Skip to content

chore: bump @modelcontextprotocol/sdk from 1.30.1 to 1.31.0 - #77

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/modelcontextprotocol/sdk-1.31.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/modelcontextprotocol/sdk-1.31.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps @modelcontextprotocol/sdk from 1.30.1 to 1.31.0.

Release notes

Sourced from @​modelcontextprotocol/sdk's releases.

1.31.0

Upgrade notes

  • Stored OAuth tokens and client information now include an issuer field. Storage that rejects unknown fields needs to allow it.
  • Pass expectedIssuer when constructing ClientCredentialsProvider, PrivateKeyJwtProvider or StaticPrivateKeyJwtProvider. Constructing them without it is deprecated.

What's Changed

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.1...1.31.0

Commits
  • 4b0051f chore: bump version to 1.31.0 (#2890)
  • 51ad4f0 [v1.x] Bind stored OAuth credentials to the authorization server that issued ...
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) from 1.30.1 to 1.31.0.
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@1.30.1...1.31.0)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.31.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026
@claude

claude Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Claude finished @dependabot[bot]'s task in 1m 19s —— View job


Dependency review: @modelcontextprotocol/sdk 1.30.1 → 1.31.0

  • Identify what changed / semver scope
  • Check release notes for breaking or behaviour changes
  • Check how the SDK is used in this repo
  • Verify build + test on the PR branch
  • Post review

Verdict: safe to merge. No code changes needed.


What changed

Minor bump, not a major — lockfile only (3/-3). package.json:42 already declares ^1.29.0, so the range covers it and Dependabot correctly left it alone.

Upstream has exactly two commits: the version bump, and #2888 "Bind stored OAuth credentials to the authorization server that issued them".

Release-note items, checked against this repo

Both upgrade notes are scoped to the SDK's OAuth client machinery:

  1. "Stored OAuth tokens and client information now include an issuer field. Storage that rejects unknown fields needs to allow it."
  2. "Pass expectedIssuer when constructing ClientCredentialsProvider, PrivateKeyJwtProvider or StaticPrivateKeyJwtProvider. Constructing them without it is deprecated."

Neither applies. A repo-wide grep for ClientCredentialsProvider, PrivateKeyJwtProvider, OAuthClientProvider, sdk/*/auth, tokenStore, and expectedIssuer returns nothing outside the lockfile. This server authenticates to Kosli with a static bearer token (KOSLI_API_TOKEN) that KosliClient puts on a globalThis.fetch call — it never touches the SDK's auth layer, and it stores no credentials.

SDK surface actually used

Import Location Touched by 1.31.0?
McpServer + registerTool (incl. readOnlyHint / destructiveHint annotations) src/server.ts:1, src/server.ts:33-99 No
StdioServerTransport src/index.ts:2 No
Client, InMemoryTransport test/server.test.ts:2-3 No

Tool registration and the read/write annotation split are untouched by this release, so the execute_read_action (readOnlyHint: true, auto-allowed) vs execute_write_action (destructiveHint: true, requires approval) distinction behaves as before.

Verification

CI on this branch is green (run 37269192658) — that covers build, tests, and the .mcpb smoke test across the Node matrix.

For transparency: I was not able to run npm ci / npm run build / npm test locally in this review sandbox (dependency install isn't in my allowed tools here), so the build/test evidence above is the repo's own CI run on this exact commit rather than a local reproduction. Given the SDK's only functional change is in an auth path this repo doesn't import, I don't think a local run would tell you anything CI hasn't.

One unrelated note (not blocking)

The dependency-review prompt in .github/workflows/claude-review.yaml:78 says to check "tool registration and annotations in src/index.ts", but those moved to createServer in src/server.ts — index.ts is now only the stdio bin. Worth a one-line correction so future dependency reviews look in the right file. I can't edit files under .github/workflows/ (GitHub App permissions don't allow workflow modifications), and per CLAUDE.md a change to that file wouldn't be reviewable by itself anyway — it takes effect only after merge to main.
· branch dependabot/npm_and_yarn/modelcontextprotocol/sdk-1.31.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants