Skip to content

build(deps): bump @modelcontextprotocol/sdk from 1.30.0 to 1.31.0 in /examples/think - #199

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/examples/think/modelcontextprotocol/sdk-1.31.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/examples/think/modelcontextprotocol/sdk-1.31.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @modelcontextprotocol/sdk from 1.30.0 to 1.31.0.

Release notes

Sourced from @鈥媘odelcontextprotocol/sdk's releases.

1.31.0

Upgrade notes

  • Stored OAuth tokens and client information now include an issuer field. Storage that rejects unknown fields needs to allow it.
  • Pass expectedIssuer when constructing ClientCredentialsProvider, PrivateKeyJwtProvider or StaticPrivateKeyJwtProvider. Constructing them without it is deprecated.

What's Changed

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.1...1.31.0

1.30.1

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.0...1.30.1

Commits
  • 4b0051f chore: bump version to 1.31.0 (#2890)
  • 51ad4f0 [v1.x] Bind stored OAuth credentials to the authorization server that issued ...
  • 289ac2c chore: bump version to 1.30.1 (#2848)
  • 12b4256 fix(auth): preserve resource URI without trailing slash (#1968) (#1972)
  • a9f6eb7 [v1.x] fix(server): read HTTP request bodies with a size limit and bound JSON...
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026
@changeset-bot

changeset-bot Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

鈿狅笍 No Changeset found

Latest commit: 64b7639

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

Devin Review

"@cloudflare/think": "^0.15.1",
"@modelcontextprotocol/client": "2.0.0",
"@modelcontextprotocol/sdk": "1.30.0",
"@modelcontextprotocol/sdk": "1.31.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃敶 Clean installs fail across the workspace

After @modelcontextprotocol/sdk changes to 1.31.0, npm ci rejects the unchanged root lockfile. The lockfile still pins 1.30.0 for the think workspace, so CI stops before any checks run.

Learn more

The root lockfile records both the think workspace's dependency and its installed SDK version as 1.30.0. CI runs npm ci through Install dependencies, which requires the lockfile to match every workspace manifest. This version change makes that install fail in every CI job before the build and typecheck steps.

Example: A clean checkout runs npm ci at the repository root. It finds 1.31.0 in the think manifest but only 1.30.0 in the lockfile and exits instead of installing dependencies.

Recommended fix: Regenerate and commit the root package-lock.json for the updated workspace dependency, then verify npm ci succeeds from a clean checkout.

Devin Review


Was this helpful? React with 馃憤 or 馃憥 to provide feedback.

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Checks failing on this update: dofs, rpc, computer, computerd, example/artifacts, example/assets, example/container, example/container-legacy, example/mcp, example/pi-ai, example/tanstack-ai, example/think, example/think-compare-runtimes, example/tutorial, example/worker-javascript and example/worker-shell. The one annotation I read (dofs) only says "Process completed with exit code 1.", with no further detail. The same checks pass on the latest commit of main (33299d2), so the update or its base likely caused the failures. A maintainer should look at the job logs.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/examples/think/modelcontextprotocol/sdk-1.31.0 branch from 69fb737 to 3b856c0 Compare October 7, 2026 14:54
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Fifteen checks failed on this update: computer, rpc, dofs, computerd, example/tutorial, example/mcp, example/container-legacy, example/artifacts, example/worker-shell, example/pi-ai, example/container, example/tanstack-ai, example/think, example/think-compare-runtimes, example/assets and example/worker-javascript. The annotation I read (computer) only says "Process completed with exit code 1.", with no further detail. The latest commit on main (154ca10) doesn't run these checks (only CodeQL), so I can't tell whether the update caused the failures. A maintainer should look at the job logs.

Bumps [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) from 1.30.0 to 1.31.0.
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@1.30.0...1.31.0)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.31.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/examples/think/modelcontextprotocol/sdk-1.31.0 branch from 3b856c0 to 64b7639 Compare October 9, 2026 11:20
@aron-cf aron-cf closed this Oct 9, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/examples/think/modelcontextprotocol/sdk-1.31.0 branch October 9, 2026 11:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant