Repository navigation
chore(deps): bump the production-dependencies group across 1 directory with 4 updates - #55
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
…y with 4 updates Bumps the production-dependencies group with 4 updates in the / directory: [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk), [commander](https://github.com/tj/commander.js), [smol-toml](https://github.com/squirrelchat/smol-toml) and [zod](https://github.com/colinhacks/zod). Updates `@modelcontextprotocol/sdk` from 1.29.0 to 1.32.0 - [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases) - [Commits](modelcontextprotocol/typescript-sdk@v1.29.0...1.32.0) Updates `commander` from 14.0.3 to 15.0.0 - [Release notes](https://github.com/tj/commander.js/releases) - [Changelog](https://github.com/tj/commander.js/blob/master/CHANGELOG.md) - [Commits](tj/commander.js@v14.0.3...v15.0.0) Updates `smol-toml` from 1.7.0 to 1.9.0 - [Release notes](https://github.com/squirrelchat/smol-toml/releases) - [Commits](squirrelchat/smol-toml@v1.7.0...v1.9.0) Updates `zod` from 4.4.3 to 4.6.5 - [Release notes](https://github.com/colinhacks/zod/releases) - [Commits](colinhacks/zod@v4.4.3...v4.6.5) --- updated-dependencies: - dependency-name: "@modelcontextprotocol/sdk" dependency-version: 1.32.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: commander dependency-version: 15.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: production-dependencies - dependency-name: smol-toml dependency-version: 1.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: zod dependency-version: 4.6.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Contributor
Author
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
dependabot
Bot
deleted the
dependabot/npm_and_yarn/production-dependencies-8d82feee4f
branch
October 7, 2026 05:28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the production-dependencies group with 4 updates in the / directory: @modelcontextprotocol/sdk, commander, smol-toml and zod.
Updates
@modelcontextprotocol/sdkfrom 1.29.0 to 1.32.0Release notes
Sourced from @modelcontextprotocol/sdk's releases.
... (truncated)
Commits
32549b0chore: bump version to 1.32.0 (#2935)588d51d[v1.x] test(e2e): cover tools/call and prompts/get without arguments (#2931)5a0724d[v1.x] feat(auth): add expectedResource to requireBearerAuth (#2930)0ca0b62[v1.x] fix(server): accept tools/call and prompts/get requests that omit argu...fd26801[v1.x] feat(server): add maxToolInputElements option to limit the number of e...727075b[v1.x] fix(tasks): keep tasks of the in-memory task store within the session ...0ff6377[v1.x] examples: close idle sessions and cap the session map (#2914)c2ce003docs: point SECURITY.md at GitHub Security Advisories (v1.x) (#2910)30bfe51[v1.x] fix(client): follow redirects only within the endpoint's origin (#2902)4b0051fchore: bump version to 1.31.0 (#2890)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@modelcontextprotocol/sdksince your current version.Updates
commanderfrom 14.0.3 to 15.0.0Release notes
Sourced from commander's releases.
... (truncated)
Changelog
Sourced from commander's changelog.
Commits
ba6d13dFix release dates in changelog (#2523)a752ed9Pin GitHub actions with hash (#2521)74d5dfeDrop EOL node 20 from test matrix, and add node 26 (#2520)6df9b68Update details for 15.0.0 release (#2519)01ce5d0Remove jest esm examples (#2517)d785d8bUpdate dependencies (#2518)9098b48Update dependencies (#2506)373f660Use node:util stripVTControlCharacters instead of own code (#2486)987f289Use simple match in test (to avoid warning about expensive regex) (#2485)0ea3bb3Update dependecies and lint (#2489)Updates
smol-tomlfrom 1.7.0 to 1.9.0Release notes
Sourced from smol-toml's releases.
... (truncated)
Commits
6f9739afix: gate[is|to]WellFormed(Node 18 compat)a73ca32fix: no Temporal with toml-test when Node < 267727890chore: version bump641903dchore: rewrite README.md2df14c5fix(types): make it work if Temporal doesn't exist3eaa44echore: update benchmark harnesscd3ba60feat: safety option for dangerous properties6746a7fperf: refactor TomlDate to avoid regex path16fa64fchore: move benchmarks and test harness under 0BSDbbd14b1fix: correct sign for single-char numbersUpdates
zodfrom 4.4.3 to 4.6.5Release notes
Sourced from zod's releases.
... (truncated)
Commits
59bbc03chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump0f3f5ee4.6.5cc4cd4eRevert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, ref...ca0229aRevert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed w...56222cdfeat(instanceof): key the .properties() shape off the instance type (#6600)de65a5cdocs: lead the properties section with the check and add a Zod Mini tab (#6598)f1448f7docs: fold the 4.6.x patch highlights into the 4.6 post's own sectionsd2b135cdocs: add the 4.6.x patch highlights to the 4.6 post2bb0871chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump743aedb4.6.4Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsSummary by cubic
Bumps
@modelcontextprotocol/sdkto 1.32.0,commanderto 15.0.0,smol-tomlto 1.9.0, andzodto 4.6.5. Thecommandermajor bump and the SDK redirect change need attention.Migration
commander15 is ESM-only and requires Node.js v22.12.0 or higher; the package now needs pnpm 10.commander15 no longer implicitly sets a default when both a positive and a lone--no-*option are defined.redirectPolicy: 'follow'.issuerfield on OAuth credentials, so storage rejecting unknown fields must accept it.smol-tomlreturns objects with a null prototype;zodaddsz.currencyCode()and speeds upz.url()validation.Written for commit 9375354. Summary will update on new commits.