testing framework or bundler.

If you have problems using Commander 15 in your environment, one option is stay on Commander 14 for now. Commander 14 will get security updates until May 2027 and things will hopefully improve for your setup in the meantime.

[15.0.0-0] (2026-02-22)

(Released as 15.0.0)

Commits

Updates smol-toml from 1.7.0 to 1.9.0

Release notes

Sourced from smol-toml's releases.

v1.9.0

Huge update!!! This is most likely the largest update the library received since its release, with lots of new features and improvements.

Performance improvements

Significant parts of the internal parse logic have been rewritten, improving performance by 1.5x-2x. The library was already comfortably ahead of the others, but it is now faster than ever, sitting at 4x faster parse performance than the closest maintained implementation.

Problematic code paths have also been replaced by safer implementations, solving potential DoS vectors. See GHSA-r4xh-jqrq-34v2.

Note: the objects returned by the library now have a null prototype. This is a transparent change for 99.9% of users, and is one of the most significant contributors to the major performance gains in this version.

Full Temporal support

Version 1.8.0 brought support for Temporal in stringify; now the library is also able to emit Temporal objects instead of its own ad-hoc TomlDate object. It is not enabled by default, but it will become the default in v2. Enable by setting useLegacyDate: false in the parser's options.

Better Temporal support in stringify

Temporal support has been improved since it released: Temporal objects that cannot be represented (such as Temporal.PlainMonthDay) now throw an error (instead of silently emitting a bogus object).

A new option has been added to stringify to disallow Temporal objects that cannot be fully represented in TOML. This includes ZonedDateTime objects with a IANA timezone attached instead of a plain offset, and dates with a specific calendar value set. Enable by setting strictTemporal: true in the options.

Handling of unsafe keys

Since its release the library has been protected against prototype pollution attacks, setting properties like __proto__ using safe mechanisms that do not trigger prototype pollution. However, while the returned objects are safe on their own, they may become problematic if used carelessly.

Inspired by secure-json-parse, the library now offers a way to either drop unsafe properties from the returned object, or to throw an error and reject documents altogether. By default, these potentially unsafe keys are preserved and returned.

Miscellaneous updates

  • Unicode BOM is now gracefully accepted and ignored.
  • Table array headers are now properly checked again. Reported in #65.
  • Closed certain gaps where invalid whitespace would be accepted. Reported in #61.
  • Bogus local date and local time values with a UTC offset are no longer accepted.
  • Certain error messages are more accurate and handle errors at line boundaries better.
  • The default export of the lib is now formally deprecated; use a import * instead. Proposed in #50.
  • On Node 20+, strings that contain lone surrogates are now normalised to well-formed strings.
  • On Node 20+, keys that contain lone surrogates are now rejected.

Full Changelog: squirrelchat/smol-toml@v1.8.0...v1.9.0

v1.8.0

What's Changed

Full Changelog: squirrelchat/smol-toml@v1.7.2...v1.8.0

v1.7.2

What's Changed

... (truncated)

Commits
  • 6f9739a fix: gate [is|to]WellFormed (Node 18 compat)
  • a73ca32 fix: no Temporal with toml-test when Node < 26
  • 7727890 chore: version bump
  • 641903d chore: rewrite README.md
  • 2df14c5 fix(types): make it work if Temporal doesn't exist
  • 3eaa44e chore: update benchmark harness
  • cd3ba60 feat: safety option for dangerous properties
  • 6746a7f perf: refactor TomlDate to avoid regex path
  • 16fa64f chore: move benchmarks and test harness under 0BSD
  • bbd14b1 fix: correct sign for single-char numbers
  • Additional commits viewable in compare view

Updates zod from 4.4.3 to 4.6.5

Release notes

Sourced from zod's releases.

v4.6.5

Commits:

  • d2b135cfb7a3582b9eb515756b9166bcb9521f4a docs: add the 4.6.x patch highlights to the 4.6 post
  • f1448f7cee00df9fe1e9ad84a000aa1828cc8bc1 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • de65a5cb39ed22a507fac935788f718fa88d104f docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • 56222cd1532c07bcb91b67df529cab4c0a215330 feat(instanceof): key the .properties() shape off the instance type (#6600)
  • ca0229a404818290e6cdcfefcd7eb2d04bcbb543 Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)"
  • cc4cd4ee9c52fcaa10964e48cc144541e41a5ed9 Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)""
  • 0f3f5ee3ca56c7574bf849e54f79e9a6e02562ee 4.6.5
  • 59bbc03e10c636b9eb3c393dfeb552819774ec21 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump

v4.6.4

A patch on top of 4.6.3.

  • d6bc1e30 feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)
  • ad32d751 perf: z.url() rejects an invalid URL with URL.canParse() instead of a throwing constructor, about 50x faster; fewer allocations on the validation path (#6588)
  • 2bb08717 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • f6e1701a chore(deps): bump next to 15.5.25 and vite to 7.3.6 (#6153)

v4.6.3

A patch on top of 4.6.2.

  • 413cce9a fix(v4): make z.properties() a check again (#6594) — removes the standalone z.properties() schema from 4.6.0; z.instanceof().properties() and .check(...z.properties()) are unchanged
  • 75d63ee1 docs: show only the .properties() method form in the 4.6 post
  • 46da9572 docs: match the error-message examples to what the parsers emit

v4.6.2

A patch on top of 4.6.1.

v4.6.1

A patch on top of 4.6.0.

v4.6.0

Zod 4.6 is now available.

npm install zod@latest

At a glance:

... (truncated)

Commits
  • 59bbc03 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump
  • 0f3f5ee 4.6.5
  • cc4cd4e Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, ref...
  • ca0229a Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed w...
  • 56222cd feat(instanceof): key the .properties() shape off the instance type (#6600)
  • de65a5c docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • f1448f7 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • d2b135c docs: add the 4.6.x patch highlights to the 4.6 post
  • 2bb0871 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • 743aedb 4.6.4
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Summary by cubic

Bumps @modelcontextprotocol/sdk to 1.32.0, commander to 15.0.0, smol-toml to 1.9.0, and zod to 4.6.5. The commander major bump and the SDK redirect change need attention.

Migration

  • commander 15 is ESM-only and requires Node.js v22.12.0 or higher; the package now needs pnpm 10.
  • commander 15 no longer implicitly sets a default when both a positive and a lone --no-* option are defined.
  • The MCP SDK HTTP transports now follow redirects only within the same origin; deployments redirecting to another host must set redirectPolicy: 'follow'.
  • The MCP SDK stores an issuer field on OAuth credentials, so storage rejecting unknown fields must accept it.
  • smol-toml returns objects with a null prototype; zod adds z.currencyCode() and speeds up z.url() validation.

Written for commit 9375354. Summary will update on new commits.

Review in cubic Turn on auto-fix

…y with 4 updates

Bumps the production-dependencies group with 4 updates in the / directory: [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk), [commander](https://github.com/tj/commander.js), [smol-toml](https://github.com/squirrelchat/smol-toml) and [zod](https://github.com/colinhacks/zod).


Updates `@modelcontextprotocol/sdk` from 1.29.0 to 1.32.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@v1.29.0...1.32.0)

Updates `commander` from 14.0.3 to 15.0.0
- [Release notes](https://github.com/tj/commander.js/releases)
- [Changelog](https://github.com/tj/commander.js/blob/master/CHANGELOG.md)
- [Commits](tj/commander.js@v14.0.3...v15.0.0)

Updates `smol-toml` from 1.7.0 to 1.9.0
- [Release notes](https://github.com/squirrelchat/smol-toml/releases)
- [Commits](squirrelchat/smol-toml@v1.7.0...v1.9.0)

Updates `zod` from 4.4.3 to 4.6.5
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.4.3...v4.6.5)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.32.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: commander
  dependency-version: 15.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
- dependency-name: smol-toml
  dependency-version: 1.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the enhancement New feature or request label Oct 7, 2026
@dependabot
dependabot Bot requested a review from Boulea7 as a code owner October 7, 2026 03:07
@dependabot dependabot Bot added the enhancement New feature or request label Oct 7, 2026
@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 46ab816d-9da7-4977-aee1-7071bfbdc245

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dependabot @github

dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 7, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/production-dependencies-8d82feee4f branch October 7, 2026 05:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants