build(deps): bump @modelcontextprotocol/ext-apps from 1.7.5 to 2.0.0 - #815
Merged
ScriptedAlchemy merged 9 commits intoSep 25, 2026
Merged
ScriptedAlchemy merged 9 commits into
ScriptedAlchemy merged 9 commits into
Conversation
Bumps [@modelcontextprotocol/ext-apps](https://github.com/modelcontextprotocol/ext-apps) from 1.7.5 to 2.0.0. - [Release notes](https://github.com/modelcontextprotocol/ext-apps/releases) - [Changelog](https://github.com/modelcontextprotocol/ext-apps/blob/main/RELEASES.md) - [Commits](modelcontextprotocol/ext-apps@v1.7.5...v2.0.0) --- updated-dependencies: - dependency-name: "@modelcontextprotocol/ext-apps" dependency-version: 2.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
commit: |
…ext-apps 1.x size figures
dependabot
Bot
deleted the
dependabot/npm_and_yarn/modelcontextprotocol/ext-apps-2.0.0
branch
September 25, 2026 01:01
This was referenced Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps @modelcontextprotocol/ext-apps from 1.7.5 to 2.0.0.
Release notes
Sourced from @modelcontextprotocol/ext-apps's releases.
Commits
352f6ceCI: build the WSL job on ext4, skip the unused Chromium download, list tsconf...ae4f7e0Sync the quickstart tsconfig snippetsa0dcf16CI: build the WSL job on ext4, skip the unused Chromium download, list tsconf...ae0fe55Migration guide fixes and editor-visible deprecation for the 1.x handler form...853c9f7Migration guide fixes and editor-visible deprecation for the 1.x handler form12aa50bAdd cross-version interop test against the published ext-apps 1.7.5 (#770)218aef1Keep the 1.x handler registration forms as deprecated overloads (#769)5f6346eAdd cross-version interop test against published ext-apps 1.7.54eab52eExport the legacy handler types from the root entry728b0bfKeep the 1.x handler registration forms as deprecated overloadsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Maintainer notes
ext-apps 2.0 moves to the MCP SDK 2 split packages (
@modelcontextprotocol/clientandcoreare required peers,serveris optional) with an unchanged wire protocol. Breakages in this repo, and the fixes:packages/workbench/src/mcp/runtime-app-bridge.ts). Handlers now receive the SDK 2BaseContext, so the bridge readsextra.mcpReq.signal(it wasextra.signal). Without this, consent prompts and the open-link, download, and display-mode abort checks silently lose cancellation.tools/listis now registered in the method-keyed form and forwarded asrequest(req, { signal }). The last SDK v1 import is gone, and@modelcontextprotocol/sdkis removed from the Workbench. Thesandbox.cspreadonly type is cast toMcpUiResourceCsp. Tests now pass the real context shape, and a new test drivesui/open-linkandtools/listthrough the realAppBridgeto prove the signal reaches consent and the forwarded request.createRuntimeAppBridgeFactoryhas had no production caller since it landed (40d04ba).main.tsxnever supplies the runtime preview'screateBridgeFactory, so the built Workbench contains no ext-apps code. This PR therefore ships nothing in theagent-bundletarball and carriesskip-changeset; the only publishable-file edit is a source comment.examples/rsc-agent-runtime. The server moved from SDK v1 to@modelcontextprotocol/serverandnode2.0.0:McpServer,ServerContext,ctx.mcpReq.send({ method: 'roots/list' }), and@modelcontextprotocol/server/stdio. HTTP now usescreateMcpHandler(..., { legacy: 'stateless' })withtoNodeHandlerandhostHeaderValidation, keeping the example's exact-origin check. The old express behavior is preserved: a 100 kB body cap (413) and JSON parse errors (400); non-identityContent-Encodingnow returns 415. express and SDK v1 are removed, tests use the v2Client, and the ambientext-apps/reacttype shim is deleted because 2.0's declarations resolve. The materializer no longer requires async chunks formcp/http: the only async chunk there came from ext-apps 1.7.5 lazily importingzod/v4.GET/DELETE /mcpreturn 405 JSON instead of express's 404 page. Clients that negotiate the 2026-07-28 protocol refuse server-to-client requests, so for them the roots lookup falls back to the working directory.AB4772size guidance with agent-bundle's App compiler. A minimal ext-apps 2.0 view is 249,236 bytes (64,844 gzip); the same view on 1.7.5 is 444,505 bytes (105,773 gzip). Updateddocs/diagnostics.md, en/zhmcp.mdx, and the source comment.Local gate (branch contains origin/main 64492dd)
pnpm build/pnpm typecheck/pnpm lintpnpm test:unitrstest --config rstest.integration.config.tsfor discovery, lifecycles, mcp-app-real, mcp-app-preview-browser, mcp-app-frame, mcp-page-app-browser, examples-real, rsc-runtime-topology-script, mcp-apps-compilenode scripts/run-packed-tests.mjsfor workbench packed-release, dev-workbench-packaging, rsc-runtime-optional-packagingnode scripts/run-examples-check.mjspnpm --filter @agent-bundle/rsc-agent-runtime-demo check(after the review fixes)pnpm docs:site:buildThe independent review (change-risk-reviewer, GPT-5.6 Sol Max) found three issues: the dormant bridge made the changeset inaccurate (changeset removed), compressed bodies were misreported as parse errors (now 415, with a test), and the 1.x size figures didn't match the probe (aligned). Its follow-up review found no remaining blockers.
Root verification verdict: PASS+NOTES on the merged commit
dd322cb647This PR merged at 01:01Z before a root verdict, with CI still pending and no local gate or independent review recorded in the body. The root verified the merged commit on
mainagainst its parentb9fbc2e06d.dd322cb647typecheck,lint,test:unit(4487 passed),examples:check, the mcp-app browser test (14 passed),eval:spot, and thersc-agent-runtimesuite (170 passed, includingmcp-transports.integration.test.ts) all pass. The first integration pool run had 3 failures that each passed solo. That run overlapped a root e2e run on the same machine.examples-real.e2e.test.ts, which rebuilds the Workbenchdd322cb647and 7/7 on the parentb9fbc2e06d. That covers every populated MCP App workflow surface and the flagship Application tree.2025-11-25, 3 tools with UI metadata, and an App resource served astext/html;profile=mcp-app. The HTTP probes return 403 for a foreign host, 403 for a foreign origin, 413 for an oversized body, 400 for invalid JSON, and 405 for GET and DELETE.http.tskeeps its host and origin checks and tightens two others. The 100 KB body limit now covers non-JSON posts, and a non-identityContent-Encodingreturns 415. The Workbench bridge's origin and source checks and its teardown are untouched. The only publishable change is a JSDoc comment, so no changeset is needed.Notes:
writeJsonandreadRequestBodyin the example'shttp.tsmirrordev/http.ts. That module is not a public export, and examples may only use public exports, so the copy is forced.@modelcontextprotocol/sdk@1.30.0andexpressremain in the lockfile only through the root@modelcontextprotocol/conformancedevDependency.No regression attributable to this merge was found, so no fix or revert PR is needed.