Skip to content

Version Packages - #2

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
changeset-release/main
Open

github-actions[bot] wants to merge 1 commit into
mainfrom
changeset-release/main

Conversation

@github-actions

@github-actions github-actions Bot commented Jul 3, 2026 •

Copy link
Copy Markdown

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and publish to npm yourself or setup this action to publish automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@modelcontextprotocol/client@2.1.1

Patch Changes

  • #2883 c0f7aec Thanks @claude! - Fix a type-check failure for CommonJS TypeScript projects introduced in 2.1.0: dist/index.d.cts imported types from jose, which is ESM-only, so tsc with module: node16/node18 and skipLibCheck: false failed with TS1479. The two jose types used by the DPoP API (CryptoKey, JWK) are now inlined into the declaration files. No runtime change.

  • #2768 efebf5b Thanks @web-abin! - Correct the JSDoc for insecure OAuth token endpoints. The TLS requirement comes from the MCP authorization specification's OAuth 2.1 communication-security rules, not SEP-2207, which covers OIDC-flavored refresh-token guidance. Documentation only; no runtime behavior change.

  • #2729 a4ae2f9 Thanks @claude! - Correct the registerClient @deprecated notice: Dynamic Client Registration was deprecated by spec PR fix(spec): freeze 2026-07-28 release references modelcontextprotocol/typescript-sdk#2858 (Client ID Metadata Documents), not SEP-2577 (which deprecates roots, sampling, and logging). The notice now also names the earliest possible removal date under the feature lifecycle policy (2027-07-28) and clarifies that the client_id_metadata_document_supported gating lives in the built-in auth() flow — registerClient called directly always sends the registration request. Documentation only; no runtime behavior change.

  • #2862 e780e13 Thanks @SyedTashfin! - Preserve _meta on input_required results. The 2026-07-28 decode seam rebuilt the payload from inputRequests and requestState only, so result-level metadata a server sent on an input_required result (including io.modelcontextprotocol/serverInfo) was dropped before an allowInputRequired: true caller could see it. Result._meta is a result-level field, so input_required carries it exactly like any other result.

  • #2642 cfa09db Thanks @claude! - Fix Client.listen() rejections escaping as process-level unhandled rejections. The internal opening promise could reject (ack timeout, transport close, server cancel, caller abort) while listen() was still serially awaiting transport.send(...), so no rejection handler was attached yet — the rejection surfaced as an unhandledRejection that caller-side handling cannot prevent, and a send that never settles (e.g. a stdio write parked on 'drain') left listen() suspended forever even though the ack timer had already fired. listen() now suspends on the opening state machine directly and routes send failures into it, so every termination path rejects the returned promise and nothing escapes.

  • #2597 7f7a94c Thanks @arimu1! - Treat hostnames ending in .localhost as loopback for the SEP-2207 token-endpoint https guard (RFC 6761 §6.3), so host-based multi-tenant local OAuth works. The SDK does not resolve the name itself: *.localhost reaches the local machine only if the system resolver follows RFC 6761.

  • Updated dependencies []:

    • @modelcontextprotocol/core@2.1.1

@modelcontextprotocol/codemod@2.1.1

Patch Changes

  • #2582 f091897 Thanks @axits-lab! - The v1-to-v2 codemod now writes rewritten imports where the first v1 import stood, not at the top of the file, so a license header, // @ts-nocheck, /// <reference> or a 'use client' / 'use server' / 'use strict' directive above it stays in place. Known gap: when a later step of the codemod replaces or removes the import (for example a file whose only SDK import is ErrorCode or StreamableHTTPError), the new import can still land above or inside the header, and a /** */ header can be removed. Files already migrated with codemod 2.1.0 or earlier are not repaired; check the top of those files.

@modelcontextprotocol/server@2.1.1

Patch Changes

  • #2778 e3fb9ed Thanks @vjymisal0! - Fix a stack overflow in createMcpHandler when the factory returns the same server instance for more than one request. Returning a fresh instance per request is still required.

  • Updated dependencies []:

    • @modelcontextprotocol/core@2.1.1

@modelcontextprotocol/server-legacy@2.1.1

Patch Changes

  • Updated dependencies []:
    • @modelcontextprotocol/core@2.1.1

@modelcontextprotocol/core@2.1.1

@modelcontextprotocol/core-internal@2.0.2

Patch Changes

  • Updated dependencies []:
    • @modelcontextprotocol/core@2.1.1

@github-actions
github-actions Bot force-pushed the changeset-release/main branch 4 times, most recently from 0dc45b6 to b598c15 Compare July 7, 2026 17:51
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 3 times, most recently from 94c73b5 to 88acdce Compare July 20, 2026 15:36
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 88acdce to 6a0903c Compare July 27, 2026 15:38
@github-actions github-actions Bot changed the title Version Packages (beta) Version Packages Jul 27, 2026
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 6a0903c to 4465346 Compare July 27, 2026 22:13
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 5 times, most recently from 4b1805d to b790ac2 Compare August 18, 2026 22:03
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 3 times, most recently from ddc94ef to 33d763f Compare September 1, 2026 06:34
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 3 times, most recently from e31d4c6 to eee7fe0 Compare September 10, 2026 05:21
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 2 times, most recently from 81b83d0 to 86d9b9a Compare September 17, 2026 02:43
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 86d9b9a to 892cd82 Compare September 24, 2026 07:10
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 892cd82 to 64e0f2b Compare September 28, 2026 15:34

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants