Repository navigation
chore: version packages - #4941
Open
github-actions[bot] wants to merge 1 commit into
Open
github-actions[bot] wants to merge 1 commit into
github-actions[bot] wants to merge 1 commit into
Conversation
github-actions
Bot
force-pushed
the
changeset-release/v2/main
branch
29 times, most recently
from
October 5, 2026 05:01
f749f38 to
c2d5cc6
Compare
github-actions
Bot
force-pushed
the
changeset-release/v2/main
branch
7 times, most recently
from
October 5, 2026 05:47
57da1a3 to
feb85cb
Compare
github-actions
Bot
force-pushed
the
changeset-release/v2/main
branch
from
October 5, 2026 05:59
feb85cb to
df511dc
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and publish to npm yourself or setup this action to publish automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to v2/main, this PR will be updated.
Releases
@modelcontextprotocol/server-everything@1.0.1
Patch Changes
#5014
8ea5e05Thanks @cliffhall! - Fix the async task tools:trigger-elicitation-request-asyncnow stops polling before the 10-minute TTL it requests for the client's task runs out, instead of polling past it and failing on a task the client has expired (#4986); andtrigger-sampling-request-asyncreports the status message of a client task that is already finished when it is created, instead of "No message" (#4987).trigger-elicitation-request-asynchad the same flaw and gets the same fix.#5005
63dc92fThanks @cliffhall! - Label dynamic blob resourcesapplication/octet-stream, matching their resource template, instead oftext/plain. This applies toresources/read, theget-resource-referenceandget-resource-linkstools, and theresource-promptprompt; blob resource links are now described as "binary blob resource".#5034
6bed4c5Thanks @cliffhall! - Server instructions no longer tell every client to use tools that are registered only for clients declaring a capability; they list those tools and the capability each needs (#4792, ported from #4835).trigger-elicitation-requestandtrigger-elicitation-request-asyncare now registered only for clients that support form-mode elicitation, so a client that declared only URL-mode elicitation no longer sees tools it cannot answer (#4985).#5053
c63255aThanks @cliffhall! - Stop shipping the compiled test suite and Vitest config in the published package: the build now excludes__tests__/,*.test.ts,*.spec.tsandvitest.config.ts, as the other TypeScript servers' builds do.#5032
d4fb2f4Thanks @cliffhall! - Session resources are now tracked per server, so two sessions that create a session resource with the same name (for example viagzip-file-as-resource) no longer evict each other's resource (#4808).#5020
f7af617Thanks @cliffhall! - The HTTP+SSE transport now answers requests for sessions it cannot serve instead of leaving them hanging or failing with a 500:POST /messagefor an unknown session returns404(and400with nosessionId), andGET /sse?sessionId=…returns409for a session that already has its stream and404for an unknown one. Each carries a JSON-RPC error body.#5006
dbd1b2eThanks @cliffhall! - Streamable HTTP: answer an unknown or ended session ID with404 Not Found(carrying the request'sidon a POST) instead of400; replay only the resumed stream's events after aLast-Event-ID, and refuse an unknown one; close every open session on shutdown.#4970
c449b5eThanks @cliffhall! - Internal refactor for in-process testing, with no change in behavior: the launcher only starts a transport when run as the binary, and the stdio, SSE and Streamable HTTP transport modules export their start-up (startStdioServer,startSseServer,startStreamableHttpServer, andcreateApp()for the HTTP transports) instead of starting a server when imported.#4936
feb251dThanks @cliffhall! - The HTTP+SSE transport no longer prints "Server is running" and stays up when its port is already in use: it reports the port and exits non-zero, as Streamable HTTP does. Streamable HTTP no longer prints its listening line before that error.@modelcontextprotocol/server-filesystem@1.0.1
Patch Changes
#4970
3a63f52Thanks @cliffhall! - Internal: the server is now built by acreateServer()factory inserver.ts, andindex.tsstarts it over stdio only when run as the bin, with each server instance holding its own allowed directories. No change to the tools, their results, or how the allowed directories are resolved from arguments and Roots.#5011
d8ebdbeThanks @cliffhall! -edit_filekeeps a file's line endings: a CRLF file is written back with CRLF instead of being converted to LF. WhenoldTexthas no exact match and the whitespace-tolerant matcher is used, each replacement line now takes the indentation of the file line it replaces, shifted by its indentation relative to the matchingoldTextline, instead of only the first line being reindented.#5022
7dc802fThanks @cliffhall! -write_fileandedit_filenow overwrite an existing file in place instead of renaming a temp file over it, so the file keeps its inode, creation time (birthtime), hard links and permission bits (#4512), and an overwrite no longer fails withEPERMon Windows when another process holds the file open (#3199). A symlink swapped in after the path was validated is still refused rather than written through, now by anO_NOFOLLOWopen (on POSIX) and a check that the opened file is the one validated (on every platform). The overwrite is no longer crash-atomic. A read-only file is now refused (EACCES, orEPERMon Windows) instead of being replaced, since writing in place opens the file itself for writing.#5025
2309e08Thanks @cliffhall! - Tool calls now wait for the client's initial roots before checking paths, so a call sent right after connecting is no longer refused with "Access denied" (#3204). A server started with no directories, connected to a client without Roots support, now fails visibly: it logs the reason, closes the connection and exits with status 1, instead of staying up and refusing every call (#4992).#5030
5c04d74Thanks @cliffhall! - Every tool's input and output schema intools/listnow declares"$schema": "https://json-schema.org/draft/2020-12/schema"instead of draft-07, so clients that validate tool schemas strictly against JSON Schema 2020-12 no longer reject every tool. The schemas are otherwise unchanged.#5010
fd4dff7Thanks @cliffhall! - On Windows, a UNC share root given as an allowed directory (\\server\shareor\\server\share\) now admits the files and subdirectories under it. Before, only the share root itself was accessible and every path below it was refused. Sibling shares such as\\server\share-evilare still refused.#5009
f621c75Thanks @cliffhall! - Paths that differ from the names on disk only in Unicode form now resolve (#1970). An NFC spelling of an allowed directory whose name is stored NFD (macOS "Capture d’écran", Japanese dakuten) is no longer refused as outside the allowed directories, and a request that spells a U+202F or U+00A0 in a name as a plain space (the macOS screenshot "Screenshot … at 2.40.40 PM.png") finds the file instead of failing with ENOENT. The exact spelling still wins when it exists, and a name matching two entries is refused as ambiguous.@modelcontextprotocol/server-memory@1.0.1
Patch Changes
#5008
bb8aa6fThanks @cliffhall! -create_entitiesnow reports the entities it skipped because their name already exists (or repeats earlier in the same call): the structured result lists them in a new optionalskippedarray, a second text item names them and points toadd_observations, and the tool description says so. Skipped entities are still not created and their observations are still not added (#4887).#4970
a8127baThanks @cliffhall! - Build the server with an exportedcreateServer()factory and start stdio only when the package is run as a program, so importing the module no longer starts a server. Behavior over stdio is unchanged.#5037
7be08e9Thanks @cliffhall! - Two server processes sharing one memory file no longer silently discard each other's writes: every write tool now holds an exclusive lock file (<memory file>.lock) while it reads, changes and saves the graph, and a lock left by a crashed server is recovered automatically (#4797).#4937
478db6aThanks @cliffhall! - Internal:ensureMemoryFilePathaccepts the directory its default files live in, so the server's tests no longer write into the package directory. No change to how the server chooses or migrates its memory file.#5035
2b1305fThanks @cliffhall! - Lines in the memory file that the server cannot read (malformed JSON, an entity or relation that fails validation, an unknown record type) are no longer deleted by the next write. They are still left out of the graph, and are now written back unchanged after the graph's own lines.#5053
c63255aThanks @cliffhall! - Stop shipping the compiled test helperdist/__tests__/helpers.jsin the published package: the build now excludes everything under__tests__/, not just*.test.ts.#5013
819ae90Thanks @cliffhall! - Saving the knowledge graph keeps the memory file's permission bits (an operator's0600no longer comes back0644), and a write to a read-only memory file now fails withEACCESinstead of silently replacing it (#4827).@modelcontextprotocol/server-sequential-thinking@1.0.1
Patch Changes
#5015
8a4139cThanks @cliffhall! - Advertise thesequentialthinkingtool asreadOnlyHint: falseandidempotentHint: false. Every call appends to the server's thought history, and a call with bothbranchFromThoughtandbranchIdalso appends to that branch, so the tool was never read-only or idempotent.destructiveHintandopenWorldHintstayfalse. (#4721)#4970
86806ccThanks @cliffhall! - Build the server with an exportedcreateServer()factory and attach stdio only whenindex.jsruns as the binary, so the server can be tested in-process. No change to the tool, its schemas or its results.#5031
bc52d0eThanks @cliffhall! - The thought log on stderr no longer prints "undefined" in its headers: a revision with norevisesThoughtreads "Revision N/M", and a branch with nobranchIdreads "(from thought N)" with no ID. The box border is sized from the header's visible text, so colour escape codes no longer make it wider than its text.#5053
c63255aThanks @cliffhall! - Stop shipping the compiled test helperdist/__tests__/helpers.jsin the published package: the build now excludes everything under__tests__/, not just*.test.ts.#5036
b5c5cccThanks @cliffhall! - AbranchIdthat names anObject.prototypekey, such as"constructor"or"__proto__", now creates and lists its branch like any other id instead of failing the call. A call that fails no longer adds its thought to the history first, sothoughtHistoryLengthcounts only thoughts that were accepted.