Version Packages - #175
Open
github-actions[bot] wants to merge 1 commit into
Open
Version Packages#175github-actions[bot] wants to merge 1 commit into
github-actions[bot] wants to merge 1 commit into
Conversation
github-actions
Bot
force-pushed
the
changeset-release/main
branch
from
December 23, 2025 12:33
9bf0e19 to
b798e3c
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
5 times, most recently
from
January 14, 2026 00:33
df38f93 to
59df763
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
5 times, most recently
from
January 22, 2026 18:33
5582238 to
b362edf
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
4 times, most recently
from
January 28, 2026 18:33
89b57bb to
085b09c
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
7 times, most recently
from
February 6, 2026 18:33
e385700 to
41a64d9
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
5 times, most recently
from
February 13, 2026 18:33
f341bd3 to
636fae5
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
3 times, most recently
from
February 20, 2026 06:33
ada79de to
d9110e9
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
2 times, most recently
from
March 15, 2026 18:33
e956327 to
ee99040
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
12 times, most recently
from
March 30, 2026 12:34
752fad9 to
894c2e2
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
3 times, most recently
from
March 31, 2026 06:34
c5aad6d to
e9f4a90
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
4 times, most recently
from
April 4, 2026 06:34
72ccc3f to
3b6840e
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
4 times, most recently
from
April 16, 2026 12:34
e6326bb to
53f503a
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
2 times, most recently
from
April 23, 2026 00:34
940e536 to
c2e832f
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and publish to npm yourself or setup this action to publish automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.
Releases
@modelcontextprotocol/client@2.2.0
Minor Changes
#2887
edd12e2Thanks @maxisbey! - ConstructingClientCredentialsProvider,PrivateKeyJwtProvider,StaticPrivateKeyJwtProviderorCrossAppAccessProviderwithoutexpectedIssueris deprecated: the constructor logs oneconsole.warnand that call signature is marked@deprecated. Behaviour is otherwise unchanged. Pass theissuerof the authorization server the credentials were registered with.fetchToken()throwsAuthorizationServerMismatchError, before sending anything, when the provider's client information is bound to a different authorization server than the one it is called with. TheAuthorizationServerMismatchErrormessage no longer assumes the authorization-code callback; its fields are unchanged.OAuthTokensSchemaandOAuthClientInformationSchemaaccept the optionalissuerstamp, so a provider that reads storage back through them keeps it.auth()overwrites it on every save.Patch Changes
#2885
9dd722fThanks @claude! - Sending a notification on a closed connection no longer produces a briefly unhandled promise rejection (seen asunhandledrejectionon Cloudflare Workers) in addition to the returned rejection.#2883
c0f7aecThanks @claude! - Fix a type-check failure for CommonJS TypeScript projects introduced in 2.1.0:dist/index.d.ctsimported types fromjose, which is ESM-only, sotscwithmodule: node16/node18andskipLibCheck: falsefailed with TS1479. The twojosetypes used by the DPoP API (CryptoKey,JWK) are now inlined into the declaration files. No runtime change.#2768
efebf5bThanks @web-abin! - Correct the JSDoc for insecure OAuth token endpoints. The TLS requirement comes from the MCP authorization specification's OAuth 2.1 communication-security rules, not SEP-2207, which covers OIDC-flavored refresh-token guidance. Documentation only; no runtime behavior change.#2729
a4ae2f9Thanks @claude! - Correct theregisterClient@deprecatednotice: Dynamic Client Registration was deprecated by spec PR fix(spec): freeze 2026-07-28 release references modelcontextprotocol/typescript-sdk#2858 (Client ID Metadata Documents), not SEP-2577 (which deprecates roots, sampling, and logging). The notice now also names the earliest possible removal date under the feature lifecycle policy (2027-07-28) and clarifies that theclient_id_metadata_document_supportedgating lives in the built-inauth()flow —registerClientcalled directly always sends the registration request. Documentation only; no runtime behavior change.#2862
e780e13Thanks @SyedTashfin! - Preserve_metaoninput_requiredresults. The 2026-07-28 decode seam rebuilt the payload frominputRequestsandrequestStateonly, so result-level metadata a server sent on aninput_requiredresult (includingio.modelcontextprotocol/serverInfo) was dropped before anallowInputRequired: truecaller could see it.Result._metais a result-level field, soinput_requiredcarries it exactly like any other result.#2886
ef39308Thanks @claude! -listTools(),listPrompts(),listResources()andlistResourceTemplates()called without a cursor now follownextCursoruntil the server stops sending one, instead of stopping silently with a short list when a cursor repeats; a page that has the same items and the samenextCursoras the page before it ends the walk and is not added twice, andlistMaxPagesstill caps the walk.#2642
cfa09dbThanks @claude! - FixClient.listen()rejections escaping as process-level unhandled rejections. The internalopeningpromise could reject (ack timeout, transport close, server cancel, caller abort) whilelisten()was still serially awaitingtransport.send(...), so no rejection handler was attached yet — the rejection surfaced as anunhandledRejectionthat caller-side handling cannot prevent, and a send that never settles (e.g. a stdio write parked on'drain') leftlisten()suspended forever even though the ack timer had already fired.listen()now suspends on theopeningstate machine directly and routes send failures into it, so every termination path rejects the returned promise and nothing escapes.#2597
7f7a94cThanks @arimu1! - Treat hostnames ending in.localhostas loopback for the SEP-2207 token-endpoint https guard (RFC 6761 §6.3), so host-based multi-tenant local OAuth works. The SDK does not resolve the name itself:*.localhostreaches the local machine only if the system resolver follows RFC 6761.Updated dependencies [
edd12e2]:@modelcontextprotocol/core@2.2.0
Minor Changes
#2887
edd12e2Thanks @maxisbey! - ConstructingClientCredentialsProvider,PrivateKeyJwtProvider,StaticPrivateKeyJwtProviderorCrossAppAccessProviderwithoutexpectedIssueris deprecated: the constructor logs oneconsole.warnand that call signature is marked@deprecated. Behaviour is otherwise unchanged. Pass theissuerof the authorization server the credentials were registered with.fetchToken()throwsAuthorizationServerMismatchError, before sending anything, when the provider's client information is bound to a different authorization server than the one it is called with. TheAuthorizationServerMismatchErrormessage no longer assumes the authorization-code callback; its fields are unchanged.OAuthTokensSchemaandOAuthClientInformationSchemaaccept the optionalissuerstamp, so a provider that reads storage back through them keeps it.auth()overwrites it on every save.@modelcontextprotocol/codemod@2.2.0
Patch Changes
f091897Thanks @axits-lab! - Thev1-to-v2codemod now writes rewritten imports where the first v1 import stood, not at the top of the file, so a license header,// @ts-nocheck,/// <reference>or a'use client'/'use server'/'use strict'directive above it stays in place. Known gap: when a later step of the codemod replaces or removes the import (for example a file whose only SDK import isErrorCodeorStreamableHTTPError), the new import can still land above or inside the header, and a/** */header can be removed. Files already migrated with codemod 2.1.0 or earlier are not repaired; check the top of those files.@modelcontextprotocol/server@2.2.0
Patch Changes
#2885
9dd722fThanks @claude! - Sending a notification on a closed connection no longer produces a briefly unhandled promise rejection (seen asunhandledrejectionon Cloudflare Workers) in addition to the returned rejection.#2778
e3fb9edThanks @vjymisal0! - Fix a stack overflow increateMcpHandlerwhen the factory returns the same server instance for more than one request. Returning a fresh instance per request is still required.Updated dependencies [
edd12e2]:@modelcontextprotocol/server-legacy@2.2.0
Patch Changes
edd12e2]:@modelcontextprotocol/core-internal@2.0.2
Patch Changes
edd12e2]: