Skip to content

feat(deps): update dependency @modelcontextprotocol/sdk (1.29.0 → 1.30.0) - #673

Merged
joryirving merged 1 commit into
mainfrom
renovate/modelcontextprotocol-sdk-1.x-lockfile
Jul 29, 2026
Merged

feat(deps): update dependency @modelcontextprotocol/sdk (1.29.0 → 1.30.0)#673
joryirving merged 1 commit into
mainfrom
renovate/modelcontextprotocol-sdk-1.x-lockfile

Conversation

@its-miso

@its-miso its-miso Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@modelcontextprotocol/sdk (source) 1.29.01.30.0 age adoption passing confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

modelcontextprotocol/typescript-sdk (@​modelcontextprotocol/sdk)

v1.30.0

Compare Source

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@v1.29.0...1.30.0


Configuration

📅 Schedule: (in timezone America/Edmonton)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@its-miso its-miso Bot added the type/minor label Jul 27, 2026
@its-miso
its-miso Bot requested a review from joryirving as a code owner July 27, 2026 18:42
@its-miso its-miso Bot added the type/minor label Jul 27, 2026

@its-saffron its-saffron Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — escalated (fast_low_confidence)

PR Review: @modelcontextprotocol/sdk 1.29.0 → 1.30.0

Recommendation

Approve. This is a low-risk minor version bump within the 1.x stable line. The upstream changelog contains only bug fixes, internal improvements, and widened dependency constraints — no API surface changes. CI has already confirmed the upgrade is compatible with this codebase.


Change Summary

The diff updates only package-lock.json, bumping @modelcontextprotocol/sdk from 1.29.0 to 1.30.0. The lockfile also reflects a widened peer dependency for @hono/node-server (^1.19.9^1.19.9 || ^2.0.5), which is a permissive change and not a regression.


Required Checks

✅ check for breaking API changes in updated dependencies

Verified by inspecting the upstream release notes and 10-commit diff for v1.29.0 → v1.30.0:

All 10 commits are patch-level fixes (confirmed by upstream's patch changeset labels) or internal tooling changes (CI, ESLint config):

  • Fix SSE keep-alive timer lifecycle in Streamable HTTP transport (patch)
  • Send SSE keep-alive comment frames to prevent intermediaries killing idle connections (patch)
  • Validate Content-Type by parsed media type instead of substring match (patch) — this is a behavioral improvement that rejects malformed Content-Type values that would have incorrectly passed before
  • Prioritize Zod error issue messages over the JSON-blob fallback (patch)
  • Support Zod 3.25 method literals (patch)
  • Widen @hono/node-server past a security advisory (patch)
  • v1 stdio buffer limit (patch)
  • End-to-end test suite and CI tooling additions

No breaking API changes. The SDK's exported interfaces, transport APIs, and client/server contracts are unchanged. One behavioral hardening note: POSTs to the Streamable HTTP server transport with non-application/json media types now correctly return 415 Unsupported Media Type — this is a correctness fix, not a regression, and CI already validated this codebase against the new version.

✅ run full test suite after upgrade

CI ran and passed all checks for commit 331fe2d:

Check Result
review success
Lint success
Tests success
Build success
Typecheck success
Docker Build success

The full test suite, typecheck, lint, and Docker build all passed. No additional testing is required.


Standards Compliance

The PR follows repository conventions:

  • Only package-lock.json was modified — no hand-editing of package.json or tsconfig.
  • The change is scoped and surgical, consistent with the project's Renovate-managed dependency upgrade workflow.
  • No secrets, credentials, or environment configurations were touched.

Unknowns / Needs Verification

None. The CI results are authoritative evidence that the upgrade integrates correctly with this codebase. The upstream release notes provide sufficient confidence that no API surface was broken. There are no linked issues to evaluate against.

@its-miso
its-miso Bot force-pushed the renovate/modelcontextprotocol-sdk-1.x-lockfile branch from 331fe2d to 802f1e2 Compare July 28, 2026 08:42
@its-miso
its-miso Bot force-pushed the renovate/modelcontextprotocol-sdk-1.x-lockfile branch from 802f1e2 to 3becd74 Compare July 29, 2026 15:42
@joryirving
joryirving merged commit 539cb05 into main Jul 29, 2026
6 checks passed
@joryirving
joryirving deleted the renovate/modelcontextprotocol-sdk-1.x-lockfile branch July 29, 2026 15:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant