Skip to content

chore(deps): bump the npm group across 1 directory with 9 updates - #68

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-e95aefc2d8
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-e95aefc2d8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm group with 9 updates in the / directory:

Package From To
@modelcontextprotocol/sdk 1.29.0 1.31.0
smol-toml 1.8.0 1.9.0
@semantic-release/git 10.0.1 11.0.1
@semantic-release/github 12.0.9 12.0.10
@semantic-release/npm 13.1.5 13.2.0
@types/node 26.1.0 26.6.3
semantic-release 25.0.5 25.0.9
typescript 6.0.3 7.0.2
ws 8.21.3 8.22.0

Updates @modelcontextprotocol/sdk from 1.29.0 to 1.31.0

Release notes

Sourced from @​modelcontextprotocol/sdk's releases.

1.31.0

Upgrade notes

  • Stored OAuth tokens and client information now include an issuer field. Storage that rejects unknown fields needs to allow it.
  • Pass expectedIssuer when constructing ClientCredentialsProvider, PrivateKeyJwtProvider or StaticPrivateKeyJwtProvider. Constructing them without it is deprecated.

What's Changed

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.1...1.31.0

1.30.1

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.0...1.30.1

1.30.0

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@v1.29.0...1.30.0

Commits
  • 4b0051f chore: bump version to 1.31.0 (#2890)
  • 51ad4f0 [v1.x] Bind stored OAuth credentials to the authorization server that issued ...
  • 289ac2c chore: bump version to 1.30.1 (#2848)
  • 12b4256 fix(auth): preserve resource URI without trailing slash (#1968) (#1972)
  • a9f6eb7 [v1.x] fix(server): read HTTP request bodies with a size limit and bound JSON...
  • 2d889f2 chore: bump version to 1.30.0 (#2563)
  • e3f3daa Fix SSE keep-alive timer lifecycle in Streamable HTTP server transport (v1.x)...
  • bb5a718 fix(deps): widen @​hono/node-server past GHSA-frvp-7c67-39w9 (#2549)
  • 1dad263 fix: send SSE keep-alive comment frames from Streamable HTTP server transport...
  • 69749aa Validate Content-Type by parsed media type instead of substring match (v1.x) ...
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​modelcontextprotocol/sdk since your current version.


Updates smol-toml from 1.8.0 to 1.9.0

Release notes

Sourced from smol-toml's releases.

v1.9.0

Huge update!!! This is most likely the largest update the library received since its release, with lots of new features and improvements.

Performance improvements

Significant parts of the internal parse logic have been rewritten, improving performance by 1.5x-2x. The library was already comfortably ahead of the others, but it is now faster than ever, sitting at 4x faster parse performance than the closest maintained implementation.

Problematic code paths have also been replaced by safer implementations, solving potential DoS vectors. See GHSA-r4xh-jqrq-34v2.

Note: the objects returned by the library now have a null prototype. This is a transparent change for 99.9% of users, and is one of the most significant contributors to the major performance gains in this version.

Full Temporal support

Version 1.8.0 brought support for Temporal in stringify; now the library is also able to emit Temporal objects instead of its own ad-hoc TomlDate object. It is not enabled by default, but it will become the default in v2. Enable by setting useLegacyDate: false in the parser's options.

Better Temporal support in stringify

Temporal support has been improved since it released: Temporal objects that cannot be represented (such as Temporal.PlainMonthDay) now throw an error (instead of silently emitting a bogus object).

A new option has been added to stringify to disallow Temporal objects that cannot be fully represented in TOML. This includes ZonedDateTime objects with a IANA timezone attached instead of a plain offset, and dates with a specific calendar value set. Enable by setting strictTemporal: true in the options.

Handling of unsafe keys

Since its release the library has been protected against prototype pollution attacks, setting properties like __proto__ using safe mechanisms that do not trigger prototype pollution. However, while the returned objects are safe on their own, they may become problematic if used carelessly.

Inspired by secure-json-parse, the library now offers a way to either drop unsafe properties from the returned object, or to throw an error and reject documents altogether. By default, these potentially unsafe keys are preserved and returned.

Miscellaneous updates

  • Unicode BOM is now gracefully accepted and ignored.
  • Table array headers are now properly checked again. Reported in #65.
  • Closed certain gaps where invalid whitespace would be accepted. Reported in #61.
  • Bogus local date and local time values with a UTC offset are no longer accepted.
  • Certain error messages are more accurate and handle errors at line boundaries better.
  • The default export of the lib is now formally deprecated; use a import * instead. Proposed in #50.
  • On Node 20+, strings that contain lone surrogates are now normalised to well-formed strings.
  • On Node 20+, keys that contain lone surrogates are now rejected.

Full Changelog: squirrelchat/smol-toml@v1.8.0...v1.9.0

Commits
  • 6f9739a fix: gate [is|to]WellFormed (Node 18 compat)
  • a73ca32 fix: no Temporal with toml-test when Node < 26
  • 7727890 chore: version bump
  • 641903d chore: rewrite README.md
  • 2df14c5 fix(types): make it work if Temporal doesn't exist
  • 3eaa44e chore: update benchmark harness
  • cd3ba60 feat: safety option for dangerous properties
  • 6746a7f perf: refactor TomlDate to avoid regex path
  • 16fa64f chore: move benchmarks and test harness under 0BSD
  • bbd14b1 fix: correct sign for single-char numbers
  • Additional commits viewable in compare view

Updates @semantic-release/git from 10.0.1 to 11.0.1

Release notes

Sourced from @​semantic-release/git's releases.

v11.0.1

11.0.1 (2026-07-24)

Bug Fixes

  • deps: update dependency execa to v10 (#564) (b39d5c6)

v11.0.0

11.0.0 (2026-07-21)

Features

BREAKING CHANGES

  • @semantic-release/git is now a native ES Module. It has named exports for each plugin hook (verifyConditions, prepare)
  • the minimum required version of semantic-release to use @semantic-release/git is now v20.1.0

v11.0.0-beta.2

11.0.0-beta.2 (2026-07-20)

Bug Fixes

  • update Node.js engine version requirements in package.json and package-lock.json (ddf699e)

v11.0.0-beta.1

11.0.0-beta.1 (2026-07-17)

Features

BREAKING CHANGES

  • @semantic-release/git is now a native ES Module. It has named exports for each plugin hook (verifyConditions, prepare)
  • the minimum required version of semantic-release to use @semantic-release/changelog is now v20.1.0

Other Notable Changes

... (truncated)

Commits
  • b39d5c6 fix(deps): update dependency execa to v10 (#564)
  • 9dd61f1 chore(deps): lock file maintenance (#470)
  • c5c6f06 chore(deps): update dependency lodash-es to v4.18.1 [security] (#545)
  • b67458c ci(action): update actions/setup-node action to v6.5.0 (#557)
  • d4990ff ci(action): update actions/checkout action to v6.1.0 (#556)
  • 16d191f chore(deps): update dependency tempy to v3.2.0 (#448)
  • 8efa7b7 chore(deps): update dependency sinon to v21.1.2 (#554)
  • e53dc53 chore(deps): update dependency prettier to v3.9.5 (#552)
  • 4c2f87f chore(deps): update dependency ls-engines to v0.10.1 (#551)
  • 7685d83 chore(deps): update dependency ava to v6.4.1 (#548)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​semantic-release/git since your current version.


Updates @semantic-release/github from 12.0.9 to 12.0.10

Release notes

Sourced from @​semantic-release/github's releases.

v12.0.10

12.0.10 (2026-09-21)

Bug Fixes

  • deps: update dependency @​octokit/plugin-paginate-rest to v15 (#1284) (a63f458)
Commits
  • a63f458 fix(deps): update dependency @​octokit/plugin-paginate-rest to v15 (#1284)
  • f5f6d0e build(deps): bump brace-expansion (#1300)
  • eaffbba build(deps): bump undici from 6.27.0 to 6.28.1 (#1301)
  • 07686dc chore(deps): update dependency undici to v7.29.0 [security] (#1283)
  • 9f010ee build(deps-dev): bump baseline-browser-mapping from 2.10.42 to 2.11.25 (#1295)
  • 81eeeca build(deps-dev): bump js-yaml from 3.15.0 to 3.15.2 (#1294)
  • 43c2210 build(deps-dev): bump fast-uri from 3.1.4 to 3.1.8 (#1290)
  • e703272 build(deps-dev): bump browserslist from 4.28.4 to 4.29.0 (#1291)
  • e7f4b4b chore(deps): update dependency prettier to v3.9.8 (#1298)
  • 2e9e42b chore(deps): update dependency prettier to v3.9.7 (#1296)
  • Additional commits viewable in compare view

Updates @semantic-release/npm from 13.1.5 to 13.2.0

Release notes

Sourced from @​semantic-release/npm's releases.

v13.2.0

13.2.0 (2026-09-21)

Features

  • trusted-publishing: add support for CircleCI (fb35b81)
Commits
  • 5ef76be Merge pull request #1212 from Thomaash/trusted-publishing--circleci
  • 1a4bdda chore(deps): lock file maintenance (#1232)
  • 886ec16 chore(deps): update dependency prettier to v3.9.8 (#1231)
  • 0388a4d chore(deps): update dependency prettier to v3.9.7 (#1230)
  • fb35b81 feat(trusted-publishing): add support for CircleCI
  • f5cca0a chore(deps): lock file maintenance (#1229)
  • 095f289 chore(deps): update dependency p-retry to v8.0.1 (#1227)
  • bb003a4 chore(deps): lock file maintenance (#1228)
  • ca0b340 chore(deps): update dependency got to v16 (#1226)
  • 22a1e17 chore(deps): lock file maintenance (#1225)
  • Additional commits viewable in compare view

Updates @types/node from 26.1.0 to 26.6.3

Commits

Updates semantic-release from 25.0.5 to 25.0.9

Release notes

Sourced from semantic-release's releases.

v25.0.9

25.0.9 (2026-08-05)

Bug Fixes

  • do not expose the authenticated repository URL in EGITNOPERMISSION errors (#4283) (8d905a5)

v25.0.8

25.0.8 (2026-07-18)

Bug Fixes

  • handle potential null values in commit message and gitTags trimming (0a60004)
  • hide-sensitive: mask key/auth/webhook env vars (973d763)
  • mask sensitive environment variables and improve commit handling (#4252) (1bfdc52)
  • prevent template evaluation syntax in branch expansion and tag formatting (f121540)

v25.0.7

25.0.7 (2026-07-13)

Bug Fixes

  • argument Injection via repositoryUrl in package.json (#4245) (c46dbda)

v25.0.6

25.0.6 (2026-07-10)

Bug Fixes

  • ensure encoded secrets get masked (8e28dd3)
Commits
  • 8d905a5 fix: do not expose the authenticated repository URL in EGITNOPERMISSION error...
  • e176eb7 ci(action): update github/codeql-action action to v4.37.6 (#4282)
  • d27db1b chore(deps): update dependency js-yaml to v4.3.1 (#4279)
  • 55beeac ci(action): update github/codeql-action action to v4.37.5 (#4277)
  • 7bf348d chore(deps): update dependency nock to v14.0.17 (#4275)
  • 2ec3ba2 chore(deps): update dependency mockserver-client to v7.5.0 (#4274)
  • d3b7724 chore(deps): update npm to v12.0.2 (#4273)
  • 514dc5f chore(deps): update dependency npm-run-all2 to v9.0.3 (#4271)
  • f25b716 ci(action): update github/codeql-action action to v4.37.4 (#4270)
  • 1114416 chore: remove 'next version' badge from README (#4265)
  • Additional commits viewable in compare view

Updates typescript from 6.0.3 to 7.0.2

Release notes

Sourced from typescript's releases.

TypeScript 7.0.2

https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/

This tag was originally released at: https://github.com/microsoft/typescript-go/releases/tag/typescript%2Fv7.0.2

Commits
  • 1e4744d Merge branch 'main' into ts7-release
  • a5a219cmicrosoft/typescript-go#4558
  • ecfe30d Update status localization
  • 5de25b5 Hide executable name in TypeScript status
  • d7ce74a Show bundled TypeScript version for packaged servers
  • 29be66a Correct TS 7 release version to 7.0.2
  • ed2bd1b Merge branch 'main' into ts7-release
  • 8873075 Bump the github-actions group across 1 directory with 3 updates (microsoft/ty...
  • 9427131 Set up stable / nightly extension split, other prep (microsoft/typescript-go#...
  • d4eaca5microsoft/typescript-go#4549
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by microsoft1es, a new releaser for typescript since your current version.


Updates ws from 8.21.3 to 8.22.0

Release notes

Sourced from ws's releases.

8.22.0

Features

  • Introduced the protocols option (8b918b01).

Bug fixes

  • Calling websocket.close() with invalid arguments no longer transitions the state to WebSocket.CLOSING (#2337).
Commits
  • 297202c [dist] 8.22.0
  • 8b918b0 [feature] Introduce the protocols option
  • 73e03eb [ci] Update actions/setup-node action to v7
  • d9b8954 [fix] Change the ready state after validating the arguments (#2337)
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 30, 2026
@socket-security

socket-security Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-e95aefc2d8 branch 4 times, most recently from ed1eb74 to 9fbff4d Compare October 3, 2026 15:10
Bumps the npm group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.29.0` | `1.31.0` |
| [smol-toml](https://github.com/squirrelchat/smol-toml) | `1.8.0` | `1.9.0` |
| [@semantic-release/git](https://github.com/semantic-release/git) | `10.0.1` | `11.0.1` |
| [@semantic-release/github](https://github.com/semantic-release/github) | `12.0.9` | `12.0.10` |
| [@semantic-release/npm](https://github.com/semantic-release/npm) | `13.1.5` | `13.2.0` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.0` | `26.6.3` |
| [semantic-release](https://github.com/semantic-release/semantic-release) | `25.0.5` | `25.0.9` |
| [typescript](https://github.com/microsoft/TypeScript) | `6.0.3` | `7.0.2` |
| [ws](https://github.com/websockets/ws) | `8.21.3` | `8.22.0` |



Updates `@modelcontextprotocol/sdk` from 1.29.0 to 1.31.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@v1.29.0...1.31.0)

Updates `smol-toml` from 1.8.0 to 1.9.0
- [Release notes](https://github.com/squirrelchat/smol-toml/releases)
- [Commits](squirrelchat/smol-toml@v1.8.0...v1.9.0)

Updates `@semantic-release/git` from 10.0.1 to 11.0.1
- [Release notes](https://github.com/semantic-release/git/releases)
- [Commits](semantic-release/git@v10.0.1...v11.0.1)

Updates `@semantic-release/github` from 12.0.9 to 12.0.10
- [Release notes](https://github.com/semantic-release/github/releases)
- [Commits](semantic-release/github@v12.0.9...v12.0.10)

Updates `@semantic-release/npm` from 13.1.5 to 13.2.0
- [Release notes](https://github.com/semantic-release/npm/releases)
- [Commits](semantic-release/npm@v13.1.5...v13.2.0)

Updates `@types/node` from 26.1.0 to 26.6.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `semantic-release` from 25.0.5 to 25.0.9
- [Release notes](https://github.com/semantic-release/semantic-release/releases)
- [Commits](semantic-release/semantic-release@v25.0.5...v25.0.9)

Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v6.0.3...v7.0.2)

Updates `ws` from 8.21.3 to 8.22.0
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.21.3...8.22.0)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.30.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@semantic-release/git"
  dependency-version: 11.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm
- dependency-name: "@semantic-release/github"
  dependency-version: 12.0.10
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@semantic-release/npm"
  dependency-version: 13.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@types/node"
  dependency-version: 26.6.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: semantic-release
  dependency-version: 25.0.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: smol-toml
  dependency-version: 1.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm
- dependency-name: ws
  dependency-version: 8.22.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-e95aefc2d8 branch from 9fbff4d to 48bba3f Compare October 4, 2026 21:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants