Skip to content

build(deps): bump @modelcontextprotocol/node from 2.0.0 to 2.1.0 - #10

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/modelcontextprotocol/node-2.1.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/modelcontextprotocol/node-2.1.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown

Bumps @modelcontextprotocol/node from 2.0.0 to 2.1.0.

Release notes

Sourced from @​modelcontextprotocol/node's releases.

@​modelcontextprotocol/node@​2.1.0

Minor Changes

  • #1624 6032170 Thanks @​SamMorrowDrums! - Add request-time OAuth scope challenges for tools, resources, resource templates, and prompts. Each primitive's scopeChallenge callback receives the parsed request and verified authentication info, then either continues or returns the exact scope set for an insufficient_scope response. requireScopes provides a small helper for static all-of checks.

    createMcpHandler and Streamable HTTP transports return HTTP 403 with an insufficient_scope challenge before handler execution or SSE setup. The preflight is active whenever a registered primitive carries a scopeChallenge callback — there is no handler- or transport-level configuration. The challenge's WWW-Authenticate header is built by the same formatter as the bearer-auth 401/403 answers, and its resource_metadata parameter is derived from the verified AuthInfo: requireBearerAuth / verifyBearerToken now stamp their configured resourceMetadataUrl onto the AuthInfo they return (new optional AuthInfo.resourceMetadataUrl field), with a fallback to the well-known location for an HTTP(S) RFC 8707 resource identifier; the parameter is omitted when neither is available.

Patch Changes

  • #2698 7b781ed Thanks @​maxisbey! - Read Streamable HTTP request bodies with a size limit. Every SDK-owned body read — WebStandardStreamableHTTPServerTransport (and the Node transport built on it), createMcpHandler, toNodeHandler, and createMcpHonoApp's JSON pre-parse — now stops at 4 MiB by default (the limit the legacy SSE transport already uses; the Express adapter and stdio bound their reads too) and answers 413 Payload Too Large before anything is parsed. toWebRequest (when it reads the Node stream itself) now rejects once the body exceeds the limit with an error whose name is 'RequestBodyTooLargeError' and status is 413, and toNodeHandler answers that with 413; hand-wired callers of toWebRequest should handle the rejection or pass a pre-parsed body, and isLegacyRequest reports such a request as non-legacy so the modern handler answers it. JSON-RPC batch arrays are limited to 100 messages; a longer batch is answered 400 / -32600 and none of it is dispatched.

    The limit is configurable with a new maxRequestBodySize option (bytes, default DEFAULT_MAX_REQUEST_BODY_SIZE = 4 MiB, exported from @modelcontextprotocol/server) on WebStandardStreamableHTTPServerTransportOptions, CreateMcpHandlerOptions (forwarded to its stateless legacy leg; isLegacyRequest and legacyStatelessFallback take the same option), CreateMcpHonoAppOptions, and ToNodeHandlerOptions / ToWebRequestOptions (the adapter's bound applies before the handler's, so raise both). The bounded reader is exported as readRequestBody for adapter authors. Hosts that pre-parse the body and pass it as parsedBody skip the SDK's read and its size limit entirely; the batch bound applies either way.

    createMcpHonoApp and createMcpExpressApp now run their Host/Origin validation before the JSON body parser, so a request from a disallowed Host or Origin with an invalid JSON body is answered 403 rather than 400, and its body is not read.

  • Updated dependencies [6fa4227, 03842cd, 3e90449, 7b781ed, 75dc7ea, 6032170, 6a05402, 70de0c8]:

    • @​modelcontextprotocol/server@​2.1.0
Commits
  • 9517506 Version Packages (#2808)
  • 6a05402 fix(server): close StdioServerTransport when stdin ends or closes (#2494)
  • c4248a9 fix(client): add missing Windows env vars to DEFAULT_INHERITED_ENV_VARS (#2043)
  • 0b403f0 chore(changesets): only bump peer dependents when out of range (#2819)
  • 6032170 feat(server): add request-time OAuth scope challenges (#1624)
  • b654261 fix(client): let OAuth-derived Authorization override caller-supplied header ...
  • 5ecc791 fix(codemod): only count real module specifiers in project-type inference (#2...
  • 5119ee7 fix: preserve exact OAuth resource indicators (#2581)
  • 6fa4227 fix(client): surface underlying network error via Error.cause on probe failur...
  • dcc0102 feat(client): add DPoP (RFC 9449) sender-constrained token support (#2629)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@modelcontextprotocol/node](https://github.com/modelcontextprotocol/typescript-sdk) from 2.0.0 to 2.1.0.
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/node@2.0.0...@modelcontextprotocol/node@2.1.0)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/node"
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 2, 2026
@dependabot
dependabot Bot requested a review from autoantohaki as a code owner October 2, 2026 02:34
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants