Repository navigation
MCP-25: Upgrade the MCP SDK and proxy-addr past new advisories - #21
Merged
Merged
Conversation
The Security workflow's audit gate fails on develop: two advisories published after the allowlist's 2026-10-01 review hit the locked @modelcontextprotocol/sdk 1.30.0 (GHSA-6qxp-vccf-f47h) and proxy-addr 2.0.7 (GHSA-jqcg-44mw-7w3h), which express pulls in through the SDK. Both have fixed releases inside the ranges their parents accept, so they are upgraded rather than waived: the SDK to ^1.32.1 and proxy-addr to 2.0.8. The gate passes and all offline suites stay green. The lockfile's own version field also catches up to 2.6.0. Fixes MCP-25: https://linear.app/gravitykit/issue/MCP-25/security-audit-gate-fails-on-develop-new-advisories-on-the-mcp-sdk-and
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Upgrades
@modelcontextprotocol/sdkandproxy-addrpast two new advisories, so the Security workflow passes ondevelopagain. Needs a check that the SDK minor bump is acceptable.Fixes MCP-25
What was wrong
scripts/audit-gate.mjsfails on an untouchedorigin/developcheckout, so every pull request intodevelopshows a red Security check. It reports two production advisories that came out after the allowlist's 2026-10-01 review:@modelcontextprotocol/sdk1.30.0, high, GHSA-6qxp-vccf-f47h: the SDK's OAuth client could send credentials to an authorization server chosen by the MCP server.proxy-addr2.0.7, critical, GHSA-jqcg-44mw-7w3h: IP spoofing through an IPv4-mapped IPv6 trust subnet. Reached throughexpress, part of the SDK's HTTP transport.What changed
@modelcontextprotocol/sdk^1.30.0to^1.32.1(locked 1.32.1).proxy-addr2.0.7 to 2.0.8 in the lockfile, inside the rangeexpressalready accepts.package.json.[Unreleased].Upgraded rather than allowlisted. The SDK is code this server runs, and the allowlist's own rule puts live packages in upgrades or
overrides, never in waivers.proxy-addrsits on the unused HTTP transport and could have been waived, but a patch release inside the accepted range removes the question.Tests
node scripts/audit-gate.mjs: exit 1 onorigin/develop, exit 0 on this branch ("No unexpected production advisories").npm ci:test:unit,test:node(787 passed, 0 failed),test:field-validation,test:views,test:tools,lint:package,lint:docsall exit 0. No test touches a live site.Blast radius
Users get this once a new
@gravitykit/mcpversion is published; this PR does not publish.This was 🤖 Generated
Summary by CodeRabbit
Bug Fixes
Documentation