Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

[v2] @modelcontextprotocol/server inlines fast-uri 3.1.0, which has 9 published advisories

未关闭 适合新手
#2,966 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
2/5
预计耗时
1-3 小时
新手友好度
72/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃

调研方向

从 main 上的 pnpm-lock.yaml 开始,[email protected](以及 [email protected])在此解析,找出是什么引入了它们——很可能是通过构建所用的 ajv。然后定位将它们内联到 dist/ 的打包步骤(dist/ajvProvider-*.mjs 中的 //#region ../../node_modules/.pnpm/... 注释显示了路径)。完成标准如下:fast-uri 在锁文件中解析为 3.1.8 或更高版本,新构建的 dist/ 中出现相同版本,且重新构建加上 npm pack 以及 issue 中的 grep -ho '#region ../../node_modules/.pnpm/[^/]*/' package/dist/*.mjs | sort -u 检查不再输出 [email protected];可选地,在 README 或包元数据中记录被内联的包列表。

由索引模型根据 Issue 内容生成。

描述

v2
What happened?

@modelcontextprotocol/server 2.2.0, 2.3.0, and 2.3.1 inline ajv 8.18.0 and fast-uri 3.1.0 into dist/ instead of declaring them as dependencies (their dependencies are only zod and @modelcontextprotocol/core; fast-uri is in dist/ajvProvider-*.mjs, under //#region ../../node_modules/.pnpm/[email protected]/...). pnpm-lock.yaml on main still resolves [email protected].

fast-uri 3.1.0 is affected by these advisories, all fixed in 3.1.8. All 9 are already public, and #2036 asks for the same kind of bump in v1:
GHSA-4c8g-83qw-93j6, GHSA-7p8r-x3mc-p8w7, GHSA-f65p-4m7j-42xc, GHSA-hrr3-gc8f-f4qj, GHSA-jqff-g426-hqxp, GHSA-q3j6-qgpj-74h6, GHSA-qw65-cvwx-89v3, GHSA-v2hh-gcrm-f6hx, GHSA-v39h-62p7-jpjc.

Because the code is inlined, a consumer cannot raise it with overrides or resolutions, and the inlined versions do not appear in the consumer's lockfile, so tools that read the lockfile cannot report them. In our case, moving from @modelcontextprotocol/sdk 1.x (whose ajv resolved to fast-uri 3.1.8 in our lockfile) to v2 would ship an older fast-uri than before, so we are holding the migration.

We have not checked whether any of these advisories is reachable through the SDK's use of ajv.

What did you expect?
  • A release built with fast-uri 3.1.8 or later.
  • Optionally, a list of the packages and versions inlined in dist/ (in the README or package metadata), so consumers can keep their SBOMs and third-party notices accurate.
Code to reproduce
npm pack @modelcontextprotocol/[email protected]
tar xzf modelcontextprotocol-server-2.3.1.tgz
grep -ho '#region ../../node_modules/.pnpm/[^/]*/' package/dist/*.mjs | sort -u
# prints, among others, .pnpm/[email protected]/ and .pnpm/[email protected]/
SDK version

@modelcontextprotocol/server 2.2.0, 2.3.0, 2.3.1

Area

Server

主要语言
TypeScript
星标
13.5k
派生
2.3k
平均合并
2 天 7 小时
30 天内合并 PR
54

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

modelcontextprotocol/typescript-sdk 的其他 Issue

查看 modelcontextprotocol/typescript-sdk 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。