Skip to content

Version Packages - #175

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
changeset-release/main
Open

github-actions[bot] wants to merge 1 commit into
mainfrom
changeset-release/main

Conversation

@github-actions

@github-actions github-actions Bot commented Dec 20, 2025 •

Copy link
Copy Markdown

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and publish to npm yourself or setup this action to publish automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@modelcontextprotocol/client@2.2.0

Minor Changes

  • #2887 edd12e2 Thanks @maxisbey! - Constructing ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider or CrossAppAccessProvider without expectedIssuer is deprecated: the constructor logs one console.warn and that call signature is marked @deprecated. Behaviour is otherwise unchanged. Pass the issuer of the authorization server the credentials were registered with.

    fetchToken() throws AuthorizationServerMismatchError, before sending anything, when the provider's client information is bound to a different authorization server than the one it is called with. The AuthorizationServerMismatchError message no longer assumes the authorization-code callback; its fields are unchanged.

    OAuthTokensSchema and OAuthClientInformationSchema accept the optional issuer stamp, so a provider that reads storage back through them keeps it. auth() overwrites it on every save.

Patch Changes

  • #2885 9dd722f Thanks @claude! - Sending a notification on a closed connection no longer produces a briefly unhandled promise rejection (seen as unhandledrejection on Cloudflare Workers) in addition to the returned rejection.

  • #2883 c0f7aec Thanks @claude! - Fix a type-check failure for CommonJS TypeScript projects introduced in 2.1.0: dist/index.d.cts imported types from jose, which is ESM-only, so tsc with module: node16/node18 and skipLibCheck: false failed with TS1479. The two jose types used by the DPoP API (CryptoKey, JWK) are now inlined into the declaration files. No runtime change.

  • #2768 efebf5b Thanks @web-abin! - Correct the JSDoc for insecure OAuth token endpoints. The TLS requirement comes from the MCP authorization specification's OAuth 2.1 communication-security rules, not SEP-2207, which covers OIDC-flavored refresh-token guidance. Documentation only; no runtime behavior change.

  • #2729 a4ae2f9 Thanks @claude! - Correct the registerClient @deprecated notice: Dynamic Client Registration was deprecated by spec PR fix(spec): freeze 2026-07-28 release references modelcontextprotocol/typescript-sdk#2858 (Client ID Metadata Documents), not SEP-2577 (which deprecates roots, sampling, and logging). The notice now also names the earliest possible removal date under the feature lifecycle policy (2027-07-28) and clarifies that the client_id_metadata_document_supported gating lives in the built-in auth() flow — registerClient called directly always sends the registration request. Documentation only; no runtime behavior change.

  • #2862 e780e13 Thanks @SyedTashfin! - Preserve _meta on input_required results. The 2026-07-28 decode seam rebuilt the payload from inputRequests and requestState only, so result-level metadata a server sent on an input_required result (including io.modelcontextprotocol/serverInfo) was dropped before an allowInputRequired: true caller could see it. Result._meta is a result-level field, so input_required carries it exactly like any other result.

  • #2886 ef39308 Thanks @claude! - listTools(), listPrompts(), listResources() and listResourceTemplates() called without a cursor now follow nextCursor until the server stops sending one, instead of stopping silently with a short list when a cursor repeats; a page that has the same items and the same nextCursor as the page before it ends the walk and is not added twice, and listMaxPages still caps the walk.

  • #2642 cfa09db Thanks @claude! - Fix Client.listen() rejections escaping as process-level unhandled rejections. The internal opening promise could reject (ack timeout, transport close, server cancel, caller abort) while listen() was still serially awaiting transport.send(...), so no rejection handler was attached yet — the rejection surfaced as an unhandledRejection that caller-side handling cannot prevent, and a send that never settles (e.g. a stdio write parked on 'drain') left listen() suspended forever even though the ack timer had already fired. listen() now suspends on the opening state machine directly and routes send failures into it, so every termination path rejects the returned promise and nothing escapes.

  • #2597 7f7a94c Thanks @arimu1! - Treat hostnames ending in .localhost as loopback for the SEP-2207 token-endpoint https guard (RFC 6761 §6.3), so host-based multi-tenant local OAuth works. The SDK does not resolve the name itself: *.localhost reaches the local machine only if the system resolver follows RFC 6761.

  • Updated dependencies [edd12e2]:

    • @modelcontextprotocol/core@2.2.0

@modelcontextprotocol/core@2.2.0

Minor Changes

  • #2887 edd12e2 Thanks @maxisbey! - Constructing ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider or CrossAppAccessProvider without expectedIssuer is deprecated: the constructor logs one console.warn and that call signature is marked @deprecated. Behaviour is otherwise unchanged. Pass the issuer of the authorization server the credentials were registered with.

    fetchToken() throws AuthorizationServerMismatchError, before sending anything, when the provider's client information is bound to a different authorization server than the one it is called with. The AuthorizationServerMismatchError message no longer assumes the authorization-code callback; its fields are unchanged.

    OAuthTokensSchema and OAuthClientInformationSchema accept the optional issuer stamp, so a provider that reads storage back through them keeps it. auth() overwrites it on every save.

@modelcontextprotocol/codemod@2.2.0

Patch Changes

  • #2582 f091897 Thanks @axits-lab! - The v1-to-v2 codemod now writes rewritten imports where the first v1 import stood, not at the top of the file, so a license header, // @ts-nocheck, /// <reference> or a 'use client' / 'use server' / 'use strict' directive above it stays in place. Known gap: when a later step of the codemod replaces or removes the import (for example a file whose only SDK import is ErrorCode or StreamableHTTPError), the new import can still land above or inside the header, and a /** */ header can be removed. Files already migrated with codemod 2.1.0 or earlier are not repaired; check the top of those files.

@modelcontextprotocol/server@2.2.0

Patch Changes

  • #2885 9dd722f Thanks @claude! - Sending a notification on a closed connection no longer produces a briefly unhandled promise rejection (seen as unhandledrejection on Cloudflare Workers) in addition to the returned rejection.

  • #2778 e3fb9ed Thanks @vjymisal0! - Fix a stack overflow in createMcpHandler when the factory returns the same server instance for more than one request. Returning a fresh instance per request is still required.

  • Updated dependencies [edd12e2]:

    • @modelcontextprotocol/core@2.2.0

@modelcontextprotocol/server-legacy@2.2.0

Patch Changes

  • Updated dependencies [edd12e2]:
    • @modelcontextprotocol/core@2.2.0

@modelcontextprotocol/core-internal@2.0.2

Patch Changes

  • Updated dependencies [edd12e2]:
    • @modelcontextprotocol/core@2.2.0

@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 9bf0e19 to b798e3c Compare December 23, 2025 12:33
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 5 times, most recently from df38f93 to 59df763 Compare January 14, 2026 00:33
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 5 times, most recently from 5582238 to b362edf Compare January 22, 2026 18:33
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 4 times, most recently from 89b57bb to 085b09c Compare January 28, 2026 18:33
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 7 times, most recently from e385700 to 41a64d9 Compare February 6, 2026 18:33
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 5 times, most recently from f341bd3 to 636fae5 Compare February 13, 2026 18:33
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 3 times, most recently from ada79de to d9110e9 Compare February 20, 2026 06:33
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 2 times, most recently from e956327 to ee99040 Compare March 15, 2026 18:33
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 12 times, most recently from 752fad9 to 894c2e2 Compare March 30, 2026 12:34
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 3 times, most recently from c5aad6d to e9f4a90 Compare March 31, 2026 06:34
@github-actions github-actions Bot changed the title Version Packages Version Packages (alpha) Mar 31, 2026
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 4 times, most recently from 72ccc3f to 3b6840e Compare April 4, 2026 06:34
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 4 times, most recently from e6326bb to 53f503a Compare April 16, 2026 12:34
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 2 times, most recently from 940e536 to c2e832f Compare April 23, 2026 00:34
@coderabbitai

coderabbitai Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 01ecd064-5871-4f54-805d-25c898bb4117

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants