Repository navigation
Commit ceaf2a1
fix: Bump @modelcontextprotocol/sdk to ^1.26.0 and agents to ^0.3.10 (#785)
Bumps two SDK dependencies:
- `@modelcontextprotocol/sdk` from `^1.25.3` to `^1.26.0` — picks up the
fix for [CVE
GHSA-345p-7cg4-v4c7](GHSA-345p-7cg4-v4c7)
(cross-client response data leakage when sharing server/transport
instances) and the SDK's new runtime guard that throws if a server is
connected twice. This project is already architecturally safe
(`buildServer()` creates a fresh `McpServer` per request in the
Cloudflare handler), but bumping the dep hardens things further.
- `agents` from `^0.3.6` to `^0.3.10`
Note: pnpm warns about unsatisfied `@cloudflare/ai-chat` and
`@cloudflare/codemode` peer deps from `agents@0.3.10`. These should be
optional but aren't marked as such — a packaging issue upstream. We
don't use either package and the warnings are harmless.
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>1 parent 9f4d012 commit ceaf2a1
3 files changed
Lines changed: 102 additions & 72 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
74 | 74 | | |
75 | 75 | | |
76 | 76 | | |
77 | | - | |
| 77 | + | |
78 | 78 | | |
79 | 79 | | |
80 | 80 | | |
| |||
0 commit comments