Skip to content

MCP-25: Upgrade the MCP SDK and proxy-addr past new advisories - #21

Merged
zackkatz merged 1 commit into
developfrom
feature/mcp-25-audit-sdk-proxy-addr
Oct 10, 2026
Merged

zackkatz merged 1 commit into
developfrom
feature/mcp-25-audit-sdk-proxy-addr

Conversation

@zackkatz

@zackkatz zackkatz commented Oct 10, 2026 •

Copy link
Copy Markdown
Member

Upgrades @modelcontextprotocol/sdk and proxy-addr past two new advisories, so the Security workflow passes on develop again. Needs a check that the SDK minor bump is acceptable.

Fixes MCP-25

What was wrong

scripts/audit-gate.mjs fails on an untouched origin/develop checkout, so every pull request into develop shows a red Security check. It reports two production advisories that came out after the allowlist's 2026-10-01 review:

  • @modelcontextprotocol/sdk 1.30.0, high, GHSA-6qxp-vccf-f47h: the SDK's OAuth client could send credentials to an authorization server chosen by the MCP server.
  • proxy-addr 2.0.7, critical, GHSA-jqcg-44mw-7w3h: IP spoofing through an IPv4-mapped IPv6 trust subnet. Reached through express, part of the SDK's HTTP transport.

What changed

  • @modelcontextprotocol/sdk ^1.30.0 to ^1.32.1 (locked 1.32.1).
  • proxy-addr 2.0.7 to 2.0.8 in the lockfile, inside the range express already accepts.
  • The lockfile's own version field moves from 2.5.0 to 2.6.0 to match package.json.
  • Changelog entry under [Unreleased].

Upgraded rather than allowlisted. The SDK is code this server runs, and the allowlist's own rule puts live packages in upgrades or overrides, never in waivers. proxy-addr sits on the unused HTTP transport and could have been waived, but a patch release inside the accepted range removes the question.

Tests

  • node scripts/audit-gate.mjs: exit 1 on origin/develop, exit 0 on this branch ("No unexpected production advisories").
  • After a clean npm ci: test:unit, test:node (787 passed, 0 failed), test:field-validation, test:views, test:tools, lint:package, lint:docs all exit 0. No test touches a live site.

Blast radius

  • Touches: two dependency versions. No source change.
  • Used by: this package only.
  • Risk: Contained. The SDK moves two minor versions; the server's stdio transport, tool listing and lifecycle tests pass on it.

Users get this once a new @gravitykit/mcp version is published; this PR does not publish.

This was 🤖 Generated

Summary by CodeRabbit

  • Bug Fixes

    • Updated the MCP integration and address handling components to versions containing security updates.
  • Documentation

    • Added an Unreleased changelog entry summarizing the security updates.

The Security workflow's audit gate fails on develop: two advisories
published after the allowlist's 2026-10-01 review hit the locked
@modelcontextprotocol/sdk 1.30.0 (GHSA-6qxp-vccf-f47h) and
proxy-addr 2.0.7 (GHSA-jqcg-44mw-7w3h), which express pulls in
through the SDK.

Both have fixed releases inside the ranges their parents accept, so
they are upgraded rather than waived: the SDK to ^1.32.1 and
proxy-addr to 2.0.8. The gate passes and all offline suites stay
green. The lockfile's own version field also catches up to 2.6.0.

Fixes MCP-25: https://linear.app/gravitykit/issue/MCP-25/security-audit-gate-fails-on-develop-new-advisories-on-the-mcp-sdk-and
@linear-code

linear-code Bot commented Oct 10, 2026

Copy link
Copy Markdown

MCP-25

@coderabbitai

coderabbitai Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Review in Change Stack →Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: a2f6e276-cb9b-4747-a63f-5c30d3a6668c

📥 Commits

Reviewing files that changed from the base of the PR and between 3344097 and 867ea9b.


⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json

📒 Files selected for processing (2)
  • CHANGELOG.md
  • package.json

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 2 reviews per hour.



Walkthrough

The MCP SDK dependency range changed to ^1.32.1. The Unreleased changelog records security updates for the MCP SDK and proxy-addr.

Changes

Security dependency update

Layer / File(s) Summary
SDK dependency and changelog update
package.json, CHANGELOG.md
The MCP SDK dependency range changed from ^1.30.0 to ^1.32.1. The Unreleased changelog records security updates to the MCP SDK and proxy-addr.

Priority: ⬆️ High

Estimated code review effort: 1 (Trivial) | ~3 minutes

Merge Risk: ⚪ Minimal · up to 867ea

The security dependency update is ready to merge.

Pre-merge checks | Passed 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly identifies the main change: upgrading the MCP SDK and proxy-addr to address security advisories.
Docstring Coverage Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.


✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@zackkatz
zackkatz merged commit 7de5375 into develop Oct 10, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant