-
Notifications
You must be signed in to change notification settings - Fork 4k
Security updates: upgrade @modelcontextprotocol/sdk and @reduxjs/toolkit #9498
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
Learn moreAll Green is an AI agent that automatically: ✅ Addresses code review comments ✅ Fixes failing CI checks ✅ Resolves merge conflicts |
1 similar comment
Learn moreAll Green is an AI agent that automatically: ✅ Addresses code review comments ✅ Fixes failing CI checks ✅ Resolves merge conflicts |
Learn moreAll Green is an AI agent that automatically: ✅ Addresses code review comments ✅ Fixes failing CI checks ✅ Resolves merge conflicts |
|
|
✅ Review Complete Code Review Summary |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
1 issue found across 3 files
Prompt for AI agents (all issues)
Check if these issues are valid — if so, understand the root cause of each and fix them.
<file name="core/package.json">
<violation number="1" location="core/package.json:67">
P2: Security bump incomplete: another workspace still pins @modelcontextprotocol/sdk ^1.24.0, leaving the vulnerable version in the repo</violation>
</file>
Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.
068ca88 to
88ee148
Compare
- Upgrade @modelcontextprotocol/sdk from 1.24.0 to 1.25.2 (fixes SNYK-JS-MODELCONTEXTPROTOCOLSDK-14871802 ReDoS vulnerability) - Upgrade @reduxjs/toolkit from 2.3.0 to 2.11.2 (fixes SNYK-JS-DAGRED3ES-13110069 prototype pollution vulnerability) - Update core/package-lock.json and gui/package-lock.json with latest dependencies Generated with [Continue](https://continue.dev) Co-Authored-By: Continue <[email protected]> Co-authored-by: dallin <[email protected]>
88ee148 to
6203b99
Compare

This PR consolidates security updates from PRs #9468 and #9430 with proper package lock updates.
Changes
@modelcontextprotocol/sdk upgrade (core)
core/package.json@reduxjs/toolkit upgrade (gui)
gui/package.jsonfetchBaseQueryheadersretrybehavior and request abort handlingPackage Lock Updates
✅ Updated
package-lock.jsonwith all dependency changes✅ Successfully ran
npm installto ensure all locks are in sync✅ No breaking changes expected
Testing
Related PRs
This task was co-authored by dallin and Continue.
Continue Tasks
Powered by Continue
Summary by cubic
Upgraded @modelcontextprotocol/sdk and @reduxjs/toolkit to fix security vulnerabilities and improve performance. No application code changes.
Written for commit 6203b99. Summary will update on new commits.