Fix: Patch high-severity vulnerable dependency packages#114
Fix: Patch high-severity vulnerable dependency packages#114viratatwebflow merged 1 commit intomainfrom
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Summary
Patches high-severity vulnerable dependencies identified by Socket Security scan:
@modelcontextprotocol/sdk:1.21.1→1.25.2(resolvesGHSA-677m-j7p3-52f9)zod:3.24.2→3.25.76(resolvesGHSA-mw96-cpmx-2vgc)socket.io-parser:4.2.4→4.2.6(transitive, pulled in bysocket.io)rollup:4.39.0→4.59.0(transitive dev dependency, updated alongside MCP SDK upgrade)New transitive dependencies introduced by MCP SDK
1.25.2:@hono/node-server1.19.13hono4.12.12json-schema-typed8.0.2zod-to-json-schema3.25.2Test plan
Safety checklist
package-lock.jsonupdated consistently