Bundle Node.js security updates: hono 4.11.7, @sentry/mcp-server 0.29.0 #12521
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bundles two Dependabot PRs for
.github/workflows/package.json: hono security patch and @sentry/mcp-server minor update.Security Fixes (hono 4.11.4 → 4.11.7)
Transitive dependency via
@sentry/mcp-server→@modelcontextprotocol/sdk→@hono/node-server.Fixed CVEs:
Cache-Control: private(Web Cache Deception)Minor Update (@sentry/mcp-server 0.27.0 → 0.29.0)
Standard semver minor bump. No breaking changes identified.
Changes
.github/workflows/package.json+ lockfile: Updated versions.github/workflows/shared/mcp/sentry.md: Updated npx reference from@sentry/mcp-server@0.27.0to@0.29.0.github/workflows/mcp-inspector.lock.yml: Recompiled workflowDEPENDENCY_UPDATE_RESEARCH.md: Research report with CVE analysis and risk assessmentVerification
npm audit # found 0 vulnerabilities (was 1 moderate with 4 CVEs)No breaking changes. MCP inspector workflow uses Sentry MCP server; hono used only as peer dependency in SDK.
Warning
Firewall rules blocked me from connecting to one or more addresses (expand for details)
I tried to connect to the following addresses, but was blocked by firewall rules:
https://api.github.com/repos/getsentry/sentry-mcp/releases/usr/bin/curl curl -s REDACTED(http block)If you need me to access, download, or install something from one of these locations, you can either:
Original prompt
💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.