Repository navigation
fix(deps): update dependency @modelcontextprotocol/sdk (1.32.0 → 1.32.1) - #1181
Conversation
There was a problem hiding this comment.
AI Automated Review
Full PR review.
Analysis engine: MiniMax-M3 (anthropic) — primary route · pr-reviewer-action v3.3.0
Recommendation
Approve. This is a clean, lockfile-only patch bump (@modelcontextprotocol/sdk 1.32.0 → 1.32.1) with CI green and no source/test changes.
Change-by-change findings
package-lock.json— exactly 3 lines change atnode_modules/@modelcontextprotocol/sdk:version,resolvedURL, and integrity hash. No othernode_modulesentries are touched (1.32.0still appears, but only for the unrelatedlightningcssfamily, which is unmodified).package.json— unchanged. The pin is still"@modelcontextprotocol/sdk": "^1.29.0"(caret range), so the lockfile move to 1.32.1 is fully within the declared SemVer range and not a version-floor surprise.src// tests /Dockerfile/ charts — not touched. The MCP consumer (src/mcp/server.ts) still imports@modelcontextprotocol/sdk/server/mcp.jsand@modelcontextprotocol/sdk/server/stdio.jsand callsnew McpServer(...)plusserver.registerTool(...)— surface that is unchanged across the bump.
Upstream release notes (1.32.1)
The published 1.32.1 release contains only three commits, all documentation or chore: a CLAUDE.md rewrite for the v1 maintenance line, a README pointer to v2, and the version bump itself. No source-code or API-surface changes. CI across this repo (Tests, Typecheck, Lint, Build, Docker Build, Docker Build (MCP), npm audit, Workflow lint, Smoke, Coverage, Database migrations, Database integration) reached success against the upgraded lockfile, which directly addresses the "patch-level, backward-compatible" assumption Renovate's compatibility badge encoded.
Standards Compliance
- AGENTS.md: "Lint/typecheck blocks CI; must pass" — both Lint and Typecheck reached
successon the PR head commit, satisfying this requirement. - AGENTS.md: "Tokens are secrets... never logged or persisted" — the diff contains no tokens, env values, or paths to secrets; no risk surface introduced.
Tool Harness Findings
- 15 tool calls across 9 rounds. The harness directly read
package.json,package-lock.json(lines 1985–2045),src/mcp/server.ts, andsrc/mcp/server.test.ts; grepped the repo for the package name, for the new and old version strings, and for the upstream PR numbers. All searches returned consistent results and no additional modifications were found.
Notes on the must-checks
- Check for breaking API changes in updated dependencies: satisfied. 1.32.0 → 1.32.1 is a docs/chore-only patch in upstream; the surface Dispatch consumes (
McpServer,StdioServerTransport,registerTool) is unchanged, and CI passing against the lockfile confirms there is no runtime regression. - Run full test suite after upgrade: satisfied. CI reports
Tests: success,Typecheck: success,Lint: success,Build: success,Coverage: success, plus Docker image builds andnpm audit— a full gate run on the PR head commit (7c87795).
No further verification needed.
This PR contains the following updates:
1.32.0→1.32.1Release Notes
modelcontextprotocol/typescript-sdk (@modelcontextprotocol/sdk)
v1.32.1Compare Source
What's Changed
Full Changelog: modelcontextprotocol/typescript-sdk@1.32.0...1.32.1
Configuration
📅 Schedule: (in timezone America/Edmonton)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.