Skip to content

Bump the npm group across 3 directories with 5 updates - #289

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-aec81a0c00
Sep 30, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-aec81a0c00

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm group with 5 updates in the / directory:

Package From To
@modelcontextprotocol/core 2.0.0 2.1.0
@modelcontextprotocol/hono 2.0.0 2.0.1
@modelcontextprotocol/server 2.0.0 2.1.0
aws-cdk 2.1142.0 2.1143.0
@aws-cdk/cloud-assembly-schema 54.24.0 54.25.0

Bumps the npm group with 5 updates in the /example directory:

Package From To
@modelcontextprotocol/core 2.0.0 2.1.0
@modelcontextprotocol/hono 2.0.0 2.0.1
@modelcontextprotocol/server 2.0.0 2.1.0
aws-cdk 2.1142.0 2.1143.0
@aws-cdk/cloud-assembly-schema 54.24.0 54.25.0

Bumps the npm group with 5 updates in the /package directory:

Package From To
@modelcontextprotocol/core 2.0.0 2.1.0
@modelcontextprotocol/hono 2.0.0 2.0.1
@modelcontextprotocol/server 2.0.0 2.1.0
aws-cdk 2.1142.0 2.1143.0
@aws-cdk/cloud-assembly-schema 54.24.0 54.25.0

Updates @modelcontextprotocol/core from 2.0.0 to 2.1.0

Release notes

Sourced from @​modelcontextprotocol/core's releases.

@​modelcontextprotocol/core@​2.1.0

Minor Changes

  • #2629 dcc0102 Thanks @​gbshankar! - Add DPoP (RFC 9449 / SEP-1932) sender-constrained access token support to the client.
    • Opt in by implementing OAuthClientProvider.dpop() returning a DpopSession (new, along with generateDpopKeyPair, accessTokenHash, isDpopNonceChallenge). auth() / exchangeAuthorization / refreshAuthorization / fetchToken then sign a DPoP proof into token requests (retrying once on an authorization-server use_dpop_nonce challenge, with client authentication re-applied per attempt), and StreamableHTTPClientTransport, SSEClientTransport and withOAuth present a token_type: "DPoP" access token as Authorization: DPoP <token> plus a fresh per-request proof, retry a resource-server use_dpop_nonce challenge once, and pick up a DPoP-Nonce delivered on any response. Tokens the AS issued as Bearer are still presented as Bearer.
    • DPoP is applied at the fetch layer: the transports wrap their resource-server fetch (including a caller-supplied fetch / eventSourceInit.fetch) with the new withDpopFromProvider(provider) middleware, so proofs are always bound to the request actually sent. withDpop(session, getToken) is exported for callers that manage tokens themselves (e.g. alongside a minimal AuthProvider); the AuthProvider interface itself is unchanged.
    • auth() now recovers from invalid_dpop_proof on refresh (e.g. a refresh token bound to a key that is no longer held) by discarding the tokens and re-authorizing, like invalid_grant. OAuthErrorCode gains InvalidDpopProof and UseDpopNonce; extractWWWAuthenticateParams recognizes the DPoP challenge scheme; OAuthMetadataSchema gains dpop_signing_alg_values_supported.
Commits
  • 9517506 Version Packages (#2808)
  • 6a05402 fix(server): close StdioServerTransport when stdin ends or closes (#2494)
  • c4248a9 fix(client): add missing Windows env vars to DEFAULT_INHERITED_ENV_VARS (#2043)
  • 0b403f0 chore(changesets): only bump peer dependents when out of range (#2819)
  • 6032170 feat(server): add request-time OAuth scope challenges (#1624)
  • b654261 fix(client): let OAuth-derived Authorization override caller-supplied header ...
  • 5ecc791 fix(codemod): only count real module specifiers in project-type inference (#2...
  • 5119ee7 fix: preserve exact OAuth resource indicators (#2581)
  • 6fa4227 fix(client): surface underlying network error via Error.cause on probe failur...
  • dcc0102 feat(client): add DPoP (RFC 9449) sender-constrained token support (#2629)
  • Additional commits viewable in compare view

Updates @modelcontextprotocol/hono from 2.0.0 to 2.0.1

Release notes

Sourced from @​modelcontextprotocol/hono's releases.

@​modelcontextprotocol/hono@​2.0.1

Patch Changes

  • #2698 7b781ed Thanks @​maxisbey! - Read Streamable HTTP request bodies with a size limit. Every SDK-owned body read — WebStandardStreamableHTTPServerTransport (and the Node transport built on it), createMcpHandler, toNodeHandler, and createMcpHonoApp's JSON pre-parse — now stops at 4 MiB by default (the limit the legacy SSE transport already uses; the Express adapter and stdio bound their reads too) and answers 413 Payload Too Large before anything is parsed. toWebRequest (when it reads the Node stream itself) now rejects once the body exceeds the limit with an error whose name is 'RequestBodyTooLargeError' and status is 413, and toNodeHandler answers that with 413; hand-wired callers of toWebRequest should handle the rejection or pass a pre-parsed body, and isLegacyRequest reports such a request as non-legacy so the modern handler answers it. JSON-RPC batch arrays are limited to 100 messages; a longer batch is answered 400 / -32600 and none of it is dispatched.

    The limit is configurable with a new maxRequestBodySize option (bytes, default DEFAULT_MAX_REQUEST_BODY_SIZE = 4 MiB, exported from @modelcontextprotocol/server) on WebStandardStreamableHTTPServerTransportOptions, CreateMcpHandlerOptions (forwarded to its stateless legacy leg; isLegacyRequest and legacyStatelessFallback take the same option), CreateMcpHonoAppOptions, and ToNodeHandlerOptions / ToWebRequestOptions (the adapter's bound applies before the handler's, so raise both). The bounded reader is exported as readRequestBody for adapter authors. Hosts that pre-parse the body and pass it as parsedBody skip the SDK's read and its size limit entirely; the batch bound applies either way.

    createMcpHonoApp and createMcpExpressApp now run their Host/Origin validation before the JSON body parser, so a request from a disallowed Host or Origin with an invalid JSON body is answered 403 rather than 400, and its body is not read.

  • Updated dependencies [6fa4227, 03842cd, 3e90449, 7b781ed, 75dc7ea, 6032170, 6a05402, 70de0c8]:

    • @​modelcontextprotocol/server@​2.1.0
Commits
  • 9517506 Version Packages (#2808)
  • 6a05402 fix(server): close StdioServerTransport when stdin ends or closes (#2494)
  • c4248a9 fix(client): add missing Windows env vars to DEFAULT_INHERITED_ENV_VARS (#2043)
  • 0b403f0 chore(changesets): only bump peer dependents when out of range (#2819)
  • 6032170 feat(server): add request-time OAuth scope challenges (#1624)
  • b654261 fix(client): let OAuth-derived Authorization override caller-supplied header ...
  • 5ecc791 fix(codemod): only count real module specifiers in project-type inference (#2...
  • 5119ee7 fix: preserve exact OAuth resource indicators (#2581)
  • 6fa4227 fix(client): surface underlying network error via Error.cause on probe failur...
  • dcc0102 feat(client): add DPoP (RFC 9449) sender-constrained token support (#2629)
  • Additional commits viewable in compare view

Updates @modelcontextprotocol/server from 2.0.0 to 2.1.0

Release notes

Sourced from @​modelcontextprotocol/server's releases.

@​modelcontextprotocol/server-legacy@​2.1.0

Patch Changes

  • Updated dependencies [dcc0102]:
    • @​modelcontextprotocol/core@​2.1.0

@​modelcontextprotocol/server@​2.1.0

Minor Changes

  • #1624 6032170 Thanks @​SamMorrowDrums! - Add request-time OAuth scope challenges for tools, resources, resource templates, and prompts. Each primitive's scopeChallenge callback receives the parsed request and verified authentication info, then either continues or returns the exact scope set for an insufficient_scope response. requireScopes provides a small helper for static all-of checks.

    createMcpHandler and Streamable HTTP transports return HTTP 403 with an insufficient_scope challenge before handler execution or SSE setup. The preflight is active whenever a registered primitive carries a scopeChallenge callback — there is no handler- or transport-level configuration. The challenge's WWW-Authenticate header is built by the same formatter as the bearer-auth 401/403 answers, and its resource_metadata parameter is derived from the verified AuthInfo: requireBearerAuth / verifyBearerToken now stamp their configured resourceMetadataUrl onto the AuthInfo they return (new optional AuthInfo.resourceMetadataUrl field), with a fallback to the well-known location for an HTTP(S) RFC 8707 resource identifier; the parameter is omitted when neither is available.

Patch Changes

  • #2726 6fa4227 Thanks @​LuckTerence! - SdkError and SdkHttpError accept standard ErrorOptions as an optional fourth constructor argument and forward it to Error, so a wrapped error is reachable through the standard Error.cause chain. Version-negotiation probe failures (SdkErrorCode.EraNegotiationFailed) now use it: the underlying TypeError: fetch failed and the DNS or socket error beneath it surface via error.cause, so pino, Sentry, and util.inspect render ENOTFOUND / ECONNREFUSED / ETIMEDOUT instead of stopping at the SdkError (#2657). The previous error.data.cause slot is still populated for compatibility but is deprecated and slated for removal; read error.cause instead.

  • #2654 03842cd Thanks @​pshah19! - Treat request id 0 as a real id. Two guards tested a RequestId for truthiness, so the legal JSON-RPC ids 0 and '' were read as absent. Id 0 is not a corner case: the outbound request counter is zero-based, so it is the first id every peer assigns, which on the server→client leg is the first sampling/createMessage, elicitation/create, or roots/list a server sends.

    • notifications/cancelled carrying id 0 was ignored, and the in-flight handler ran to completion with its AbortSignal never fired.
    • A notification sent with relatedRequestId: 0 wrongly passed the debounce gate (for methods opted into debouncedNotificationMethods). Because the pending set is keyed by method alone, a second such notification in the same tick was silently dropped rather than sent.

    Absent is now the only value that means "no id".

  • #2668 3e90449 Thanks @​KKonstantinov! - Stop sending notifications/cancelled for the initialize handshake. The spec is explicit that a client MUST NOT attempt to cancel its initialize request, but the outbound cancel path fired for any in-flight request: aborting the AbortSignal passed to connect(), or letting the handshake hit its timeout, put a forbidden cancellation on the wire naming the initialize request id.

    The local behaviour is unchanged — the caller's promise still rejects with the same abort/timeout error, and connect() still tears the connection down. Only the wire notification is suppressed. Every other method keeps the existing cancellation path.

  • #2698 7b781ed Thanks @​maxisbey! - Read Streamable HTTP request bodies with a size limit. Every SDK-owned body read — WebStandardStreamableHTTPServerTransport (and the Node transport built on it), createMcpHandler, toNodeHandler, and createMcpHonoApp's JSON pre-parse — now stops at 4 MiB by default (the limit the legacy SSE transport already uses; the Express adapter and stdio bound their reads too) and answers 413 Payload Too Large before anything is parsed. toWebRequest (when it reads the Node stream itself) now rejects once the body exceeds the limit with an error whose name is 'RequestBodyTooLargeError' and status is 413, and toNodeHandler answers that with 413; hand-wired callers of toWebRequest should handle the rejection or pass a pre-parsed body, and isLegacyRequest reports such a request as non-legacy

... (truncated)

Commits
  • 9517506 Version Packages (#2808)
  • 6a05402 fix(server): close StdioServerTransport when stdin ends or closes (#2494)
  • c4248a9 fix(client): add missing Windows env vars to DEFAULT_INHERITED_ENV_VARS (#2043)
  • 0b403f0 chore(changesets): only bump peer dependents when out of range (#2819)
  • 6032170 feat(server): add request-time OAuth scope challenges (#1624)
  • b654261 fix(client): let OAuth-derived Authorization override caller-supplied header ...
  • 5ecc791 fix(codemod): only count real module specifiers in project-type inference (#2...
  • 5119ee7 fix: preserve exact OAuth resource indicators (#2581)
  • 6fa4227 fix(client): surface underlying network error via Error.cause on probe failur...
  • dcc0102 feat(client): add DPoP (RFC 9449) sender-constrained token support (#2629)
  • Additional commits viewable in compare view

Updates aws-cdk from 2.1142.0 to 2.1143.0

Release notes

Sourced from aws-cdk's releases.

aws-cdk@v2.1143.0

2.1143.0 (2026-09-23)

Features

  • cli: --debug-cli reports active handles that block process exit (#1651) (670fd75), references #1217
  • cli: support --change-set-name for cdk diff (#1982) (25b5038)
  • deps: upgrade aws-cdk-lib (#1979) (8904fc5)
  • unique change set names for diff, bootstrap and orphan (#1985) (29c9fe8), references #1982
Commits
  • eb102f8 docs(cli): document cloud assembly as a trust boundary (#1983)
  • ca64124 test(aws-cdk): mock agent detection instead of clearing its env vars (#1966)
  • 29c9fe8 feat: unique change set names for diff, bootstrap and orphan (#1985)
  • 25b5038 feat(cli): support --change-set-name for cdk diff (#1982)
  • 670fd75 feat(cli): --debug-cli reports active handles that block process exit (#1651)
  • 8904fc5 feat(deps): upgrade aws-cdk-lib (#1979)
  • a719384 chore(deps): upgrade dependencies (#1977)
  • 19baa75 chore(integ-testing): tests leak buckets under Atmosphere (#1956)
  • See full diff in compare view

Updates @aws-cdk/cloud-assembly-schema from 54.24.0 to 54.25.0

Release notes

Sourced from @​aws-cdk/cloud-assembly-schema's releases.

@​aws-cdk/cloud-assembly-schema@​v54.25.0

54.25.0 (2026-09-23)

Commits

Updates @modelcontextprotocol/core from 2.0.0 to 2.1.0

Release notes

Sourced from @​modelcontextprotocol/core's releases.

@​modelcontextprotocol/core@​2.1.0

Minor Changes

  • #2629 dcc0102 Thanks @​gbshankar! - Add DPoP (RFC 9449 / SEP-1932) sender-constrained access token support to the client.
    • Opt in by implementing OAuthClientProvider.dpop() returning a DpopSession (new, along with generateDpopKeyPair, accessTokenHash, isDpopNonceChallenge). auth() / exchangeAuthorization / refreshAuthorization / fetchToken then sign a DPoP proof into token requests (retrying once on an authorization-server use_dpop_nonce challenge, with client authentication re-applied per attempt), and StreamableHTTPClientTransport, SSEClientTransport and withOAuth present a token_type: "DPoP" access token as Authorization: DPoP <token> plus a fresh per-request proof, retry a resource-server use_dpop_nonce challenge once, and pick up a DPoP-Nonce delivered on any response. Tokens the AS issued as Bearer are still presented as Bearer.
    • DPoP is applied at the fetch layer: the transports wrap their resource-server fetch (including a caller-supplied fetch / eventSourceInit.fetch) with the new withDpopFromProvider(provider) middleware, so proofs are always bound to the request actually sent. withDpop(session, getToken) is exported for callers that manage tokens themselves (e.g. alongside a minimal AuthProvider); the AuthProvider interface itself is unchanged.
    • auth() now recovers from invalid_dpop_proof on refresh (e.g. a refresh token bound to a key that is no longer held) by discarding the tokens and re-authorizing, like invalid_grant. OAuthErrorCode gains InvalidDpopProof and UseDpopNonce; extractWWWAuthenticateParams recognizes the DPoP challenge scheme; OAuthMetadataSchema gains dpop_signing_alg_values_supported.
Commits
  • 9517506 Version Packages (#2808)
  • 6a05402 fix(server): close StdioServerTransport when stdin ends or closes (#2494)
  • c4248a9 fix(client): add missing Windows env vars to DEFAULT_INHERITED_ENV_VARS (#2043)
  • 0b403f0 chore(changesets): only bump peer dependents when out of range (#2819)
  • 6032170 feat(server): add request-time OAuth scope challenges (#1624)
  • b654261 fix(client): let OAuth-derived Authorization override caller-supplied header ...
  • 5ecc791 fix(codemod): only count real module specifiers in project-type inference (#2...
  • 5119ee7 fix: preserve exact OAuth resource indicators (#2581)
  • 6fa4227 fix(client): surface underlying network error via Error.cause on probe failur...
  • dcc0102 feat(client): add DPoP (RFC 9449) sender-constrained token support (#2629)
  • Additional commits viewable in compare view

Updates @modelcontextprotocol/hono from 2.0.0 to 2.0.1

Release notes

Sourced from @​modelcontextprotocol/hono's releases.

@​modelcontextprotocol/hono@​2.0.1

Patch Changes

  • #2698 7b781ed Thanks @​maxisbey! - Read Streamable HTTP request bodies with a size limit. Every SDK-owned body read — WebStandardStreamableHTTPServerTransport (and the Node transport built on it), createMcpHandler, toNodeHandler, and createMcpHonoApp's JSON pre-parse — now stops at 4 MiB by default (the limit the legacy SSE transport already uses; the Express adapter and stdio bound their reads too) and answers 413 Payload Too Large before anything is parsed. toWebRequest (when it reads the Node stream itself) now rejects once the body exceeds the limit with an error whose name is 'RequestBodyTooLargeError' and status is 413, and toNodeHandler answers that with 413; hand-wired callers of toWebRequest should handle the rejection or pass a pre-parsed body, and isLegacyRequest reports such a request as non-legacy so the modern handler answers it. JSON-RPC batch arrays are limited to 100 messages; a longer batch is answered 400 / -32600 and none of it is dispatched.

    The limit is configurable with a new maxRequestBodySize option (bytes, default DEFAULT_MAX_REQUEST_BODY_SIZE = 4 MiB, exported from @modelcontextprotocol/server) on WebStandardStreamableHTTPServerTransportOptions, CreateMcpHandlerOptions (forwarded to its stateless legacy leg; isLegacyRequest and legacyStatelessFallback take the same option), CreateMcpHonoAppOptions, and ToNodeHandlerOptions / ToWebRequestOptions (the adapter's bound applies before the handler's, so raise both). The bounded reader is exported as readRequestBody for adapter authors. Hosts that pre-parse the body and pass it as parsedBody skip the SDK's read and its size limit entirely; the batch bound applies either way.

    createMcpHonoApp and createMcpExpressApp now run their Host/Origin validation before the JSON body parser, so a request from a disallowed Host or Origin with an invalid JSON body is answered 403 rather than 400, and its body is not read.

  • Updated dependencies [6fa4227, 03842cd, 3e90449, 7b781ed, 75dc7ea, 6032170, 6a05402, 70de0c8]:

    • @​modelcontextprotocol/server@​2.1.0
Commits
  • 9517506 Version Packages (#2808)
  • 6a05402 fix(server): close StdioServerTransport when stdin ends or closes (#2494)
  • c4248a9 fix(client): add missing Windows env vars to DEFAULT_INHERITED_ENV_VARS (#2043)
  • 0b403f0 chore(changesets): only bump peer dependents when out of range (#2819)
  • 6032170 feat(server): add request-time OAuth scope challenges (#1624)
  • b654261 fix(client): let OAuth-derived Authorization override caller-supplied header ...
  • 5ecc791 fix(codemod): only count real module specifiers in project-type inference (#2...
  • 5119ee7 fix: preserve exact OAuth resource indicators (#2581)
  • 6fa4227 fix(client): surface underlying network error via Error.cause on probe failur...
  • dcc0102 feat(client): add DPoP (RFC 9449) sender-constrained token support (#2629)
  • Additional commits viewable in compare view

Updates @modelcontextprotocol/server from 2.0.0 to 2.1.0

Release notes

Sourced from @​modelcontextprotocol/server's releases.

@​modelcontextprotocol/server-legacy@​2.1.0

Patch Changes

  • Updated dependencies [dcc0102]:
    • @​modelcontextprotocol/core@​2.1.0

@​modelcontextprotocol/server@​2.1.0

Minor Changes

  • #1624 6032170 Thanks @​SamMorrowDrums! - Add request-time OAuth scope challenges for tools, resources, resource templates, and prompts. Each primitive's scopeChallenge callback receives the parsed request and verified authentication info, then either continues or returns the exact scope set for an insufficient_scope response. requireScopes provides a small helper for static all-of checks.

    createMcpHandler and Streamable HTTP transports return HTTP 403 with an insufficient_scope challenge before handler execution or SSE setup. The preflight is active whenever a registered primitive carries a scopeChallenge callback — there is no handler- or transport-level configuration. The challenge's WWW-Authenticate header is built by the same formatter as the bearer-auth 401/403 answers, and its resource_metadata parameter is derived from the verified AuthInfo: requireBearerAuth / verifyBearerToken now stamp their configured resourceMetadataUrl onto the AuthInfo they return (new optional AuthInfo.resourceMetadataUrl field), with a fallback to the well-known location for an HTTP(S) RFC 8707 resource identifier; the parameter is omitted when neither is available.

Patch Changes

  • #2726 6fa4227 Thanks @​LuckTerence! - SdkError and SdkHttpError accept standard ErrorOptions as an optional fourth constructor argument and forward it to Error, so a wrapped error is reachable through the standard Error.cause chain. Version-negotiation probe failures (SdkErrorCode.EraNegotiationFailed) now use it: the underlying TypeError: fetch failed and the DNS or socket error beneath it surface via error.cause, so pino, Sentry, and util.inspect render ENOTFOUND / ECONNREFUSED / ETIMEDOUT instead of stopping at the SdkError (#2657). The previous error.data.cause slot is still populated for compatibility but is deprecated and slated for removal; read error.cause instead.

  • #2654 03842cd Thanks @​pshah19! - Treat request id 0 as a real id. Two guards tested a RequestId for truthiness, so the legal JSON-RPC ids 0 and '' were read as absent. Id 0 is not a corner case: the outbound request counter is zero-based, so it is the first id every peer assigns, which on the server→client leg is the first sampling/createMessage, elicitation/create, or roots/list a server sends.

    • notifications/cancelled carrying id 0 was ignored, and the in-flight handler ran to completion with its AbortSignal never fired.
    • A notification sent with relatedRequestId: 0 wrongly passed the debounce gate (for methods opted into debouncedNotificationMethods). Because the pending set is keyed by method alone, a second such notification in the same tick was silently dropped rather than sent.

    Absent is now the only value that means "no id".

  • #2668 3e90449 Thanks @​KKonstantinov! - Stop sending notifications/cancelled for the initialize handshake. The spec is explicit that a client MUST NOT attempt to cancel its initialize request, but the outbound cancel path fired for any in-flight request: aborting the AbortSignal passed to connect(), or letting the handshake hit its timeout, put a forbidden cancellation on the wire naming the initialize request id.

    The local behaviour is unchanged — the caller's promise still rejects with the same abort/timeout error, and connect() still tears the connection down. Only the wire notification is suppressed. Every other method keeps the existing cancellation path.

  • #2698 7b781ed Thanks @​maxisbey! - Read Streamable HTTP request bodies with a size limit. Every SDK-owned body read — WebStandardStreamableHTTPServerTransport (and the Node transport built on it), createMcpHandler, toNodeHandler, and createMcpHonoApp's JSON pre-parse — now stops at 4 MiB by default (the limit the legacy SSE transport already uses; the Express adapter and stdio bound their reads too) and answers 413 Payload Too Large before anything is parsed. toWebRequest (when it reads the Node stream itself) now rejects once the body exceeds the limit with an error whose name is 'RequestBodyTooLargeError' and status is 413, and toNodeHandler answers that with 413; hand-wired callers of toWebRequest should handle the rejection or pass a pre-parsed body, and isLegacyRequest reports such a request as non-legacy

... (truncated)

Commits
  • 9517506 Version Packages (#2808)
  • 6a05402 fix(server): close StdioServerTransport when stdin ends or closes (#2494)
  • c4248a9 fix(client): add missing Windows env vars to DEFAULT_INHERITED_ENV_VARS (#2043)
  • 0b403f0 chore(changesets): only bump peer dependents when out of range (#2819)
  • 6032170 feat(server): add request-time OAuth scope challenges (#1624)
  • b654261 fix(client): let OAuth-derived Authorization override caller-supplied header ...
  • 5ecc791 fix(codemod): only count real module specifiers in project-type inference (#2...
  • 5119ee7 fix: preserve exact OAuth resource indicators (#2581)
  • 6fa4227 fix(client): surface underlying network error via Error.cause on probe failur...
  • dcc0102 feat(client): add DPoP (RFC 9449) sender-constrained token support (#2629)
  • Additional commits viewable in compare view

Updates aws-cdk from 2.1142.0 to 2.1143.0

Release notes

Sourced from aws-cdk's releases.

aws-cdk@v2.1143.0

2.1143.0 (2026-09-23)

Features

  • cli: --debug-cli reports active handles that block process exit (#1651) (670fd75), references #1217
  • cli: support --change-set-name for cdk diff (#1982) (25b5038)
  • deps: upgrade aws-cdk-lib (#1979) (8904fc5)
  • unique change set names for diff, bootstrap and orphan (#1985) (29c9fe8), references #1982
Commits
  • eb102f8 docs(cli): document cloud assembly as a trust boundary (#1983)
  • ca64124 test(aws-cdk): mock agent detection instead of clearing its env vars (#1966)
  • 29c9fe8 feat: unique change set names for diff, bootstrap and orphan (#1985)
  • 25b5038 feat(cli): support --change-set-name for cdk diff (#1982)
  • 670fd75 feat(cli): --debug-cli reports active handles that block process exit (#1651)
  • 8904fc5 feat(deps): upgrade aws-cdk-lib (#1979)
  • a719384 chore(deps): upgrade dependencies (#1977)
  • 19baa75 chore(integ-testing): tests leak buckets under Atmosphere (#1956)
  • See full diff in compare view

Updates @aws-cdk/cloud-assembly-schema from 54.24.0 to 54.25.0

Release notes

Sourced from @​aws-cdk/cloud-assembly-schema's releases.

@​aws-cdk/cloud-assembly-schema@​v54.25.0

54.25.0 (2026-09-23)

Commits

Updates @modelcontextprotocol/core from 2.0.0 to 2.1.0

Release notes

Sourced from @​modelcontextprotocol/core's releases.

@​modelcontextprotocol/core@​2.1.0

Minor Changes

  • #2629 dcc0102 Thanks @​gbshankar! - Add DPoP (RFC 9449 / SEP-1932) sender-constrained access token support to the client.
    • Opt in by implementing OAuthClientProvider.dpop() returning a DpopSession (new, along with generateDpopKeyPair, accessTokenHash, isDpopNonceChallenge). auth() / exchangeAuthorization / refreshAuthorization / fetchToken then sign a DPoP proof into token requests (retrying once on an authorization-server use_dpop_nonce challenge, with client authentication re-applied per attempt), and StreamableHTTPClientTransport, SSEClientTransport and withOAuth present a token_type: "DPoP" access token as Authorization: DPoP <token> plus a fresh per-request proof, retry a resource-server use_dpop_nonce challenge once, and pick up a DPoP-Nonce delivered on any response. Tokens the AS issued as Bearer are still presented as Bearer.
    • DPoP is applied at the fetch layer: the transports wrap their resource-server fetch (including a caller-supplied fetch / eventSourceInit.fetch) with the new withDpopFromProvider(provider) middleware, so proofs are always bound to the request actually sent. withDpop(session, getToken) is exported for callers that manage tokens themselves (e.g. alongside a minimal AuthProvider); the AuthProvider interface itself is unchanged.
    • auth() now recovers from invalid_dpop_proof on refresh (e.g. a refresh token bound to a key that is no longer held) by discarding the tokens and re-authorizing, like invalid_grant. OAuthErrorCode gains InvalidDpopProof and UseDpopNonce; extractWWWAuthenticateParams recognizes the DPoP challenge scheme; OAuthMetadataSchema gains dpop_signing_alg_values_supported.
Commits
  • 9517506 Version Packages (#2808)
  • 6a05402 fix(server): close StdioServerTransport when stdin ends or closes (#2494)
  • c4248a9 fix(client): add missing Windows env vars to DEFAULT_INHERITED_ENV_VARS (#2043)
  • 0b403f0 chore(changesets): only bump peer dependents when out of range (#2819)
  • 6032170 feat(server): add request-time OAuth scope challenges (#1624)
  • b654261 fix(client): let OAuth-derived Authorization override caller-supplied header ...
  • 5ecc791 fix(codemod): only count real module specifiers in project-type inference (

Bumps the npm group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@modelcontextprotocol/core](https://github.com/modelcontextprotocol/typescript-sdk) | `2.0.0` | `2.1.0` |
| [@modelcontextprotocol/hono](https://github.com/modelcontextprotocol/typescript-sdk) | `2.0.0` | `2.0.1` |
| [@modelcontextprotocol/server](https://github.com/modelcontextprotocol/typescript-sdk) | `2.0.0` | `2.1.0` |
| [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) | `2.1142.0` | `2.1143.0` |
| [@aws-cdk/cloud-assembly-schema](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/@aws-cdk/cloud-assembly-schema) | `54.24.0` | `54.25.0` |

Bumps the npm group with 5 updates in the /example directory:

| Package | From | To |
| --- | --- | --- |
| [@modelcontextprotocol/core](https://github.com/modelcontextprotocol/typescript-sdk) | `2.0.0` | `2.1.0` |
| [@modelcontextprotocol/hono](https://github.com/modelcontextprotocol/typescript-sdk) | `2.0.0` | `2.0.1` |
| [@modelcontextprotocol/server](https://github.com/modelcontextprotocol/typescript-sdk) | `2.0.0` | `2.1.0` |
| [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) | `2.1142.0` | `2.1143.0` |
| [@aws-cdk/cloud-assembly-schema](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/@aws-cdk/cloud-assembly-schema) | `54.24.0` | `54.25.0` |

Bumps the npm group with 5 updates in the /package directory:

| Package | From | To |
| --- | --- | --- |
| [@modelcontextprotocol/core](https://github.com/modelcontextprotocol/typescript-sdk) | `2.0.0` | `2.1.0` |
| [@modelcontextprotocol/hono](https://github.com/modelcontextprotocol/typescript-sdk) | `2.0.0` | `2.0.1` |
| [@modelcontextprotocol/server](https://github.com/modelcontextprotocol/typescript-sdk) | `2.0.0` | `2.1.0` |
| [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) | `2.1142.0` | `2.1143.0` |
| [@aws-cdk/cloud-assembly-schema](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/@aws-cdk/cloud-assembly-schema) | `54.24.0` | `54.25.0` |



Updates `@modelcontextprotocol/core` from 2.0.0 to 2.1.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/core@2.0.0...@modelcontextprotocol/core@2.1.0)

Updates `@modelcontextprotocol/hono` from 2.0.0 to 2.0.1
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/hono@2.0.0...@modelcontextprotocol/hono@2.0.1)

Updates `@modelcontextprotocol/server` from 2.0.0 to 2.1.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/server@2.0.0...@modelcontextprotocol/server@2.1.0)

Updates `aws-cdk` from 2.1142.0 to 2.1143.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1143.0/packages/aws-cdk)

Updates `@aws-cdk/cloud-assembly-schema` from 54.24.0 to 54.25.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/@aws-cdk/cloud-assembly-schema@v54.25.0/packages/@aws-cdk/cloud-assembly-schema)

Updates `@modelcontextprotocol/core` from 2.0.0 to 2.1.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/core@2.0.0...@modelcontextprotocol/core@2.1.0)

Updates `@modelcontextprotocol/hono` from 2.0.0 to 2.0.1
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/hono@2.0.0...@modelcontextprotocol/hono@2.0.1)

Updates `@modelcontextprotocol/server` from 2.0.0 to 2.1.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/server@2.0.0...@modelcontextprotocol/server@2.1.0)

Updates `aws-cdk` from 2.1142.0 to 2.1143.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1143.0/packages/aws-cdk)

Updates `@aws-cdk/cloud-assembly-schema` from 54.24.0 to 54.25.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/@aws-cdk/cloud-assembly-schema@v54.25.0/packages/@aws-cdk/cloud-assembly-schema)

Updates `@modelcontextprotocol/core` from 2.0.0 to 2.1.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/core@2.0.0...@modelcontextprotocol/core@2.1.0)

Updates `@modelcontextprotocol/hono` from 2.0.0 to 2.0.1
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/hono@2.0.0...@modelcontextprotocol/hono@2.0.1)

Updates `@modelcontextprotocol/server` from 2.0.0 to 2.1.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/server@2.0.0...@modelcontextprotocol/server@2.1.0)

Updates `aws-cdk` from 2.1142.0 to 2.1143.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1143.0/packages/aws-cdk)

Updates `@aws-cdk/cloud-assembly-schema` from 54.24.0 to 54.25.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/@aws-cdk/cloud-assembly-schema@v54.25.0/packages/@aws-cdk/cloud-assembly-schema)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/core"
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@modelcontextprotocol/hono"
  dependency-version: 2.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@modelcontextprotocol/server"
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: aws-cdk
  dependency-version: 2.1143.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@aws-cdk/cloud-assembly-schema"
  dependency-version: 54.25.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@modelcontextprotocol/core"
  dependency-version: 2.1.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@modelcontextprotocol/hono"
  dependency-version: 2.0.1
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@modelcontextprotocol/server"
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: aws-cdk
  dependency-version: 2.1143.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@aws-cdk/cloud-assembly-schema"
  dependency-version: 54.25.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@modelcontextprotocol/core"
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@modelcontextprotocol/hono"
  dependency-version: 2.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@modelcontextprotocol/server"
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: aws-cdk
  dependency-version: 2.1143.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@aws-cdk/cloud-assembly-schema"
  dependency-version: 54.25.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: npm
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 30, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) September 30, 2026 18:11
@github-actions

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/@modelcontextprotocol/server 2.1.0 UnknownUnknown
npm/aws-cdk 2.1143.0 UnknownUnknown
npm/@modelcontextprotocol/core 2.1.0 UnknownUnknown
npm/@modelcontextprotocol/hono 2.0.1 UnknownUnknown
npm/@modelcontextprotocol/server 2.1.0 UnknownUnknown

Scanned Files

  • example/package.json
  • package/package.json

@github-actions
github-actions Bot merged commit a08ba5b into main Sep 30, 2026
4 checks passed
@github-actions
github-actions Bot deleted the dependabot/npm_and_yarn/npm-aec81a0c00 branch September 30, 2026 18:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant