Skip to content

chore(deps): bump the patch-and-minor group in /src/mcp-server with 3 updates - #2633

Closed
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/src/mcp-server/dev/patch-and-minor-3e2c5c5c87
Closed

dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/src/mcp-server/dev/patch-and-minor-3e2c5c5c87

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the patch-and-minor group in /src/mcp-server with 3 updates: fastmcp, @types/node and tsx.

Updates fastmcp from 4.16.13 to 4.20.2

Release notes

Sourced from fastmcp's releases.

v4.20.2

4.20.2 (2026-09-04)

Bug Fixes

  • deps: upgrade mcp-proxy to 6.7.13 and drop the WWW-Authenticate workaround (#359) (782cd88)

v4.20.1

4.20.1 (2026-09-04)

Bug Fixes

  • http: emit WWW-Authenticate on 401 when authenticate() fails without oauth (#358) (55bb3c0)

v4.20.0

4.20.0 (2026-09-04)

Features

  • openapi: wire outputSchema/structuredContent and query/body serialization styles (#351) (10b08f7)

v4.19.1

4.19.1 (2026-09-04)

Bug Fixes

  • auth: cancel CIMD response body on early-return paths (#354) (5b68657)
  • http: authenticate once per httpStream request (#355) (da55e21)

v4.19.0

4.19.0 (2026-09-01)

Features

  • openapi: fix form-urlencoded request bodies, add GET-to-resource mapping (#350) (7ff8731)

v4.18.0

4.18.0 (2026-09-01)

Features

  • openapi: add fromOpenAPI() converter v1 for OpenAPI 3.x specs + real-world benchmark suite (#349) (27d054f)

v4.17.1

... (truncated)

Commits
  • 782cd88 fix(deps): upgrade mcp-proxy to 6.7.13 and drop the WWW-Authenticate workarou...
  • 55bb3c0 fix(http): emit WWW-Authenticate on 401 when authenticate() fails without oau...
  • 10b08f7 feat(openapi): wire outputSchema/structuredContent and query/body serializati...
  • da55e21 fix(http): authenticate once per httpStream request (#355)
  • 5b68657 fix(auth): cancel CIMD response body on early-return paths (#354)
  • ef9ba65 chore(openapi): re-pin box and posthog benchmark spec hashes (#356)
  • 7ff8731 feat(openapi): fix form-urlencoded request bodies, add GET-to-resource mappin...
  • 27d054f feat(openapi): add fromOpenAPI() converter v1 for OpenAPI 3.x specs + real-wo...
  • 7016fa0 fix(oauth): require S256 PKCE from CIMD clients (#348)
  • 0f2b438 feat(oauth): add Client ID Metadata Document (CIMD) support to OAuthProxy (#347)
  • Additional commits viewable in compare view

Updates @types/node from 26.4.0 to 26.4.1

Commits

Updates tsx from 4.23.12 to 4.23.13

Release notes

Sourced from tsx's releases.

v4.23.13

4.23.13 (2026-08-30)

Bug Fixes

  • cache: bound shared transform cache memory (#835) (28e1f12)

This release is also available on:

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the patch-and-minor group in /src/mcp-server with 3 updates: [fastmcp](https://github.com/punkpeye/fastmcp), [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) and [tsx](https://github.com/privatenumber/tsx).


Updates `fastmcp` from 4.16.13 to 4.20.2
- [Release notes](https://github.com/punkpeye/fastmcp/releases)
- [Commits](punkpeye/fastmcp@v4.16.13...v4.20.2)

Updates `@types/node` from 26.4.0 to 26.4.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `tsx` from 4.23.12 to 4.23.13
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.12...v4.23.13)

---
updated-dependencies:
- dependency-name: fastmcp
  dependency-version: 4.20.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: "@types/node"
  dependency-version: 26.4.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: tsx
  dependency-version: 4.23.13
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency label Sep 8, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: mcp-server. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot @github

dependabot Bot commented on behalf of github Sep 15, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 15, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/src/mcp-server/dev/patch-and-minor-3e2c5c5c87 branch September 15, 2026 21:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants