Skip to content

Commit ceaf2a1

Browse files
dcramerclaude
andauthored
fix: Bump @modelcontextprotocol/sdk to ^1.26.0 and agents to ^0.3.10 (#785)
Bumps two SDK dependencies: - `@modelcontextprotocol/sdk` from `^1.25.3` to `^1.26.0` — picks up the fix for [CVE GHSA-345p-7cg4-v4c7](GHSA-345p-7cg4-v4c7) (cross-client response data leakage when sharing server/transport instances) and the SDK's new runtime guard that throws if a server is connected twice. This project is already architecturally safe (`buildServer()` creates a fresh `McpServer` per request in the Cloudflare handler), but bumping the dep hardens things further. - `agents` from `^0.3.6` to `^0.3.10` Note: pnpm warns about unsatisfied `@cloudflare/ai-chat` and `@cloudflare/codemode` peer deps from `agents@0.3.10`. These should be optional but aren't marked as such — a packaging issue upstream. We don't use either package and the warnings are harmless. --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
1 parent 9f4d012 commit ceaf2a1

3 files changed

Lines changed: 102 additions & 72 deletions

File tree

‎package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -74,7 +74,7 @@
7474
"workerd"
7575
],
7676
"overrides": {
77-
"@modelcontextprotocol/sdk": "^1.25.3"
77+
"@modelcontextprotocol/sdk": "^1.26.0"
7878
}
7979
},
8080
"devDependencies": {

0 commit comments

Comments
 (0)