Skip to content

deps(examples): bump @modelcontextprotocol/client from 2.1.0 to 2.3.1 in /examples/otel-recipes/js - #854

Merged
irparent merged 1 commit into
mainfrom
dependabot/npm_and_yarn/examples/otel-recipes/js/modelcontextprotocol/client-2.3.1
Oct 6, 2026
Merged

irparent merged 1 commit into
mainfrom
dependabot/npm_and_yarn/examples/otel-recipes/js/modelcontextprotocol/client-2.3.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor

Bumps @modelcontextprotocol/client from 2.1.0 to 2.3.1.

Release notes

Sourced from @​modelcontextprotocol/client's releases.

@​modelcontextprotocol/client@​2.3.1

Patch Changes

  • Updated dependencies []:
    • @​modelcontextprotocol/core@​2.3.1

@​modelcontextprotocol/client@​2.3.0

Minor Changes

  • #2901 433eb41 Thanks @​claude! - The HTTP client transports and the OAuth client helpers now follow a redirect only when it stays within the origin of the request (same scheme, host and port, or http to https on the same host with default ports) and keeps the method (a 307 or 308, or any redirect of a GET). Any other redirect is not followed. A transport then fails the request with an error that names the target; the session is kept and later messages still send. OAuth metadata discovery moves on to the next well-known URL, and any other OAuth request fails with an error that gives the status. Same-origin redirects that keep the method keep working on Node, up to five in a row, and no code changes are needed there. If your endpoint redirects to another origin, configure the transport with the URL it redirects to. A requestInit.redirect of 'error' or 'manual' is passed to fetch as it is for the requests a transport sends to the server (POST, GET and DELETE of the Streamable HTTP transport, POST of the SSE transport); for its OAuth requests, and for any other value, requestInit.redirect is not consulted by default. Browsers do not expose the target of a redirect to a page, so there a redirected request fails instead of being followed. Setting redirectPolicy: 'follow' on a transport leaves its redirects to the fetch implementation, as before this change.

Patch Changes

  • #2599 5238fba Thanks @​freya0926! - A server can now serve, and a client can now call, tasks/get and tasks/cancel of the Tasks extension (SEP-2663) on a 2026-07-28 connection, when the handler is registered and the request is sent with an explicit schema. Every other method that a protocol revision removed is still refused. If one server factory serves both eras and such a handler is meant for 2025-era clients only, register it only when ctx.era === 'legacy'.

  • #2846 63c0fca Thanks @​Sthreal! - Receiving a large message as a single SSE event over Streamable HTTP, such as a tool result of tens of megabytes, is now fast: a 50 MB result that took about 13 seconds arrives in under a second. The client now requires eventsource-parser 3.0.8 or later. SSEClientTransport reads through the eventsource package and gets the same speed-up once that also resolves eventsource-parser 3.0.8 or later.

  • #2908 633dd3e Thanks @​claude! - The license field of the package manifests is now Apache-2.0; the LICENSE file shipped in each package carries the full terms, including the MIT text for earlier contributions. No code change.

  • #2903 e765b3b Thanks @​claude! - With versionNegotiation in 'auto' or pin mode, a server/discover probe answered with a 2xx that carries no usable reply (a body that is not JSON under application/json, a bare 204, a missing or unaccepted content type) still rejects connect() with EraNegotiationFailed; an empty SSE stream or a 202 surfaces as the probe timeout instead. The message now says the server answered with an unusable reply (...) instead of reading like a network failure. To connect to a 2025 server behind a front that answers the probe this way, pass connect(transport, { prior: { kind: 'legacy' } }) or use mode: 'legacy'.

  • #2905 c0cd01a Thanks @​claude! - SSEClientTransport now retries the SSE connection once after onUnauthorized() resolves, as documented. If the retry is also answered with 401, start() rejects with SdkHttpError (ClientHttpAuthentication) instead of calling onUnauthorized() again. A 401 on a later reconnect of a stream that had opened still gets one refresh.

  • Updated dependencies [633dd3e]:

    • @​modelcontextprotocol/core@​2.3.0

@​modelcontextprotocol/client@​2.2.0

Minor Changes

  • #2887 edd12e2 Thanks @​maxisbey! - Constructing ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider or CrossAppAccessProvider without expectedIssuer is deprecated: the constructor logs one console.warn and that call signature is marked @deprecated. Behaviour is otherwise unchanged. Pass the issuer of the authorization server the credentials were registered with.

    fetchToken() throws AuthorizationServerMismatchError, before sending anything, when the provider's client information is bound to a different authorization server than the one it is called with. The AuthorizationServerMismatchError message no longer assumes the authorization-code callback; its fields are unchanged.

    OAuthTokensSchema and OAuthClientInformationSchema accept the optional issuer stamp, so a provider that reads storage back through them keeps it. auth() overwrites it on every save.

Patch Changes

  • #2885 9dd722f Thanks @​claude! - Sending a notification on a closed connection no longer produces a briefly unhandled promise rejection (seen as unhandledrejection on Cloudflare Workers) in addition to the returned rejection.

  • #2883 c0f7aec Thanks @​claude! - Fix a type-check failure for CommonJS TypeScript projects introduced in 2.1.0: dist/index.d.cts imported types from jose, which is ESM-only, so tsc with module: node16/node18 and skipLibCheck: false failed with TS1479. The two jose types used by the DPoP API (CryptoKey, JWK) are now inlined into the declaration files. No runtime change.

  • #2768 efebf5b Thanks @​web-abin! - Correct the JSDoc for insecure OAuth token endpoints. The TLS requirement comes from the MCP authorization specification's OAuth 2.1 communication-security rules, not SEP-2207, which covers OIDC-flavored refresh-token guidance. Documentation only; no runtime behavior change.

  • #2729 a4ae2f9 Thanks @​claude! - Correct the registerClient @deprecated notice: Dynamic Client Registration was deprecated by spec PR modelcontextprotocol#2858 (Client ID Metadata Documents), not SEP-2577 (which deprecates roots, sampling, and logging). The notice now also names the earliest possible removal date under the feature lifecycle policy (2027-07-28) and clarifies that the client_id_metadata_document_supported gating lives in the built-in auth() flow — registerClient called directly always sends the registration request. Documentation only; no runtime behavior change.

  • #2862 e780e13 Thanks @​SyedTashfin! - Preserve _meta on input_required results. The 2026-07-28 decode seam rebuilt the payload from inputRequests and requestState only, so result-level metadata a server sent on an input_required result (including io.modelcontextprotocol/serverInfo) was dropped before an allowInputRequired: true caller could see it. Result._meta is a result-level field, so input_required carries it exactly like any other result.

... (truncated)

Commits
  • fcef852 Version Packages (#2953)
  • e8b7f05 docs: one opening note in the server and client package READMEs (#2955)
  • 5a18673 feat(server-legacy): add expectedResource to requireBearerAuth (#2952)
  • 3ab61c6 docs: update the README banners (#2940)
  • 8aabbdc test(e2e): expect SdkHttpError after a second 401 from onUnauthorized (#2936)
  • 33fecfb test(e2e): cover tools/call without arguments (#2933)
  • 818f782 docs: state the principles in CLAUDE.md and shorten REVIEW.md (#2938)
  • a202a36 Version Packages (#2896)
  • 2d731fa fix(client): refresh again when an SSE retry failed for a reason other than 4...
  • b6e5c55 test(e2e): cover prompts/get without arguments for prompts with a schema (#2928)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [@modelcontextprotocol/client](https://github.com/modelcontextprotocol/typescript-sdk) from 2.1.0 to 2.3.1.
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/client@2.1.0...@modelcontextprotocol/client@2.3.1)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/client"
  dependency-version: 2.3.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 6, 2026
@dependabot
dependabot Bot requested a review from irparent as a code owner October 6, 2026 17:58
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Iris gate — 1 of 2 tripped --fail-on detector_veto

iris-eval ingest: 3 stored, 1 tripped --fail-on detector_veto (2 of 3 evaluated in dataset "release-gate")

Trace Verdict Basis Rules, classes or missing inputs Evidence
91140123e8122f3958403e9f3e6d4a2e failed detector_veto + risk_over_loss no_pii, pii_leak, credential_leak no_pii: AWS Access Key (output 45–65)
Verdict basis Traces
detector_veto 2
clean 1

Unjudged questions: task_completed (3), tool_use_correct (3) — a trace that did not carry what a rule needs.

tests/fixtures/ci-gate/traces.ndjson · 3 evaluated · dataset release-gate: 2 in the gate · exit 1 · what the bases mean

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Iris gate — 1 stored, nothing tripped --fail-on any

iris-eval ingest: 1 stored, 0 tripped --fail-on any

Verdict basis Traces
clean 1

Unjudged questions: task_completed (1), tool_use_correct (1) — a trace that did not carry what a rule needs.

tests/fixtures/ci-gate/clean.ndjson · 1 evaluated · exit 0 · what the bases mean

@irparent
irparent merged commit fdc8653 into main Oct 6, 2026
71 checks passed
@irparent
irparent deleted the dependabot/npm_and_yarn/examples/otel-recipes/js/modelcontextprotocol/client-2.3.1 branch October 6, 2026 20:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant