Repository navigation
chore(mcp): bump the mcp-minor-and-patch group across 1 directory with 6 updates - #503
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
…h 6 updates Bumps the mcp-minor-and-patch group with 6 updates in the /mcp-server directory: | Package | From | To | | --- | --- | --- | | [jose](https://github.com/panva/jose) | `6.2.8` | `6.2.12` | | [zod](https://github.com/colinhacks/zod) | `4.4.3` | `4.5.4` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.2.0` | `26.4.1` | | [eslint](https://github.com/eslint/eslint) | `10.8.1` | `10.10.0` | | [tsx](https://github.com/privatenumber/tsx) | `4.23.12` | `4.23.13` | | [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.67.0` | `8.69.0` | Updates `jose` from 6.2.8 to 6.2.12 - [Release notes](https://github.com/panva/jose/releases) - [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md) - [Commits](panva/jose@v6.2.8...v6.2.12) Updates `zod` from 4.4.3 to 4.5.4 - [Release notes](https://github.com/colinhacks/zod/releases) - [Commits](colinhacks/zod@v4.4.3...v4.5.4) Updates `@types/node` from 26.2.0 to 26.4.1 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `eslint` from 10.8.1 to 10.10.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.8.1...v10.10.0) Updates `tsx` from 4.23.12 to 4.23.13 - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](privatenumber/tsx@v4.23.12...v4.23.13) Updates `typescript-eslint` from 8.67.0 to 8.69.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.69.0/packages/typescript-eslint) --- updated-dependencies: - dependency-name: "@types/node" dependency-version: 26.4.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: mcp-minor-and-patch - dependency-name: eslint dependency-version: 10.10.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: mcp-minor-and-patch - dependency-name: jose dependency-version: 6.2.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mcp-minor-and-patch - dependency-name: tsx dependency-version: 4.23.13 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: mcp-minor-and-patch - dependency-name: typescript-eslint dependency-version: 8.69.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: mcp-minor-and-patch - dependency-name: zod dependency-version: 4.5.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: mcp-minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/mcp-server/mcp-minor-and-patch-9ba24fae01
branch
from
September 8, 2026 21:34
7287305 to
a17ab78
Compare
elgorro
added a commit
that referenced
this pull request
Sep 12, 2026
…ontributing guide (#508) Started as triage of #504, the first external contribution to this repo, and grew to cover everything that triage exposed. ## 1. No contributing guide `CONTRIBUTING.md` did not exist anywhere. Nothing in the PR/issue templates or README mentioned claiming an issue before writing code, so that expectation could not fairly be held against the contributor on #504. The new guide covers: ask first, repo layout, branch and commit conventions, the per-component checks, that a new test must fail without the change, closing keywords, what to expect from CI on a fork PR, and that AI-assisted contributions are welcome when disclosed with the bar unchanged. Linked from the README and the docs index, neither of which pointed anywhere. ## 2. Reviewing a fork PR safely The automatic review **cannot** run on a fork PR — GitHub mints no OIDC token for a `pull_request` event from a fork, so the job dies before it starts and that check is permanently red through no fault of the contributor. The obvious fallback — pull the branch and run it locally — is worse than the problem: `npm ci` executes arbitrary lifecycle scripts with a maintainer's SSH keys, npm tokens and cloud credentials in reach. New **`manual-code-review.yml`**: ```bash gh workflow run manual-code-review.yml -f pr=504 ``` - **No outside trigger.** `workflow_dispatch` requires write access, so a contributor cannot review their own PR. - **Credentials work**, because it runs in base-repo context. - **Fork code is never executed.** Checks out this repo's default branch, *not* the PR head, and Claude gets only the inline-comment tool — no shell, install, build or test run. The diff is read as data. - `contents: read` + `pull-requests: write`, so a hostile diff attempting prompt injection can at worst produce an unwanted comment. ## 3. Dependabot could never trigger the review `claude-code-action` rejects non-human actors unless listed in `allowed_bots`. #497, #503, #505, #506 and #507 all went unreviewed. Verified against the action source: `isAllowedBot` lowercases and strips a trailing `[bot]` from both sides, and `checkWritePermissions` already early-returns for any `[bot]` actor, so `allowed_bots` is the only change needed. Scoped to dependabot rather than `*`. ## 4. A required check that hung forever `ESLint & Prettier` is a **required** status check, but `lint.yml` carried a `paths: mcp-server/**` filter on its trigger. A PR touching only docs never triggered it, so it was never reported and the PR sat on `Expected — Waiting for status to be reported` with nothing a maintainer could do. This PR hit it. Fixed by dropping the trigger filter and moving the same condition inside the job, so it always runs and reports. Job name unchanged, so branch protection still matches. ## 5. Granularity for the other checks Every PR previously ran the full matrix regardless of what it touched — a docs-only change paid for an `npm ci`, a Composer install, a psalm run, an OpenAPI regeneration and a Go toolchain setup to test nothing. A `changes` job now diffs against the base commit once and publishes a boolean per component; each test job always runs but gates its steps. Markdown-only changes under a component don't trigger it, and any change under `.github/workflows/` sets everything true so CI revalidates itself — as this PR does. Detection verified against six scenarios before pushing: this branch, the #504 merge, docs-only, component-markdown-only, a lone Nextcloud PHP file, and a two-component change. ## 6. Docs `docs/dev/ci-cd.md` described a setup that no longer existed: the overview table omitted all three Claude workflows, test and lint were listed as running on push, the test section never mentioned the Hetzner job, psalm or the OpenAPI drift check, and the customization examples pinned `setup-node@v4` and Node 22 where the workflows use v7 and 24. Rewritten, plus troubleshooting entries for the three states that look like bugs but aren't: a required check stuck on "Expected", a red `claude-review` on a fork, and a fork PR showing no checks at all. `CLAUDE.md` gains a **Reviewing pull requests** section as the maintainer-side counterpart to `CONTRIBUTING.md`. ## Verification - all six checks green on this PR, including all three test jobs (it edits workflows, so everything revalidates) - `ESLint & Prettier` now reports in ~6s instead of hanging - `claude-review` passes — first green since 2026-09-07, confirming the dependabot change didn't regress internal PRs - `manual-code-review.yml` **cannot be exercised until this merges**, since `workflow_dispatch` only appears once the workflow is on the default branch. First real run should be `-f pr=504`. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01UYWJYDDvbBQUCQvPgwzBaA --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
elgorro
added a commit
that referenced
this pull request
Sep 12, 2026
Clears all **11 open Dependabot alerts** (npm audit: 5 vulnerabilities → 0) and brings every ecosystem in the monorepo up to date. ## Security Every open alert was transitive through `@modelcontextprotocol/sdk@1.30.0` — which is already the latest release and declares these as *ranges*. No SDK bump was available or needed; the stale `hono: ^4.12.14` override was the only thing pinning a vulnerable floor. | Package | Before | After | |---|---|---| | `hono` | 4.13.1 | 4.13.7 | | `qs` | 6.15.3 | 6.16.0 | | `fast-uri` | 3.1.5 | 3.1.7 | | `ip-address` | 10.2.0 | 10.5.0 | | `body-parser` | 2.2.2 | 2.3.0 | ## Updates - **MCP server** — vitest 4→5, eslint 10.10.0, jose 6.2.12, tsx 4.23.13, typescript-eslint 8.70.0, zod 4.6.2, @types/node 26.5.1 - **Nextcloud frontend** — @nextcloud/dialogs 7.5.0, @nextcloud/vue 9.11.0, highlight.js 11.12.0, marked 18.0.12, vue 3.5.42, vue-router 5.3.1, vite 8.3.0 - **Nextcloud PHP** — anthropic-ai/sdk 0.43→0.48, phpunit 13.3.3, openapi-extractor 1.9.1, symfony/http-client 8.1.6, psalm 6.17.0 - **Hetzner** — x/crypto 0.57.0, x/net 0.59.0, x/sys 0.48.0, x/text 0.42.0, procfs 0.22.0 - **Actions** — checkout v7, setup-go v7, download-artifact v8, setup-qemu v4, metadata-action v6, cosign-installer v4 ## Infrastructure - `docker/standalone` pinned `aiquila-mcp:0.2.17` while the project is at `0.4.8` → `:latest` - Pinned the `:latest` third-party images (crowdsec, prometheus, node-exporter, grafana, cadvisor); all tags verified via `docker manifest inspect` - MCP image base `node:24-alpine` → `node:26-alpine` (`@types/node` was already on `^26`) - **`dependabot.yml` had no composer and no docker ecosystem** — the PHP deps and every container image were untracked. Both added, with the ecosystem table documented in `docs/dev/ci-cd.md`. ## Deliberately not done - **TypeScript 7** (#432) — `typescript-eslint` throws `does not support TS 7.0` and refuses to run, failing the required *ESLint & Prettier* check. Tracking: typescript-eslint/typescript-eslint#10940. The tsconfig was still modernized to `moduleResolution: nodenext` (node10 is removed in TS 7), so the eventual bump is a one-liner. - **`@nextcloud/vue` 9.12.0** — raises its `@nextcloud/files` peer to `^4.1.0-beta.2`; capped at `~9.11.0` rather than pull a prerelease into production. - **`nextcloud/ocp` 34** — belongs to the NC34 move (#495). ## Orphaned dependencies Checked; **none to remove**. Every npm direct dependency is referenced in source. The two PHP candidates are both load-bearing despite zero direct references: `nyholm/psr7` satisfies the Anthropic SDK's virtual PSR-17/18 requirements via `php-http/discovery`, and `doctrine/dbal` is needed because `vendor/nextcloud/ocp` types reference Doctrine and psalm parses `vendor/` via `<extraFiles>`. ## Verification - `npm audit`: **0 vulnerabilities** (both packages) - MCP: 56 files / 921 tests pass, lint 0 errors, prettier clean, build OK - Nextcloud: psalm **No errors found**, 608 tests / 1656 assertions, `generate-spec` produces no diff, vite build OK - Hetzner: `go build`, `go vet`, `go test` all pass - Docker: MCP image builds on node:26, reports `v26.8.2`, answers an MCP `initialize` handshake over stdio Supersedes #395, #398, #399, #404, #420, #432, #448–#452, #497, #498, #499, #503, #505, #506, #507. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01UYWJYDDvbBQUCQvPgwzBaA --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Contributor
Author
|
Looks like these dependencies are no longer updatable, so this is no longer needed. |
dependabot
Bot
deleted the
dependabot/npm_and_yarn/mcp-server/mcp-minor-and-patch-9ba24fae01
branch
September 12, 2026 14:38
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the mcp-minor-and-patch group with 6 updates in the /mcp-server directory:
6.2.86.2.124.4.34.5.426.2.026.4.110.8.110.10.04.23.124.23.138.67.08.69.0Updates
josefrom 6.2.8 to 6.2.12Release notes
Sourced from jose's releases.
... (truncated)
Changelog
Sourced from jose's changelog.
... (truncated)
Commits
505a55bchore(release): 6.2.127bc9a33perf: encode single-signature JWS input once78637bdperf: normalize General JWE shared headers oncebf5138bperf: deduplicate pending jwks key importsb23a6f3perf: use native encoding for larger ASCII stringsfd3ae3fperf: normalize jwks selection metadata once6925d43perf: avoid copying AES-GCM outputbe62530docs: clarify and shorten public API guidance1b41312build: preserve README when generation fails0b51829build: check tree-shaking for every public bindingUpdates
zodfrom 4.4.3 to 4.5.4Release notes
Sourced from zod's releases.
... (truncated)
Commits
e8e206f4.5.484e416ffix(v4): stop the cycle walk from firing a default factory (#6500)1a161024.5.3eab51fffix(v4): emit record numeric keys as strings in toJSONSchema (#6497)7e24a24docs(blog): drop the reading time and put a GitHub link in the navbare3a695bdocs(v4): record the email regex and container output-shape findings under Open99fce39bench(v4): z.compile() against zod-compiler (#6499)87d6464fix(docs): drop the OG description when the title wraps past two linese6b6ab3docs(blog): widen the z.compile example to a 20-property schema9a193aa4.5.2Updates
@types/nodefrom 26.2.0 to 26.4.1Commits
Updates
eslintfrom 10.8.1 to 10.10.0Release notes
Sourced from eslint's releases.
... (truncated)
Commits
3f20a5710.10.0f4e5284Build: changelog update for 10.10.0bb47dc6fix: update dependency file-entry-cache to v11 (#20801)427ac0afix: use format strings in debug calls (#21247)b3d876bchore: disable npm audit in ecosystem tests (#21306)9d81532fix: support__proto__in/* exported */comments (#21261)264b434feat: adddandvflags tono-unexpected-multiline(#21305)1696682ci: restore EMFILE test on Node.js 26 (#21297)2c7f5d6chore: update github/codeql-action action to v4.37.9 (#21296)87e0a08fix: prefer-object-has-own autofix breaks when Object is shadowed (#21282)Updates
tsxfrom 4.23.12 to 4.23.13Release notes
Sourced from tsx's releases.
Commits
28e1f12fix(cache): bound shared transform cache memory (#835)Updates
typescript-eslintfrom 8.67.0 to 8.69.0Release notes
Sourced from typescript-eslint's releases.
... (truncated)
Changelog
Sourced from typescript-eslint's changelog.
Commits
9a6e546chore(release): publish 8.69.08f4e00achore(release): publish 8.68.055f6d5dchore: enable source maps (#12677)