Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

[v2] @modelcontextprotocol/server inlines fast-uri 3.1.0, which has 9 published advisories

Offen Anfängerfreundlich
#2,966 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 1 Tag

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
2/5
Geschätzter Aufwand
1-3 Stunden
Anfängerfreundlichkeit
72/100
Issue-Typ
Bug
Klarheit
Klar beschrieben
Aktivitätsstatus
Aktiv
Tech-Stack
node.js, typescript

Rechercherichtung

Beginne bei pnpm-lock.yaml auf main, wo [email protected] (und [email protected]) aufgelöst werden, und finde heraus, was sie hineinzieht — vermutlich über ajv, das vom Build verwendet wird. Dann lokalisiere den Bundling-Schritt, der sie in dist/ einbettet (die Kommentare //#region ../../node_modules/.pnpm/... in dist/ajvProvider-*.mjs zeigen die Pfade). Fertig bedeutet: fast-uri wird im Lockfile auf 3.1.8 oder neuer aufgelöst, dieselbe Version erscheint in einem frisch gebauten dist/, und ein Rebuild plus npm pack + die Prüfung mit grep -ho '#region ../../node_modules/.pnpm/[^/]*/' package/dist/*.mjs | sort -u aus dem Issue gibt [email protected] nicht mehr aus; optional die Liste der eingebetteten Pakete in README oder Paketmetadaten dokumentieren.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

v2
What happened?

@modelcontextprotocol/server 2.2.0, 2.3.0, and 2.3.1 inline ajv 8.18.0 and fast-uri 3.1.0 into dist/ instead of declaring them as dependencies (their dependencies are only zod and @modelcontextprotocol/core; fast-uri is in dist/ajvProvider-*.mjs, under //#region ../../node_modules/.pnpm/[email protected]/...). pnpm-lock.yaml on main still resolves [email protected].

fast-uri 3.1.0 is affected by these advisories, all fixed in 3.1.8. All 9 are already public, and #2036 asks for the same kind of bump in v1:
GHSA-4c8g-83qw-93j6, GHSA-7p8r-x3mc-p8w7, GHSA-f65p-4m7j-42xc, GHSA-hrr3-gc8f-f4qj, GHSA-jqff-g426-hqxp, GHSA-q3j6-qgpj-74h6, GHSA-qw65-cvwx-89v3, GHSA-v2hh-gcrm-f6hx, GHSA-v39h-62p7-jpjc.

Because the code is inlined, a consumer cannot raise it with overrides or resolutions, and the inlined versions do not appear in the consumer's lockfile, so tools that read the lockfile cannot report them. In our case, moving from @modelcontextprotocol/sdk 1.x (whose ajv resolved to fast-uri 3.1.8 in our lockfile) to v2 would ship an older fast-uri than before, so we are holding the migration.

We have not checked whether any of these advisories is reachable through the SDK's use of ajv.

What did you expect?
  • A release built with fast-uri 3.1.8 or later.
  • Optionally, a list of the packages and versions inlined in dist/ (in the README or package metadata), so consumers can keep their SBOMs and third-party notices accurate.
Code to reproduce
npm pack @modelcontextprotocol/[email protected]
tar xzf modelcontextprotocol-server-2.3.1.tgz
grep -ho '#region ../../node_modules/.pnpm/[^/]*/' package/dist/*.mjs | sort -u
# prints, among others, .pnpm/[email protected]/ and .pnpm/[email protected]/
SDK version

@modelcontextprotocol/server 2.2.0, 2.3.0, 2.3.1

Area

Server

Vorherrschende Sprache
TypeScript
Sterne
13.5k
Forks
2.3k
Ø Merge
2 T. 7 Std.
Gemergte PRs (30 T.)
53

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus modelcontextprotocol/typescript-sdk

Alle Issues in modelcontextprotocol/typescript-sdk

Ähnliche Issues

Weitere Issues zu TypeScript

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.