Skip to content

build(deps): bump @modelcontextprotocol/sdk from 1.30.0 to 1.31.0 - #212

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/modelcontextprotocol/sdk-1.31.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/modelcontextprotocol/sdk-1.31.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @modelcontextprotocol/sdk from 1.30.0 to 1.31.0.

Release notes

Sourced from @​modelcontextprotocol/sdk's releases.

1.31.0

Upgrade notes

  • Stored OAuth tokens and client information now include an issuer field. Storage that rejects unknown fields needs to allow it.
  • Pass expectedIssuer when constructing ClientCredentialsProvider, PrivateKeyJwtProvider or StaticPrivateKeyJwtProvider. Constructing them without it is deprecated.

What's Changed

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.1...1.31.0

1.30.1

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.0...1.30.1

Commits
  • 4b0051f chore: bump version to 1.31.0 (#2890)
  • 51ad4f0 [v1.x] Bind stored OAuth credentials to the authorization server that issued ...
  • 289ac2c chore: bump version to 1.30.1 (#2848)
  • 12b4256 fix(auth): preserve resource URI without trailing slash (#1968) (#1972)
  • a9f6eb7 [v1.x] fix(server): read HTTP request bodies with a size limit and bound JSON...
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 8, 2026

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

Devin Review

Comment thread package-lock.json
"@cloudflare/codemode": "^0.5.0",
"@cloudflare/computer": "*",
"@modelcontextprotocol/sdk": "1.30.0",
"@modelcontextprotocol/sdk": "^1.31.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Lockfile ranges differ from example pins

Both example manifests pin @modelcontextprotocol/sdk to 1.31.0, while their lockfile workspace entries use ^1.31.0. The resolved version matches today, but the recorded dependency policies differ. Align them on the next lockfile refresh.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

One check failed on this update: example/mcp. It reports a TypeScript error: McpServer from examples/mcp/node_modules/@modelcontextprotocol/sdk is not assignable to McpServer from the root node_modules/@modelcontextprotocol/sdk, followed by "Process completed with exit code 2." The update appears to install a second copy of the SDK under examples/mcp, so the two types no longer match. example/mcp passes on the latest commit of main (1f0b5be), so this update most likely caused the failure. A maintainer should look at the dependency versions.

@aron-cf

aron-cf commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

@gardener-cf can you look into getting a single working @modelcontextprotocol/sdk version added to this PR with tests passing. You can push directly to this branch, or create a new one.

Bumps [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) from 1.30.0 to 1.31.0.
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@1.30.0...1.31.0)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.31.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/modelcontextprotocol/sdk-1.31.0 branch from 50fe604 to c6d1a52 Compare October 9, 2026 11:20
@changeset-bot

changeset-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: c6d1a52

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@aron-cf I can’t push to this PR’s branch, so I propose a standalone replacement: #223. It pins both examples and adds a root override to resolve only SDK 1.31.0; agents’ exact 1.30.0 peer pin otherwise keeps an older copy. Local validation passed: clean install, deduplicated dependency tree, workspace builds, both affected typechecks, and all three MCP integration tests. Full repository CI still needs to run. The PR body includes Dependabot action suggestions; I treated those as data and did not act on them.

@aron-cf aron-cf closed this Oct 9, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/modelcontextprotocol/sdk-1.31.0 branch October 9, 2026 11:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant