Skip to content

Commit 66c6da7

Browse files
authored
security: dependabot alert triage (#2768)
- Upgrade @modelcontextprotocol/sdk to 1.24.3 - Override jws to 3.2.3
1 parent 7fba9e9 commit 66c6da7

File tree

4 files changed

+49
-20
lines changed

4 files changed

+49
-20
lines changed
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"trigger.dev": patch
3+
---
4+
5+
Upgrade @modelcontextprotocol/sdk to 1.24.3

package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -90,7 +90,8 @@
9090
"form-data@^4": "4.0.4",
9191
"[email protected]": ">=1.12.0",
9292
"js-yaml@>=3.0.0 <3.14.2": "3.14.2",
93-
"js-yaml@>=4.0.0 <4.1.1": "4.1.1"
93+
"js-yaml@>=4.0.0 <4.1.1": "4.1.1",
94+
"jws@<3.2.3": "3.2.3"
9495
},
9596
"onlyBuiltDependencies": [
9697
"@depot/cli",

packages/cli-v3/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -83,7 +83,7 @@
8383
"dependencies": {
8484
"@clack/prompts": "0.11.0",
8585
"@depot/cli": "0.0.1-cli.2.80.0",
86-
"@modelcontextprotocol/sdk": "^1.17.0",
86+
"@modelcontextprotocol/sdk": "^1.24.0",
8787
"@opentelemetry/api": "1.9.0",
8888
"@opentelemetry/api-logs": "0.203.0",
8989
"@opentelemetry/exporter-trace-otlp-http": "0.203.0",

pnpm-lock.yaml

Lines changed: 41 additions & 18 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)