Repository navigation
chore: bump @modelcontextprotocol/sdk from 1.30.1 to 1.31.0 - #77
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) from 1.30.1 to 1.31.0. - [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases) - [Commits](modelcontextprotocol/typescript-sdk@1.30.1...1.31.0) --- updated-dependencies: - dependency-name: "@modelcontextprotocol/sdk" dependency-version: 1.31.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
Claude finished @dependabot[bot]'s task in 1m 19s —— View job Dependency review:
|
| Import | Location | Touched by 1.31.0? |
|---|---|---|
McpServer + registerTool (incl. readOnlyHint / destructiveHint annotations) |
src/server.ts:1, src/server.ts:33-99 |
No |
StdioServerTransport |
src/index.ts:2 |
No |
Client, InMemoryTransport |
test/server.test.ts:2-3 |
No |
Tool registration and the read/write annotation split are untouched by this release, so the execute_read_action (readOnlyHint: true, auto-allowed) vs execute_write_action (destructiveHint: true, requires approval) distinction behaves as before.
Verification
CI on this branch is green (run 37269192658) — that covers build, tests, and the .mcpb smoke test across the Node matrix.
For transparency: I was not able to run npm ci / npm run build / npm test locally in this review sandbox (dependency install isn't in my allowed tools here), so the build/test evidence above is the repo's own CI run on this exact commit rather than a local reproduction. Given the SDK's only functional change is in an auth path this repo doesn't import, I don't think a local run would tell you anything CI hasn't.
One unrelated note (not blocking)
The dependency-review prompt in .github/workflows/claude-review.yaml:78 says to check "tool registration and annotations in src/index.ts", but those moved to createServer in src/server.ts — index.ts is now only the stdio bin. Worth a one-line correction so future dependency reviews look in the right file. I can't edit files under .github/workflows/ (GitHub App permissions don't allow workflow modifications), and per CLAUDE.md a change to that file wouldn't be reviewable by itself anyway — it takes effect only after merge to main.
· branch dependabot/npm_and_yarn/modelcontextprotocol/sdk-1.31.0
Bumps @modelcontextprotocol/sdk from 1.30.1 to 1.31.0.
Release notes
Sourced from @modelcontextprotocol/sdk's releases.
Commits
4b0051fchore: bump version to 1.31.0 (#2890)51ad4f0[v1.x] Bind stored OAuth credentials to the authorization server that issued ...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)