Skip to content

build(deps): bump @modelcontextprotocol/client from 2.2.0 to 2.3.0 in /ui - #3431

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/ui/modelcontextprotocol/client-2.3.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/ui/modelcontextprotocol/client-2.3.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @modelcontextprotocol/client from 2.2.0 to 2.3.0.

Release notes

Sourced from @​modelcontextprotocol/client's releases.

@​modelcontextprotocol/client@​2.3.0

Minor Changes

  • #2901 433eb41 Thanks @​claude! - The HTTP client transports and the OAuth client helpers now follow a redirect only when it stays within the origin of the request (same scheme, host and port, or http to https on the same host with default ports) and keeps the method (a 307 or 308, or any redirect of a GET). Any other redirect is not followed. A transport then fails the request with an error that names the target; the session is kept and later messages still send. OAuth metadata discovery moves on to the next well-known URL, and any other OAuth request fails with an error that gives the status. Same-origin redirects that keep the method keep working on Node, up to five in a row, and no code changes are needed there. If your endpoint redirects to another origin, configure the transport with the URL it redirects to. A requestInit.redirect of 'error' or 'manual' is passed to fetch as it is for the requests a transport sends to the server (POST, GET and DELETE of the Streamable HTTP transport, POST of the SSE transport); for its OAuth requests, and for any other value, requestInit.redirect is not consulted by default. Browsers do not expose the target of a redirect to a page, so there a redirected request fails instead of being followed. Setting redirectPolicy: 'follow' on a transport leaves its redirects to the fetch implementation, as before this change.

Patch Changes

  • #2599 5238fba Thanks @​freya0926! - A server can now serve, and a client can now call, tasks/get and tasks/cancel of the Tasks extension (SEP-2663) on a 2026-07-28 connection, when the handler is registered and the request is sent with an explicit schema. Every other method that a protocol revision removed is still refused. If one server factory serves both eras and such a handler is meant for 2025-era clients only, register it only when ctx.era === 'legacy'.

  • #2846 63c0fca Thanks @​Sthreal! - Receiving a large message as a single SSE event over Streamable HTTP, such as a tool result of tens of megabytes, is now fast: a 50 MB result that took about 13 seconds arrives in under a second. The client now requires eventsource-parser 3.0.8 or later. SSEClientTransport reads through the eventsource package and gets the same speed-up once that also resolves eventsource-parser 3.0.8 or later.

  • #2908 633dd3e Thanks @​claude! - The license field of the package manifests is now Apache-2.0; the LICENSE file shipped in each package carries the full terms, including the MIT text for earlier contributions. No code change.

  • #2903 e765b3b Thanks @​claude! - With versionNegotiation in 'auto' or pin mode, a server/discover probe answered with a 2xx that carries no usable reply (a body that is not JSON under application/json, a bare 204, a missing or unaccepted content type) still rejects connect() with EraNegotiationFailed; an empty SSE stream or a 202 surfaces as the probe timeout instead. The message now says the server answered with an unusable reply (...) instead of reading like a network failure. To connect to a 2025 server behind a front that answers the probe this way, pass connect(transport, { prior: { kind: 'legacy' } }) or use mode: 'legacy'.

  • #2905 c0cd01a Thanks @​claude! - SSEClientTransport now retries the SSE connection once after onUnauthorized() resolves, as documented. If the retry is also answered with 401, start() rejects with SdkHttpError (ClientHttpAuthentication) instead of calling onUnauthorized() again. A 401 on a later reconnect of a stream that had opened still gets one refresh.

  • Updated dependencies [633dd3e]:

    • @​modelcontextprotocol/core@​2.3.0
Commits
  • a202a36 Version Packages (#2896)
  • 2d731fa fix(client): refresh again when an SSE retry failed for a reason other than 4...
  • b6e5c55 test(e2e): cover prompts/get without arguments for prompts with a schema (#2928)
  • 40f8f4e feat(server): add expectedResource to the bearer-token check (#2929)
  • 6d8dbc6 feat(server): add maxToolInputElements option to limit the number of elements...
  • 2fc49ea fix(server): accept prompts/get requests that omit arguments (#2107)
  • 63c0fca fix(client): update eventsource-parser for large SSE responses (#2846)
  • 84804c2 fix(server): refuse a second connect and stateless transport reuse (#2918)
  • e16d277 docs: close idle sessions and cap the session map in the sessions guide and e...
  • 433eb41 fix(client): follow redirects only within the origin of the request (#2901)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 6, 2026 13:45
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026
Bumps [@modelcontextprotocol/client](https://github.com/modelcontextprotocol/typescript-sdk) from 2.2.0 to 2.3.0.
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/client@2.2.0...@modelcontextprotocol/client@2.3.0)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/client"
  dependency-version: 2.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/ui/modelcontextprotocol/client-2.3.0 branch from e92683f to 5b4913d Compare October 6, 2026 22:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants