Skip to content

Conversation

@ibm-mend-app
Copy link

@ibm-mend-app ibm-mend-app bot commented Oct 24, 2025

This PR contains the following updates:

Package Change Age Confidence
@modelcontextprotocol/sdk (source) 1.20.1 -> 1.24.0 age confidence

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score Vulnerability
High High 8.1 CVE-2025-66414
Medium Medium 5.8 CVE-2025-13466

Release Notes

modelcontextprotocol/typescript-sdk (@​modelcontextprotocol/sdk)

v1.24.0

Compare Source

Summary

This release brings us up to speed with the latest MCP spec 2025-11-25. Take a look at the latest spec as well as the release blog post.

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.23.0...1.24.0

v1.23.1

Compare Source

Fixed:

  • Disabled SSE priming events to fix backwards compatibility - 1.23.x clients crash on empty SSE data (JSON.parse(""))

This is a patch for servers still on 1.23.x that were breaking clients not handling the the 2025-11-25 priming event behavior with empty SSE data fields. See https://github.com/modelcontextprotocol/typescript-sdk/pull/1233 for more details.

Full Changelog: modelcontextprotocol/typescript-sdk@1.23.0...1.23.1

v1.23.0

Compare Source

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.22.0...1.23.0

v1.22.0

Compare Source

What's Changed

@github-actions github-actions bot enabled auto-merge (squash) October 24, 2025 04:56
github-actions[bot]
github-actions bot previously approved these changes Oct 24, 2025
@ibm-mend-app ibm-mend-app bot changed the title fix(deps): update dependency @modelcontextprotocol/sdk to v1.20.2 fix(deps): update dependency @modelcontextprotocol/sdk to v1.21.0 Nov 4, 2025
@ibm-mend-app ibm-mend-app bot force-pushed the whitesource-remediate/modelcontextprotocol-sdk-1.x-lockfile branch from 40e3ed6 to 75b0621 Compare November 4, 2025 05:46
github-actions[bot]
github-actions bot previously approved these changes Nov 4, 2025
@ibm-mend-app ibm-mend-app bot changed the title fix(deps): update dependency @modelcontextprotocol/sdk to v1.21.0 fix(deps): update dependency @modelcontextprotocol/sdk to v1.21.1 Nov 8, 2025
@ibm-mend-app ibm-mend-app bot force-pushed the whitesource-remediate/modelcontextprotocol-sdk-1.x-lockfile branch from 75b0621 to f62d007 Compare November 8, 2025 05:15
github-actions[bot]
github-actions bot previously approved these changes Nov 8, 2025
@ibm-mend-app ibm-mend-app bot changed the title fix(deps): update dependency @modelcontextprotocol/sdk to v1.21.1 fix(deps): update dependency @modelcontextprotocol/sdk to v1.22.0 Nov 14, 2025
@ibm-mend-app ibm-mend-app bot force-pushed the whitesource-remediate/modelcontextprotocol-sdk-1.x-lockfile branch from f62d007 to 52674cb Compare November 14, 2025 05:12
github-actions[bot]
github-actions bot previously approved these changes Nov 14, 2025
@ibm-mend-app ibm-mend-app bot force-pushed the whitesource-remediate/modelcontextprotocol-sdk-1.x-lockfile branch from 52674cb to 5939777 Compare November 25, 2025 12:04
@ibm-mend-app ibm-mend-app bot added the security fix Security fix generated by WhiteSource label Nov 25, 2025
@ibm-mend-app ibm-mend-app bot changed the title fix(deps): update dependency @modelcontextprotocol/sdk to v1.22.0 fix(deps): update dependency @modelcontextprotocol/sdk to v1.20.2 Nov 25, 2025
github-actions[bot]
github-actions bot previously approved these changes Nov 25, 2025
@ibm-mend-app ibm-mend-app bot force-pushed the whitesource-remediate/modelcontextprotocol-sdk-1.x-lockfile branch from 5939777 to 5100147 Compare December 3, 2025 06:08
@ibm-mend-app ibm-mend-app bot changed the title fix(deps): update dependency @modelcontextprotocol/sdk to v1.20.2 fix(deps): update dependency @modelcontextprotocol/sdk to v1.24.0 Dec 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by WhiteSource

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants