Skip to content

deps-dev(deps-dev): bump the dev-dependencies group across 1 directory with 7 updates - #82

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dev-dependencies-8a73390f15
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dev-dependencies-8a73390f15

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the dev-dependencies group with 7 updates in the / directory:

Package From To
@modelcontextprotocol/ext-apps 1.7.5 2.0.3
@semantic-release/github 12.0.9 12.0.10
@types/node 26.4.1 26.6.3
eslint 10.10.0 10.11.0
typescript-eslint 8.69.0 8.70.1
vite 8.2.2 8.3.1
vitest 5.0.0 5.0.2

Updates @modelcontextprotocol/ext-apps from 1.7.5 to 2.0.3

Release notes

Sourced from @​modelcontextprotocol/ext-apps's releases.

v2.0.3

What's Changed

Patch release. No changes to the @modelcontextprotocol/ext-apps library itself; the fixes are in the example packages, so that a fresh install of each published package resolves a dependency tree that passes vulnerability and supply-chain scans.

Security

  • @modelcontextprotocol/server-basic-solid now depends on solid-js 1.9.15 instead of the exact 1.9.10, which pulled in seroval 1.3 (open advisories, fixed in 1.5.3). The root overrides that pinned seroval are removed, and the lockfile is refreshed with npm audit fix (patch and minor updates only, npm audit reports 0 vulnerabilities). by @​ochafik in #793
  • @modelcontextprotocol/server-pdf now depends on the exact @cantoo/pdf-lib 2.6.5 instead of ^2.6.5. The range resolved to 2.11.x, which the repository never tests and which added dependencies with open-ended ranges (culori, node-html-better-parser) that supply-chain scanners flag. by @​ochafik in #792

2.0.2 already pinned pdfjs-dist to 5.4.530 for server-pdf (#789).

Full Changelog: modelcontextprotocol/ext-apps@v2.0.2...v2.0.3

v2.0.2

What's Changed

Patch release. No changes to the @modelcontextprotocol/ext-apps library itself; the fix is in the @modelcontextprotocol/server-pdf example package.

Security

  • @modelcontextprotocol/server-pdf now depends on the exact pdfjs-dist 5.4.530 instead of ^5.0.0. The range let a fresh install resolve pdfjs-dist 5.6.83 or later (currently 5.7.284), which is affected by GHSA-hq66-cqwq-w95j (arbitrary JavaScript execution when opening a crafted PDF). 5.4.530 is outside the affected range and is the version the repository already tests against. Node support is unchanged. by @​ochafik in #789

Full Changelog: modelcontextprotocol/ext-apps@v2.0.1...v2.0.2

v2.0.1

What's Changed

Patch release. No changes to the @modelcontextprotocol/ext-apps library itself; the fixes are in the example servers, which are published as their own packages (including @modelcontextprotocol/server-pdf).

Bug fixes

  • Example servers no longer crash at startup on Node older than 20.11. They computed their dist directory from import.meta.filename / import.meta.dirname, which only exist from Node 20.11, so on Node 18 and 20.0 to 20.10 the module threw TypeError: Cannot read properties of undefined (reading 'endsWith') at load, before the server could answer initialize. All 21 affected servers and the quickstart now derive the path from import.meta.url with fileURLToPath. No behaviour change on Node 20.11+. Affected the published @modelcontextprotocol/server-pdf 1.7.5 and 2.0.0. by @​ochafik in #787
  • engines.node: ">=20" is now declared on the 21 published example packages, matching the root package and the README.

CI

  • The build now also runs the pdf-server MCPB bundle on Node 20.0.0, so this regression fails the build. #787
  • The dependency isolation check adds the ES2022.Error lib to its consumer projects. @modelcontextprotocol/client 2.1.0's typings reference ErrorOptions, so a project compiling with skipLibCheck: false and a lib older than ES2022 needs the same. #788

Packaging

  • repository.url uses the canonical git+https://github.com/modelcontextprotocol/ext-apps.git form in all manifests, which removes the "repository.url" was normalized warning from every publish job. by @​ochafik in #773

Full Changelog: modelcontextprotocol/ext-apps@v2.0.0...v2.0.1

v2.0.0

What's Changed

ext-apps 2.0 moves to the MCP TypeScript SDK 2.0 split packages. The MCP Apps wire protocol is unchanged: 2.x Views run in 1.x hosts and 2.x hosts render 1.x Views (covered by a test that runs the published 1.7.5 against this release in both directions). What breaks is dependencies and the TypeScript API; see the migration guide.

... (truncated)

Commits
  • 82221c0 Bump version to 2.0.3 (#794)
  • f20a1ff Update dependencies to clear npm audit findings (#793)
  • c9e00bd Pin @​cantoo/pdf-lib to 2.6.5 in pdf-server (#792)
  • fe9a9f1 Bump version to 2.0.2
  • 7bc2c5c Pin pdfjs-dist to 5.4.530 in pdf-server
  • a523ab3 Fix dependency isolation check against @​modelcontextprotocol/client 2.1
  • b0ddf50 Bump version to 2.0.1
  • 8e1b3bd Fix example servers crashing at startup on Node older than 20.11
  • 6d9bdc7 Merge pull request #773 from modelcontextprotocol/repo-url-fix
  • 2be172d Use the canonical git+https form for repository.url
  • Additional commits viewable in compare view

Updates @semantic-release/github from 12.0.9 to 12.0.10

Release notes

Sourced from @​semantic-release/github's releases.

v12.0.10

12.0.10 (2026-09-21)

Bug Fixes

  • deps: update dependency @​octokit/plugin-paginate-rest to v15 (#1284) (a63f458)
Commits
  • a63f458 fix(deps): update dependency @​octokit/plugin-paginate-rest to v15 (#1284)
  • f5f6d0e build(deps): bump brace-expansion (#1300)
  • eaffbba build(deps): bump undici from 6.27.0 to 6.28.1 (#1301)
  • 07686dc chore(deps): update dependency undici to v7.29.0 [security] (#1283)
  • 9f010ee build(deps-dev): bump baseline-browser-mapping from 2.10.42 to 2.11.25 (#1295)
  • 81eeeca build(deps-dev): bump js-yaml from 3.15.0 to 3.15.2 (#1294)
  • 43c2210 build(deps-dev): bump fast-uri from 3.1.4 to 3.1.8 (#1290)
  • e703272 build(deps-dev): bump browserslist from 4.28.4 to 4.29.0 (#1291)
  • e7f4b4b chore(deps): update dependency prettier to v3.9.8 (#1298)
  • 2e9e42b chore(deps): update dependency prettier to v3.9.7 (#1296)
  • Additional commits viewable in compare view

Updates @types/node from 26.4.1 to 26.6.3

Commits

Updates eslint from 10.10.0 to 10.11.0

Release notes

Sourced from eslint's releases.

v10.11.0

Features

  • d136fa4 feat: object-shorthand handle quoted properties for ignoreConstructors (#21271) (Pavel)
  • 397b3b8 feat: report unsafe labeled continue in no-unsafe-finally rule (#21316) (electrohyun)
  • d3dd47f feat: only exempt new-cap built-ins that reference the global (#21290) (sethamus)

Bug Fixes

  • 22b09f5 fix: ignore __proto__ properties in prefer-object-spread (#21311) (xbinaryx)
  • b684bb1 fix: make TimePass.parse optional in types and docs (#21313) (ntnyq)
  • 26d11bc fix: don't report __proto__ properties in object-shorthand (#21310) (xbinaryx)

Documentation

  • 9ecfdc5 docs: note that --cache can serve stale results for cross-file rules (#21312) (bytedoe)
  • 6c789ff docs: Update README (GitHub Actions Bot)
  • 5997825 docs: clarify preserve-caught-error known limitation (#21294) (Akinyemi Toluwalase)

Chores

  • 520dd77 perf: Implement fast paths in critical areas (#21210) (Nicholas C. Zakas)
  • 92086c8 test: update EMFILE error generation for Node.js 26.9.0 compatibility (#21330) (Francesco Trotta)
  • 9ac7eb6 chore: update github/codeql-action action to v4.38.0 (#21331) (renovate[bot])
  • 24310e3 chore: update ecosystem plugins (#21324) (ESLint Bot)
  • 45ad79e ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (#21318) (dependabot[bot])
  • ac74e37 chore: Add AGENTS.md with AI disclosure requirements (#21221) (Nicholas C. Zakas)
  • c832660 chore: Upgrade Stylelint to the latest version in docs (#21245) (Jung Hyeon Jun)
  • f9f88fc chore: update ecosystem plugins (#21308) (ESLint Bot)
  • fc81076 ci: add more types integration tests (#20395) (Nitin Kumar)
Commits
  • 3c0b7c6 10.11.0
  • 321f0a7 Build: changelog update for 10.11.0
  • 520dd77 perf: Implement fast paths in critical areas (#21210)
  • 9ecfdc5 docs: note that --cache can serve stale results for cross-file rules (#21312)
  • 92086c8 test: update EMFILE error generation for Node.js 26.9.0 compatibility (#21330)
  • 9ac7eb6 chore: update github/codeql-action action to v4.38.0 (#21331)
  • 22b09f5 fix: ignore __proto__ properties in prefer-object-spread (#21311)
  • 24310e3 chore: update ecosystem plugins (#21324)
  • d136fa4 feat: object-shorthand handle quoted properties for ignoreConstructors (#21...
  • 45ad79e ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (#21318)
  • Additional commits viewable in compare view

Updates typescript-eslint from 8.69.0 to 8.70.1

Release notes

Sourced from typescript-eslint's releases.

v8.70.1

8.70.1 (2026-09-21)

🩹 Fixes

  • ast-spec: narrow import attribute keys to identifiers and strings (#12879)
  • eslint-plugin: [no-useless-default-assignment] avoid false positives on tuples with a rest element (#12768)
  • eslint-plugin: [no-unnecessary-type-parameters] handle type precedence in the suggestion fixer (#12637)
  • eslint-plugin: [no-explicit-any] use unknown[] for bare any rest parameters (#12818)
  • eslint-plugin: [no-generated-empty-object-type] don't report a mapped type whose keys are not resolved yet (#12854)
  • eslint-plugin: [no-misused-spread] omit WeakMap spread suggestions (#12850)
  • eslint-plugin: [no-unnecessary-type-assertion] false positive for empty object asserted to a type alias of Record (#12869)
  • eslint-plugin: [no-meaningless-void-operator] allow void on assignment expressions (#12873)
  • eslint-plugin: [await-thenable] prevent autofix from breaking code when removing await (#12716)
  • eslint-plugin: [no-unnecessary-parameter-property-assignment] account for parameter reassignment (#12880)
  • eslint-plugin: [unbound-method] treat Intl.Collator.prototype.compare as spec-bound (#12845)
  • eslint-plugin: [no-unnecessary-condition] handle union-keyed index access on the left-hand side of nullish assignment (#12747)
  • eslint-plugin: [no-useless-default-assignment] convert the fixer to a suggestion fixer (#12826)
  • eslint-plugin: [no-misused-promises] handle multiple Promise constituents (#12904)
  • rule-tester: test the final autofix output instead of the first pass (#12867)
  • scope-manager: merge implicit global definitions (#12809)
  • type-utils: match package specifiers on whole path components (#12838)
  • typescript-estree: resolve symlinked paths when matching files to projects (#12725)
  • typescript-estree: add missing < token opening type arguments (#12821)
  • typescript-estree: require string literal import attribute values (#12894)
  • website: prevent playground from breaking down after opening link with the .js file type (#12777)

❤️ Thank You

See GitHub Releases for more information.

... (truncated)

Changelog

Sourced from typescript-eslint's changelog.

8.70.1 (2026-09-21)

This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

8.70.0 (2026-09-07)

🩹 Fixes

  • eslint-plugin: [no-deprecated] report deprecated imported values used in object shorthand properties (#12780)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Commits
  • 23d38ce chore(release): publish 8.70.1
  • eb42d9b chore: cleanup and fix Nx dependencies and missing tasks (#12897)
  • 8c80531 chore: fix typos in comments and docs (#12846)
  • b6b86a1 chore: migrate to nx 23.2.0 (#12843)
  • 7ee7608 chore(release): publish 8.70.0
  • 4586535 fix(eslint-plugin): [no-deprecated] report deprecated imported values used in...
  • See full diff in compare view

Updates vite from 8.2.2 to 8.3.1

Release notes

Sourced from vite's releases.

v8.3.1

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (9aecbbf)
  • handle server.ws: false in mergeConfig (#23511) (f68c0d5)
  • merge build.rolldownOptions.output.comments correctly (#23514) (4aba8d8)
  • optimizer: don't skip imports whose binding starts with type (#23540) (39330f4)
  • optimizer: resolve pending discovered dep processing on close before init (#23567) (5f89433)
  • server: avoid reinitializing watcher when adding file after server close (#23572) (6f831f9)
  • sourcemap: skip URL source roots when injecting sources content (#23519) (04fc30a)

Miscellaneous Chores

Code Refactoring

create-vite@8.3.0

Please refer to CHANGELOG.md for details.

v8.3.0

Features

  • build: avoid settling seen preload dependencies for performance (#23446) (e6f6b3e)

Bug Fixes

  • handle CRLF line endings in code frame positions (#23219) (9913672)
  • only treat whole node_modules path segments as dependencies (fix #17467) (#23437) (ef0dc17)

Performance Improvements

  • proxy: pre-compile context matchers at server creation (#23263) (8abf700)

v8.3.0-beta.1

Features

Bug Fixes

  • build: keep hash placeholders as-is in resolveFileUrl hook (#23422) (e8d6a4d)

... (truncated)

Changelog

Sourced from vite's changelog.

8.3.1 (2026-09-24)

Bug Fixes

  • deps: update all non-major dependencies (#23482) (3c752c8)
  • deps: update all non-major dependencies (#23537) (e8990c4)
  • deps: update rolldown-related dependencies (#23483) (9aecbbf)
  • handle server.ws: false in mergeConfig (#23511) (f68c0d5)
  • merge build.rolldownOptions.output.comments correctly (#23514) (4aba8d8)
  • optimizer: don't skip imports whose binding starts with type (#23540) (39330f4)
  • optimizer: resolve pending discovered dep processing on close before init (#23567) (5f89433)
  • server: avoid reinitializing watcher when adding file after server close (#23572) (6f831f9)
  • sourcemap: skip URL source roots when injecting sources content (#23519) (04fc30a)

Miscellaneous Chores

Code Refactoring

8.3.0 (2026-09-10)

Features

  • build: avoid settling seen preload dependencies for performance (#23446) (e6f6b3e)
  • devtools: enable dev server integration (#23333) (68aeb8a)
  • accept Rolldown watch options in server.watch (#23133) (1b5cfe3)
  • add closeServer and closePreviewServer hooks (#23110) (e17d2d5)
  • add top-level tsconfig option (#23310) (93164c3)
  • add warning for unsupported hooks in plugin returned from applyToEnvironment hook (#23191) (fdef04f)
  • cli: support naming the CPU profile via --profile [name] (#23042) (a500dee)
  • config: warn on named imports from JSON modules (#23378) (472385e)
  • css: minify style tag (#23183) (8156684)
  • searched params attached to workers are now preserved (#22280) (517b97f)
  • support subpath imports in dynamic import statements (#23185) (b78e2f1)
  • use import.meta.ROLLDOWN_FILE_URL_* for assets in JS (#22888) (4366ac4)
  • use import.meta.ROLLDOWN_FILE_URL_* for other plugins (#22894) (e38f29e)
  • worker: remove worker chunk if it's detected that it's not referenced (#22473) (924997a)

Bug Fixes

  • handle CRLF line endings in code frame positions (#23219) (9913672)
  • only treat whole node_modules path segments as dependencies (fix #17467) (#23437) (ef0dc17)
  • build: keep hash placeholders as-is in resolveFileUrl hook (#23422) (e8d6a4d)
  • bundled-dev: mark payload delivered on client report (#23373) (a6d43bc)

... (truncated)

Commits
  • 39ddf7c release: v8.3.1 (#23573)
  • f68c0d5 fix: handle server.ws: false in mergeConfig (#23511)
  • 6f831f9 fix(server): avoid reinitializing watcher when adding file after server close...
  • 04fc30a fix(sourcemap): skip URL source roots when injecting sources content (#23519)
  • 5f89433 fix(optimizer): resolve pending discovered dep processing on close before ini...
  • 63567c7 chore(optimizer): add debug log when waiting for dep before init (#23566)
  • e8990c4 fix(deps): update all non-major dependencies (#23537)
  • af7cdf6 refactor: replace find with some (#23554)
  • 39330f4 fix(optimizer): don't skip imports whose binding starts with type (#23540)
  • 9abd99b refactor: remove duplicate configurations (#23532)
  • Additional commits viewable in compare view

Updates vitest from 5.0.0 to 5.0.2

Release notes

Sourced from vitest's releases.

v5.0.2

   🐞 Bug Fixes

    View changes on GitHub

v5.0.1

   🚀 Features

   🐞 Bug Fixes

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

…y with 7 updates

Bumps the dev-dependencies group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@modelcontextprotocol/ext-apps](https://github.com/modelcontextprotocol/ext-apps) | `1.7.5` | `2.0.3` |
| [@semantic-release/github](https://github.com/semantic-release/github) | `12.0.9` | `12.0.10` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.4.1` | `26.6.3` |
| [eslint](https://github.com/eslint/eslint) | `10.10.0` | `10.11.0` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.69.0` | `8.70.1` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.2.2` | `8.3.1` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.0` | `5.0.2` |



Updates `@modelcontextprotocol/ext-apps` from 1.7.5 to 2.0.3
- [Release notes](https://github.com/modelcontextprotocol/ext-apps/releases)
- [Changelog](https://github.com/modelcontextprotocol/ext-apps/blob/main/RELEASES.md)
- [Commits](modelcontextprotocol/ext-apps@v1.7.5...v2.0.3)

Updates `@semantic-release/github` from 12.0.9 to 12.0.10
- [Release notes](https://github.com/semantic-release/github/releases)
- [Commits](semantic-release/github@v12.0.9...v12.0.10)

Updates `@types/node` from 26.4.1 to 26.6.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `eslint` from 10.10.0 to 10.11.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.10.0...v10.11.0)

Updates `typescript-eslint` from 8.69.0 to 8.70.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/typescript-eslint)

Updates `vite` from 8.2.2 to 8.3.1
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.1/packages/vite)

Updates `vitest` from 5.0.0 to 5.0.2
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/vitest)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/ext-apps"
  dependency-version: 2.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dev-dependencies
- dependency-name: "@semantic-release/github"
  dependency-version: 12.0.10
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: "@types/node"
  dependency-version: 26.6.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: eslint
  dependency-version: 10.11.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: typescript-eslint
  dependency-version: 8.70.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: vite
  dependency-version: 8.3.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: vitest
  dependency-version: 5.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
@dependabot
dependabot Bot requested a review from asachs01 as a code owner September 28, 2026 23:45
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 9b754962-b27a-4618-adc6-36fa0c125293

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants