chore(deps): update dependency @modelcontextprotocol/server to v2.2.0 - #115
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
renovate
Bot
force-pushed
the
renovate/modelcontextprotocol-server-2.x
branch
from
September 29, 2026 00:50
ecb1fd0 to
084863a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.1.0→2.2.0Release Notes
modelcontextprotocol/typescript-sdk (@modelcontextprotocol/server)
v2.2.0Compare Source
Minor Changes
#2887
edd12e2Thanks @maxisbey! - ConstructingClientCredentialsProvider,PrivateKeyJwtProvider,StaticPrivateKeyJwtProviderorCrossAppAccessProviderwithoutexpectedIssueris deprecated: the constructor logs oneconsole.warnand that call signature is marked@deprecated. Behaviour is otherwise unchanged. Pass theissuerof the authorization server the credentials were registered with.fetchToken()throwsAuthorizationServerMismatchError, before sending anything, when the provider's client information is bound to a different authorization server than the one it is called with. TheAuthorizationServerMismatchErrormessage no longer assumes the authorization-code callback; its fields are unchanged.OAuthTokensSchemaandOAuthClientInformationSchemaaccept the optionalissuerstamp, so a provider that reads storage back through them keeps it.auth()overwrites it on every save.Patch Changes
#2885
9dd722fThanks @claude! - Sending a notification on a closed connection no longer produces a briefly unhandled promise rejection (seen asunhandledrejectionon Cloudflare Workers) in addition to the returned rejection.#2883
c0f7aecThanks @claude! - Fix a type-check failure for CommonJS TypeScript projects introduced in 2.1.0:dist/index.d.ctsimported types fromjose, which is ESM-only, sotscwithmodule: node16/node18andskipLibCheck: falsefailed with TS1479. The twojosetypes used by the DPoP API (CryptoKey,JWK) are now inlined into the declaration files. No runtime change.#2768
efebf5bThanks @web-abin! - Correct the JSDoc for insecure OAuth token endpoints. The TLS requirement comes from the MCP authorization specification's OAuth 2.1 communication-security rules, not SEP-2207, which covers OIDC-flavored refresh-token guidance. Documentation only; no runtime behavior change.#2729
a4ae2f9Thanks @claude! - Correct theregisterClient@deprecatednotice: Dynamic Client Registration was deprecated by spec PR #2858 (Client ID Metadata Documents), not SEP-2577 (which deprecates roots, sampling, and logging). The notice now also names the earliest possible removal date under the feature lifecycle policy (2027-07-28) and clarifies that theclient_id_metadata_document_supportedgating lives in the built-inauth()flow —registerClientcalled directly always sends the registration request. Documentation only; no runtime behavior change.#2862
e780e13Thanks @SyedTashfin! - Preserve_metaoninput_requiredresults. The 2026-07-28 decode seam rebuilt the payload frominputRequestsandrequestStateonly, so result-level metadata a server sent on aninput_requiredresult (includingio.modelcontextprotocol/serverInfo) was dropped before anallowInputRequired: truecaller could see it.Result._metais a result-level field, soinput_requiredcarries it exactly like any other result.#2886
ef39308Thanks @claude! -listTools(),listPrompts(),listResources()andlistResourceTemplates()called without a cursor now follownextCursoruntil the server stops sending one, instead of stopping silently with a short list when a cursor repeats; a page that has the same items and the samenextCursoras the page before it ends the walk and is not added twice, andlistMaxPagesstill caps the walk.#2642
cfa09dbThanks @claude! - FixClient.listen()rejections escaping as process-level unhandled rejections. The internalopeningpromise could reject (ack timeout, transport close, server cancel, caller abort) whilelisten()was still serially awaitingtransport.send(...), so no rejection handler was attached yet — the rejection surfaced as anunhandledRejectionthat caller-side handling cannot prevent, and a send that never settles (e.g. a stdio write parked on'drain') leftlisten()suspended forever even though the ack timer had already fired.listen()now suspends on theopeningstate machine directly and routes send failures into it, so every termination path rejects the returned promise and nothing escapes.#2597
7f7a94cThanks @arimu1! - Treat hostnames ending in.localhostas loopback for the SEP-2207 token-endpoint https guard (RFC 6761 §6.3), so host-based multi-tenant local OAuth works. The SDK does not resolve the name itself:*.localhostreaches the local machine only if the system resolver follows RFC 6761.Updated dependencies [
edd12e2]:Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.