Repository navigation
chore(deps-dev): bump @modelcontextprotocol/sdk from 1.30.0 to 1.31.0 in /packages/codemode - #2535
Conversation
Bumps [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) from 1.30.0 to 1.31.0. - [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases) - [Commits](modelcontextprotocol/typescript-sdk@1.30.0...1.31.0) --- updated-dependencies: - dependency-name: "@modelcontextprotocol/sdk" dependency-version: 1.31.0 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
| }, | ||
| "devDependencies": { | ||
| "@modelcontextprotocol/sdk": "1.30.0", | ||
| "@modelcontextprotocol/sdk": "1.31.0", |
There was a problem hiding this comment.
🟡 Frozen installs reject the SDK bump
With pnpm-lock.yaml still pinning 1.30.0 for codemode, pnpm install --frozen-lockfile rejects the new 1.31.0 specifier. Pull request and release CI stop before building or testing.
Learn more
The codemode lockfile importer still records @modelcontextprotocol/sdk with specifier 1.30.0 and version 1.30.0. Both pull request and release workflows use the shared install action, which runs pnpm install --frozen-lockfile. That command rejects a manifest whose specifier differs from its lockfile entry, so CI cannot install dependencies.
Example: A pull request job checks out this commit and runs the install action. The manifest asks for 1.31.0, the lockfile records 1.30.0, and installation fails before the build starts.
Recommended fix: Run pnpm install from the repository root and commit the regenerated pnpm-lock.yaml with this dependency update.
Was this helpful? React with 👍 or 👎 to provide feedback.
Bumps @modelcontextprotocol/sdk from 1.30.0 to 1.31.0.
Release notes
Sourced from @modelcontextprotocol/sdk's releases.
Commits
4b0051fchore: bump version to 1.31.0 (#2890)51ad4f0[v1.x] Bind stored OAuth credentials to the authorization server that issued ...289ac2cchore: bump version to 1.30.1 (#2848)12b4256fix(auth): preserve resource URI without trailing slash (#1968) (#1972)a9f6eb7[v1.x] fix(server): read HTTP request bodies with a size limit and bound JSON...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.