[Snyk] Security upgrade @modelcontextprotocol/sdk from 1.25.2 to 1.26.0#338
Conversation
…duce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-MODELCONTEXTPROTOCOLSDK-15208843
|
Important Review skippedIgnore keyword(s) in the title. ⛔ Ignored keywords (2)
Please check the settings in the CodeRabbit UI or the You can disable this status message by setting the
✨ Finishing touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
This PR updates the Arkiver app’s npm dependency graph to remediate a Snyk-reported vulnerability by upgrading @modelcontextprotocol/sdk.
Changes:
- Bump
@modelcontextprotocol/sdkfrom^1.25.2to^1.26.0in Arkiver. - Regenerate
apps/arkiver/package-lock.jsonto lock the new SDK version and updated transitive dependencies.
Reviewed changes
Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| apps/arkiver/package.json | Upgrades @modelcontextprotocol/sdk to ^1.26.0 to address the reported vulnerability. |
| apps/arkiver/package-lock.json | Updates the resolved SDK version and associated transitive dependency versions/integrity hashes. |
Files not reviewed (1)
- apps/arkiver/package-lock.json: Language not supported
|
@copilot open a new pull request to apply changes based on the comments in this thread |
|
@MightyPrytanis I've opened a new pull request, #346, to work on those changes. Once the pull request is ready, I'll request review from you. |
|
@copilot open a new pull request to apply changes based on the comments in this thread |
|
@MightyPrytanis I've opened a new pull request, #347, to work on those changes. Once the pull request is ready, I'll request review from you. |
|
@copilot open a new pull request to apply changes based on the comments in this thread |
|
@MightyPrytanis I've opened a new pull request, #348, to work on those changes. Once the pull request is ready, I'll request review from you. |
Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
apps/arkiver/package.jsonapps/arkiver/package-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-MODELCONTEXTPROTOCOLSDK-15208843
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Race Condition