Skip to content

chore(mcp): bump the mcp-minor-and-patch group across 1 directory with 6 updates - #503

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/mcp-server/mcp-minor-and-patch-9ba24fae01
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/mcp-server/mcp-minor-and-patch-9ba24fae01

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the mcp-minor-and-patch group with 6 updates in the /mcp-server directory:

Package From To
jose 6.2.8 6.2.12
zod 4.4.3 4.5.4
@types/node 26.2.0 26.4.1
eslint 10.8.1 10.10.0
tsx 4.23.12 4.23.13
typescript-eslint 8.67.0 8.69.0

Updates jose from 6.2.8 to 6.2.12

Release notes

Sourced from jose's releases.

v6.2.12

Documentation

  • clarify and shorten public API guidance (be62530)

Refactor

  • simplify JWS and JWE operation cores (92e9640)

Performance

  • avoid copying AES-GCM output (6925d43)
  • deduplicate pending jwks key imports (bf5138b)
  • encode single-signature JWS input once (7bc9a33)
  • normalize General JWE shared headers once (78637bd)
  • normalize jwks selection metadata once (fd3ae3f)
  • use native encoding for larger ASCII strings (b23a6f3)

v6.2.11

Documentation

  • render subpath indexes as tables (94589ee)
  • shorten API index descriptions (681482f)

Refactor

  • model JWE key management modes (e01dda6)
  • types: reduce declaration repetition (55b970f)

v6.2.10

Fixes

  • jose: consume serialization members once (9bee285)
  • jose: reject empty protected and JWE AAD members (8da4145)
  • jose: validate serialized header values (b711d8f)
  • jwe: conceal invalid decrypted CEK lengths (41fafe0)
  • jwe: enforce AES-GCM tag boundaries (9a5b744)
  • jwe: validate explicit encryption parameters (7a02697)
  • jwk: accept empty octet-sequence keys (3f871e7)
  • jwk: normalize key resolution inputs (f54ee7b)
  • jwks: enforce verification key metadata (f9ba510)
  • jwks: order overlapping remote reloads (9a1a913)
  • jwks: reject invalid remote duration values (7bdb9e5)
  • jwk: validate ext and key_ops parameters (4d91c37)
  • jws: reject mixed payload encoding modes (dc69713)
  • jws: validate unencoded payload strings (541f282)
  • jwt: enforce explicit verification policies (b347182)
  • jwt: prevent replacing protected headers (ae07d09)
  • jwt: reject invalid duration inputs (282f9aa)
  • jwt: validate builder claim values (ea03f83)

... (truncated)

Changelog

Sourced from jose's changelog.

6.2.12 (2026-09-05)

Documentation

  • clarify and shorten public API guidance (be62530)

Refactor

  • simplify JWS and JWE operation cores (92e9640)

Performance

  • avoid copying AES-GCM output (6925d43)
  • deduplicate pending jwks key imports (bf5138b)
  • encode single-signature JWS input once (7bc9a33)
  • normalize General JWE shared headers once (78637bd)
  • normalize jwks selection metadata once (fd3ae3f)
  • use native encoding for larger ASCII strings (b23a6f3)

6.2.11 (2026-09-04)

Documentation

  • render subpath indexes as tables (94589ee)
  • shorten API index descriptions (681482f)

Refactor

  • model JWE key management modes (e01dda6)
  • types: reduce declaration repetition (55b970f)

6.2.10 (2026-08-21)

Fixes

  • jose: consume serialization members once (9bee285)
  • jose: reject empty protected and JWE AAD members (8da4145)
  • jose: validate serialized header values (b711d8f)
  • jwe: conceal invalid decrypted CEK lengths (41fafe0)
  • jwe: enforce AES-GCM tag boundaries (9a5b744)
  • jwe: validate explicit encryption parameters (7a02697)
  • jwk: accept empty octet-sequence keys (3f871e7)
  • jwk: normalize key resolution inputs (f54ee7b)
  • jwks: enforce verification key metadata (f9ba510)
  • jwks: order overlapping remote reloads (9a1a913)
  • jwks: reject invalid remote duration values (7bdb9e5)
  • jwk: validate ext and key_ops parameters (4d91c37)
  • jws: reject mixed payload encoding modes (dc69713)
  • jws: validate unencoded payload strings (541f282)
  • jwt: enforce explicit verification policies (b347182)

... (truncated)

Commits
  • 505a55b chore(release): 6.2.12
  • 7bc9a33 perf: encode single-signature JWS input once
  • 78637bd perf: normalize General JWE shared headers once
  • bf5138b perf: deduplicate pending jwks key imports
  • b23a6f3 perf: use native encoding for larger ASCII strings
  • fd3ae3f perf: normalize jwks selection metadata once
  • 6925d43 perf: avoid copying AES-GCM output
  • be62530 docs: clarify and shorten public API guidance
  • 1b41312 build: preserve README when generation fails
  • 0b51829 build: check tree-shaking for every public binding
  • Additional commits viewable in compare view

Updates zod from 4.4.3 to 4.5.4

Release notes

Sourced from zod's releases.

v4.5.4

Commits:

  • 84e416fbf4740527bbc8f319634f4e1b065bb42c fix(v4): stop the cycle walk from firing a default factory (#6500)
  • e8e206fa33ac5fe7ce20a2beb12d57b1cb3df653 4.5.4

v4.5.3

Commits:

  • e6b6ab347675cd2bd54b1bdbed16f98c59be82a9 docs(blog): widen the z.compile example to a 20-property schema
  • 87d6464418582bb96fc665a01f852ca6da324ad0 fix(docs): drop the OG description when the title wraps past two lines
  • 99fce394a026823e602b9c30d8d5d9f5f1932ce7 bench(v4): z.compile() against zod-compiler (#6499)
  • e3a695b6bf3f0d591ea682816e3cdaea04b0f967 docs(v4): record the email regex and container output-shape findings under Open
  • 7e24a24288183ce02554f1ded7775d0650a7b7e6 docs(blog): drop the reading time and put a GitHub link in the navbar
  • eab51ff3592b2d11d863f4ee4d5452f31a3de1b6 fix(v4): emit record numeric keys as strings in toJSONSchema (#6497)

v4.5.2

Commits:

  • a354314ac04fdd5484aa62dd5c3a4b553211a0e4 fix(docs): keep blog posts out of the docs collection (#6484)
  • d378c42aff6869f0929058a7923cd775880f5c4c ci: drop canary publishing from the release workflow (#6487)
  • 212b941791e7faae078e17645eb612824fd8f79a fix(v4): let a prototype method getter answer a bare call so vi.spyOn works (#6488)
  • e7576f542a7bc7ef3cc5eeec237714fd0e6b6e98 docs(blog): let the page show through the navbar in dark mode (#6489)
  • fedb06fafe33a66ce0b5c236ad2557e0a5a170fe fix(docs): match the blog TOC hover bar to the 2px active indicator
  • 6c932fcb2eea6eb671710ea058ca9fdc382ada89 chore: bump devcontainer image to Node 24 (#6470)
  • 6635d9dd367a664109de83c021995821f48efa29 docs(blog): soften the "method memoization" attribution
  • 019ae299cc75daa132bf1acf59086a520abf6b85 fix(docs): drop ISR on the docs route so the home page hydrates
  • 652bb438aa4c626c1cd7948c6849c4691239fca7 chore(docs): drop the scroll log from the route-change scroller
  • 571c8e8a3d73b4305f4abfdd6977773cc12f2bf5 fix(docs): render blog tabs with the stock fumadocs tab card
  • 9a193aa24b4efa3b315b91d4c56c8bc385b8513f 4.5.2

v4.5.1

Commits:

  • 2e862dbf89da2835e5206a8fd3d3be61afe3cf7f ci: gate the GitHub release and JSR publish on the version being live on npm
  • 8e03380510db36fa6fda979fc78a375fdea8021c 4.5.1

v4.5.0

Zod 4.5 is now available.

npm install zod@latest

At a glance:

... (truncated)

Commits
  • e8e206f 4.5.4
  • 84e416f fix(v4): stop the cycle walk from firing a default factory (#6500)
  • 1a16102 4.5.3
  • eab51ff fix(v4): emit record numeric keys as strings in toJSONSchema (#6497)
  • 7e24a24 docs(blog): drop the reading time and put a GitHub link in the navbar
  • e3a695b docs(v4): record the email regex and container output-shape findings under Open
  • 99fce39 bench(v4): z.compile() against zod-compiler (#6499)
  • 87d6464 fix(docs): drop the OG description when the title wraps past two lines
  • e6b6ab3 docs(blog): widen the z.compile example to a 20-property schema
  • 9a193aa 4.5.2
  • Additional commits viewable in compare view

Updates @types/node from 26.2.0 to 26.4.1

Commits

Updates eslint from 10.8.1 to 10.10.0

Release notes

Sourced from eslint's releases.

v10.10.0

Features

  • 264b434 feat: add d and v flags to no-unexpected-multiline (#21305) (Gihyeon Jeong / 정기현)
  • c6cc6c5 feat: check Object.prototype property names in new-cap (#21269) (crimsonjay0)
  • 5661fa6 feat: no-extra-bind false negatives with class fields and static blocks (#21260) (synthex-byte)

Bug Fixes

  • bb47dc6 fix: update dependency file-entry-cache to v11 (#20801) (Milos Djermanovic)
  • 427ac0a fix: use format strings in debug calls (#21247) (Francesco Trotta)
  • 9d81532 fix: support __proto__ in /* exported */ comments (#21261) (sethamus)
  • 87e0a08 fix: prefer-object-has-own autofix breaks when Object is shadowed (#21282) (김채영)
  • 8e2cb14 fix: new-cap false positive for UTC calls with properties: false (#21275) (Pixel)
  • 9f4a364 fix: Ignore static imports in no-unreachable (#21276) (Taha Kotil)

Documentation

  • 2417cad docs: Update README (GitHub Actions Bot)
  • 9cecb8a docs: document \c control letter escapes in no-control-regex (#21286) (한국)
  • 8724829 docs: update compat table links (#21263) (fnx)
  • 5634542 docs: Clarify eqeqeq suggestion behavior (#21256) (Müslüm Yılmaz)

Chores

  • b3d876b chore: disable npm audit in ecosystem tests (#21306) (Francesco Trotta)
  • 1696682 ci: restore EMFILE test on Node.js 26 (#21297) (Marry (Subin Yang))
  • 2c7f5d6 chore: update github/codeql-action action to v4.37.9 (#21296) (renovate[bot])
  • 3c753f1 chore: update eslint (#21289) (renovate[bot])
  • 1c73469 chore: update ecosystem plugins (#21280) (ESLint Bot)
  • 08a02be test: add error locations to no-extra-boolean-cast (#21266) (lumir)
  • 77bb1db chore: update github/codeql-action action to v4.37.8 (#21270) (renovate[bot])
  • 007e81a ci: skip EMFILE test on Node.js 26 (#21265) (lumir)
  • 0430280 chore: improve ecosystem tests compatibility on Windows (#21178) (crimsonjay0)

v10.9.1

Bug Fixes

  • 1e641c9 fix: no-loss-of-precision false positive with trailing decimal point (#21251) (Aleksandr Shoronov)

Documentation

  • ad74a8d docs: add deprecation steps for EOL package versions (#21248) (Francesco Trotta)

Chores

v10.9.0

Features

  • 08de88e feat: handle underflow in no-loss-of-precision (#21218) (Rithish S)
  • 55db479 feat: add checkConditionalExpressions to no-unmodified-loop-condition (#21175) (sethamus)

Bug Fixes

  • 2ba3025 fix: prevent unsafe no-var autofix with hoisted functions (#21213) (sethamus)
  • 8e69622 fix: Prevent no-var autofix when var is shadowed by catch parameter (#21204) (Yang Hyeonjong)
  • 684b579 fix: prefer-template invalid autofix creates a tagged template call (#21207) (김채영)

... (truncated)

Commits

Updates tsx from 4.23.12 to 4.23.13

Release notes

Sourced from tsx's releases.

v4.23.13

4.23.13 (2026-08-30)

Bug Fixes

  • cache: bound shared transform cache memory (#835) (28e1f12)

This release is also available on:

Commits

Updates typescript-eslint from 8.67.0 to 8.69.0

Release notes

Sourced from typescript-eslint's releases.

v8.69.0

8.69.0 (2026-08-31)

🚀 Features

  • eslint-plugin: [no-misused-promises] add flagUnions option for checkConditionals (#12603)

🩹 Fixes

  • eslint-plugin: [no-mixed-enums] use scope analysis instead of type checking for merged namespaces (#12731)
  • eslint-plugin: [unified-signatures] compare type parameters by constraint instead of name (#12741)
  • eslint-plugin: [no-meaningless-void-operator] report void on non-call expressions (#12727)
  • website: respect allowJs playground config (#12744)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.68.0

8.68.0 (2026-08-24)

🚀 Features

  • eslint-plugin: [strict-void-return] add fix suggestions (#12086)
  • utils: support ESLint rule meta.languages (#12663)

🩹 Fixes

  • eslint-plugin: [unified-signatures] deduplicate types in report (#12656)
  • eslint-plugin: [return-await] prevent autofix from breaking code in arrow-functions (#12707)
  • eslint-plugin: [unified-signatures] report identical signatures (#12678)
  • eslint-plugin: [no-unnecessary-type-assertion] prevent stack overflow in recursive types (#12711)
  • eslint-plugin: [no-floating-promises] setting ignoreVoid: false results in false negative in ArrowFunctionExpression (#12646)
  • eslint-plugin: [no-empty-object-type] ignore suggestions that result in invalid interfaces and export defaults (#12739)
  • website: playground crashes on extends configs (#12608)
  • website: account for thanks.dev and out-of-band donors in sponsors list (#12735)

❤️ Thank You

... (truncated)

Changelog

Sourced from typescript-eslint's changelog.

8.69.0 (2026-08-31)

This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

8.68.0 (2026-08-24)

This was a version bump only for typescript-eslint to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 7, 2026
…h 6 updates

Bumps the mcp-minor-and-patch group with 6 updates in the /mcp-server directory:

| Package | From | To |
| --- | --- | --- |
| [jose](https://github.com/panva/jose) | `6.2.8` | `6.2.12` |
| [zod](https://github.com/colinhacks/zod) | `4.4.3` | `4.5.4` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.2.0` | `26.4.1` |
| [eslint](https://github.com/eslint/eslint) | `10.8.1` | `10.10.0` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.12` | `4.23.13` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.67.0` | `8.69.0` |



Updates `jose` from 6.2.8 to 6.2.12
- [Release notes](https://github.com/panva/jose/releases)
- [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md)
- [Commits](panva/jose@v6.2.8...v6.2.12)

Updates `zod` from 4.4.3 to 4.5.4
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.4.3...v4.5.4)

Updates `@types/node` from 26.2.0 to 26.4.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `eslint` from 10.8.1 to 10.10.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.8.1...v10.10.0)

Updates `tsx` from 4.23.12 to 4.23.13
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.12...v4.23.13)

Updates `typescript-eslint` from 8.67.0 to 8.69.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.69.0/packages/typescript-eslint)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.4.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: mcp-minor-and-patch
- dependency-name: eslint
  dependency-version: 10.10.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: mcp-minor-and-patch
- dependency-name: jose
  dependency-version: 6.2.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: mcp-minor-and-patch
- dependency-name: tsx
  dependency-version: 4.23.13
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: mcp-minor-and-patch
- dependency-name: typescript-eslint
  dependency-version: 8.69.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: mcp-minor-and-patch
- dependency-name: zod
  dependency-version: 4.5.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: mcp-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/mcp-server/mcp-minor-and-patch-9ba24fae01 branch from 7287305 to a17ab78 Compare September 8, 2026 21:34
elgorro added a commit that referenced this pull request Sep 12, 2026
…ontributing guide (#508)

Started as triage of #504, the first external contribution to this repo,
and grew to cover everything that triage exposed.

## 1. No contributing guide

`CONTRIBUTING.md` did not exist anywhere. Nothing in the PR/issue
templates or README mentioned claiming an issue before writing code, so
that expectation could not fairly be held against the contributor on
#504.

The new guide covers: ask first, repo layout, branch and commit
conventions, the per-component checks, that a new test must fail without
the change, closing keywords, what to expect from CI on a fork PR, and
that AI-assisted contributions are welcome when disclosed with the bar
unchanged. Linked from the README and the docs index, neither of which
pointed anywhere.

## 2. Reviewing a fork PR safely

The automatic review **cannot** run on a fork PR — GitHub mints no OIDC
token for a `pull_request` event from a fork, so the job dies before it
starts and that check is permanently red through no fault of the
contributor.

The obvious fallback — pull the branch and run it locally — is worse
than the problem: `npm ci` executes arbitrary lifecycle scripts with a
maintainer's SSH keys, npm tokens and cloud credentials in reach.

New **`manual-code-review.yml`**:

```bash
gh workflow run manual-code-review.yml -f pr=504
```

- **No outside trigger.** `workflow_dispatch` requires write access, so
a contributor cannot review their own PR.
- **Credentials work**, because it runs in base-repo context.
- **Fork code is never executed.** Checks out this repo's default
branch, *not* the PR head, and Claude gets only the inline-comment tool
— no shell, install, build or test run. The diff is read as data.
- `contents: read` + `pull-requests: write`, so a hostile diff
attempting prompt injection can at worst produce an unwanted comment.

## 3. Dependabot could never trigger the review

`claude-code-action` rejects non-human actors unless listed in
`allowed_bots`. #497, #503, #505, #506 and #507 all went unreviewed.
Verified against the action source: `isAllowedBot` lowercases and strips
a trailing `[bot]` from both sides, and `checkWritePermissions` already
early-returns for any `[bot]` actor, so `allowed_bots` is the only
change needed. Scoped to dependabot rather than `*`.

## 4. A required check that hung forever

`ESLint & Prettier` is a **required** status check, but `lint.yml`
carried a `paths: mcp-server/**` filter on its trigger. A PR touching
only docs never triggered it, so it was never reported and the PR sat on
`Expected — Waiting for status to be reported` with nothing a maintainer
could do. This PR hit it.

Fixed by dropping the trigger filter and moving the same condition
inside the job, so it always runs and reports. Job name unchanged, so
branch protection still matches.

## 5. Granularity for the other checks

Every PR previously ran the full matrix regardless of what it touched —
a docs-only change paid for an `npm ci`, a Composer install, a psalm
run, an OpenAPI regeneration and a Go toolchain setup to test nothing.

A `changes` job now diffs against the base commit once and publishes a
boolean per component; each test job always runs but gates its steps.
Markdown-only changes under a component don't trigger it, and any change
under `.github/workflows/` sets everything true so CI revalidates itself
— as this PR does.

Detection verified against six scenarios before pushing: this branch,
the #504 merge, docs-only, component-markdown-only, a lone Nextcloud PHP
file, and a two-component change.

## 6. Docs

`docs/dev/ci-cd.md` described a setup that no longer existed: the
overview table omitted all three Claude workflows, test and lint were
listed as running on push, the test section never mentioned the Hetzner
job, psalm or the OpenAPI drift check, and the customization examples
pinned `setup-node@v4` and Node 22 where the workflows use v7 and 24.
Rewritten, plus troubleshooting entries for the three states that look
like bugs but aren't: a required check stuck on "Expected", a red
`claude-review` on a fork, and a fork PR showing no checks at all.

`CLAUDE.md` gains a **Reviewing pull requests** section as the
maintainer-side counterpart to `CONTRIBUTING.md`.

## Verification

- all six checks green on this PR, including all three test jobs (it
edits workflows, so everything revalidates)
- `ESLint & Prettier` now reports in ~6s instead of hanging
- `claude-review` passes — first green since 2026-09-07, confirming the
dependabot change didn't regress internal PRs
- `manual-code-review.yml` **cannot be exercised until this merges**,
since `workflow_dispatch` only appears once the workflow is on the
default branch. First real run should be `-f pr=504`.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01UYWJYDDvbBQUCQvPgwzBaA

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
elgorro added a commit that referenced this pull request Sep 12, 2026
Clears all **11 open Dependabot alerts** (npm audit: 5 vulnerabilities →
0) and brings every ecosystem in the monorepo up to date.

## Security

Every open alert was transitive through
`@modelcontextprotocol/sdk@1.30.0` — which is already the latest release
and declares these as *ranges*. No SDK bump was available or needed; the
stale `hono: ^4.12.14` override was the only thing pinning a vulnerable
floor.

| Package | Before | After |
|---|---|---|
| `hono` | 4.13.1 | 4.13.7 |
| `qs` | 6.15.3 | 6.16.0 |
| `fast-uri` | 3.1.5 | 3.1.7 |
| `ip-address` | 10.2.0 | 10.5.0 |
| `body-parser` | 2.2.2 | 2.3.0 |

## Updates

- **MCP server** — vitest 4→5, eslint 10.10.0, jose 6.2.12, tsx 4.23.13,
typescript-eslint 8.70.0, zod 4.6.2, @types/node 26.5.1
- **Nextcloud frontend** — @nextcloud/dialogs 7.5.0, @nextcloud/vue
9.11.0, highlight.js 11.12.0, marked 18.0.12, vue 3.5.42, vue-router
5.3.1, vite 8.3.0
- **Nextcloud PHP** — anthropic-ai/sdk 0.43→0.48, phpunit 13.3.3,
openapi-extractor 1.9.1, symfony/http-client 8.1.6, psalm 6.17.0
- **Hetzner** — x/crypto 0.57.0, x/net 0.59.0, x/sys 0.48.0, x/text
0.42.0, procfs 0.22.0
- **Actions** — checkout v7, setup-go v7, download-artifact v8,
setup-qemu v4, metadata-action v6, cosign-installer v4

## Infrastructure

- `docker/standalone` pinned `aiquila-mcp:0.2.17` while the project is
at `0.4.8` → `:latest`
- Pinned the `:latest` third-party images (crowdsec, prometheus,
node-exporter, grafana, cadvisor); all tags verified via `docker
manifest inspect`
- MCP image base `node:24-alpine` → `node:26-alpine` (`@types/node` was
already on `^26`)
- **`dependabot.yml` had no composer and no docker ecosystem** — the PHP
deps and every container image were untracked. Both added, with the
ecosystem table documented in `docs/dev/ci-cd.md`.

## Deliberately not done

- **TypeScript 7** (#432) — `typescript-eslint` throws `does not support
TS 7.0` and refuses to run, failing the required *ESLint & Prettier*
check. Tracking: typescript-eslint/typescript-eslint#10940. The tsconfig
was still modernized to `moduleResolution: nodenext` (node10 is removed
in TS 7), so the eventual bump is a one-liner.
- **`@nextcloud/vue` 9.12.0** — raises its `@nextcloud/files` peer to
`^4.1.0-beta.2`; capped at `~9.11.0` rather than pull a prerelease into
production.
- **`nextcloud/ocp` 34** — belongs to the NC34 move (#495).

## Orphaned dependencies

Checked; **none to remove**. Every npm direct dependency is referenced
in source. The two PHP candidates are both load-bearing despite zero
direct references: `nyholm/psr7` satisfies the Anthropic SDK's virtual
PSR-17/18 requirements via `php-http/discovery`, and `doctrine/dbal` is
needed because `vendor/nextcloud/ocp` types reference Doctrine and psalm
parses `vendor/` via `<extraFiles>`.

## Verification

- `npm audit`: **0 vulnerabilities** (both packages)
- MCP: 56 files / 921 tests pass, lint 0 errors, prettier clean, build
OK
- Nextcloud: psalm **No errors found**, 608 tests / 1656 assertions,
`generate-spec` produces no diff, vite build OK
- Hetzner: `go build`, `go vet`, `go test` all pass
- Docker: MCP image builds on node:26, reports `v26.8.2`, answers an MCP
`initialize` handshake over stdio

Supersedes #395, #398, #399, #404, #420, #432, #448–#452, #497, #498,
#499, #503, #505, #506, #507.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01UYWJYDDvbBQUCQvPgwzBaA

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 12, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are no longer updatable, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 12, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/mcp-server/mcp-minor-and-patch-9ba24fae01 branch September 12, 2026 14:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants