Merge pull request #31940 from backstage/renovate/npm-modelcontextprotocol-sdk-vulnerability

chore(deps): update dependency @modelcontextprotocol/sdk to v1.24.0 [security]
This commit is contained in:
Fredrik Adelöw
2025-12-09 15:53:49 +01:00
committed by GitHub
3 changed files with 43 additions and 18 deletions
+5
View File
@@ -0,0 +1,5 @@
---
'@backstage/plugin-mcp-actions-backend': patch
---
Added `@cfworker/json-schema` as a dependency to this package part of the `@modelcontextprotocol/sdk` bump as it's required in the types
+2 -1
View File
@@ -40,7 +40,8 @@
"@backstage/errors": "workspace:^",
"@backstage/plugin-catalog-node": "workspace:^",
"@backstage/types": "workspace:^",
"@modelcontextprotocol/sdk": "^1.12.3",
"@cfworker/json-schema": "^4.1.1",
"@modelcontextprotocol/sdk": "^1.24.3",
"express": "^4.22.0",
"express-promise-router": "^4.1.0",
"zod": "^3.22.4"
+36 -17
View File
@@ -6012,7 +6012,8 @@ __metadata:
"@backstage/errors": "workspace:^"
"@backstage/plugin-catalog-node": "workspace:^"
"@backstage/types": "workspace:^"
"@modelcontextprotocol/sdk": "npm:^1.12.3"
"@cfworker/json-schema": "npm:^4.1.1"
"@modelcontextprotocol/sdk": "npm:^1.24.3"
"@types/express": "npm:^4.17.6"
express: "npm:^4.22.0"
express-promise-router: "npm:^4.1.0"
@@ -7922,6 +7923,13 @@ __metadata:
languageName: node
linkType: hard
"@cfworker/json-schema@npm:^4.1.1":
version: 4.1.1
resolution: "@cfworker/json-schema@npm:4.1.1"
checksum: 10/62fd08bb2e6b4f0fe7c2b8f8c19f17f94b6a34feba7f455f228898ab435eda8aae082fcf6b0fe8a235a72e0ec0041922fdcd4c526acc32d45084272f000c1af9
languageName: node
linkType: hard
"@changesets/apply-release-plan@npm:^7.0.14":
version: 7.0.14
resolution: "@changesets/apply-release-plan@npm:7.0.14"
@@ -11077,22 +11085,33 @@ __metadata:
languageName: node
linkType: hard
"@modelcontextprotocol/sdk@npm:^1.12.3":
version: 1.13.1
resolution: "@modelcontextprotocol/sdk@npm:1.13.1"
"@modelcontextprotocol/sdk@npm:^1.24.3":
version: 1.24.3
resolution: "@modelcontextprotocol/sdk@npm:1.24.3"
dependencies:
ajv: "npm:^6.12.6"
ajv: "npm:^8.17.1"
ajv-formats: "npm:^3.0.1"
content-type: "npm:^1.0.5"
cors: "npm:^2.8.5"
cross-spawn: "npm:^7.0.5"
eventsource: "npm:^3.0.2"
eventsource-parser: "npm:^3.0.0"
express: "npm:^5.0.1"
express-rate-limit: "npm:^7.5.0"
jose: "npm:^6.1.1"
pkce-challenge: "npm:^5.0.0"
raw-body: "npm:^3.0.0"
zod: "npm:^3.23.8"
zod-to-json-schema: "npm:^3.24.1"
checksum: 10/b516d72e1cd14c67c8a2e5cb95fcc1c03c50be989850e3e963a7ed11000acb604e65efeaad47ea93c847130536ee51859a8d34e6dbe99d408e1a24224592e57f
zod: "npm:^3.25 || ^4.0"
zod-to-json-schema: "npm:^3.25.0"
peerDependencies:
"@cfworker/json-schema": ^4.1.1
zod: ^3.25 || ^4.0
peerDependenciesMeta:
"@cfworker/json-schema":
optional: true
zod:
optional: false
checksum: 10/661aea493ee06674edc0d1409d5ff6e53053da2c3eb27d28ecdd5aa212d9d6bac8c00bec1cd18c1065f2d5774afef34e3cdcd19643056f954c14f611fee8cbc4
languageName: node
linkType: hard
@@ -23836,7 +23855,7 @@ __metadata:
languageName: node
linkType: hard
"ajv@npm:^6.12.2, ajv@npm:^6.12.4, ajv@npm:^6.12.5, ajv@npm:^6.12.6":
"ajv@npm:^6.12.2, ajv@npm:^6.12.4, ajv@npm:^6.12.5":
version: 6.12.6
resolution: "ajv@npm:6.12.6"
dependencies:
@@ -30108,10 +30127,10 @@ __metadata:
languageName: node
linkType: hard
"eventsource-parser@npm:^3.0.1":
version: 3.0.1
resolution: "eventsource-parser@npm:3.0.1"
checksum: 10/2730c54c3cb47d55d2967f2ece843f9fc95d8a11c2fef6fece8d17d9080193cbe3cd9ac7b04a325977f63cbf8c1664fdd0512dec1aec601666a5c5bd8564b61f
"eventsource-parser@npm:^3.0.0, eventsource-parser@npm:^3.0.1":
version: 3.0.6
resolution: "eventsource-parser@npm:3.0.6"
checksum: 10/febf7058b9c2168ecbb33e92711a1646e06bd1568f60b6eb6a01a8bf9f8fcd29cc8320d57247059cacf657a296280159f21306d2e3ff33309a9552b2ef889387
languageName: node
linkType: hard
@@ -35344,7 +35363,7 @@ __metadata:
languageName: node
linkType: hard
"jose@npm:^6.0.10":
"jose@npm:^6.0.10, jose@npm:^6.1.1":
version: 6.1.3
resolution: "jose@npm:6.1.3"
checksum: 10/9626c51e8c3792b505e954f3094698c182208617b62dfb27269230f31e57560b083985ed8128b8a9753aa92daf18d3a2341cc826d149503f14569abe87d42389
@@ -50448,7 +50467,7 @@ __metadata:
languageName: node
linkType: hard
"zod-to-json-schema@npm:^3.20.4, zod-to-json-schema@npm:^3.21.4, zod-to-json-schema@npm:^3.24.1":
"zod-to-json-schema@npm:^3.20.4, zod-to-json-schema@npm:^3.21.4, zod-to-json-schema@npm:^3.25.0":
version: 3.25.0
resolution: "zod-to-json-schema@npm:3.25.0"
peerDependencies:
@@ -50466,14 +50485,14 @@ __metadata:
languageName: node
linkType: hard
"zod@npm:^3.22.4, zod@npm:^3.23.8, zod@npm:^3.24.2":
"zod@npm:^3.22.4, zod@npm:^3.24.2":
version: 3.25.76
resolution: "zod@npm:3.25.76"
checksum: 10/f0c963ec40cd96858451d1690404d603d36507c1fc9682f2dae59ab38b578687d542708a7fdbf645f77926f78c9ed558f57c3d3aa226c285f798df0c4da16995
languageName: node
linkType: hard
"zod@npm:^4.1.11":
"zod@npm:^3.25 || ^4.0, zod@npm:^4.1.11":
version: 4.1.13
resolution: "zod@npm:4.1.13"
checksum: 10/0679190318928f69fcb07751063719de232c663b13955fcdb55db59839569d39f3f29b955cb0cba7af0b724233f88c06b3e84c550397ad4e68f8088fa6799d88