fix(node): widen @hono/node-server past GHSA-frvp-7c67-39w9 - #2574
fix(node): widen @hono/node-server past GHSA-frvp-7c67-39w9#2574ANcpLua wants to merge 1 commit into
Conversation
🦋 Changeset detectedLatest commit: 88fcc8b The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
@modelcontextprotocol/client
@modelcontextprotocol/codemod
@modelcontextprotocol/core
@modelcontextprotocol/server
@modelcontextprotocol/server-legacy
@modelcontextprotocol/express
@modelcontextprotocol/fastify
@modelcontextprotocol/hono
@modelcontextprotocol/node
commit: |
192ab2c to
185a02f
Compare
The runtimeServerOnly catalog pinned ^1.19.9, which cannot reach the advisory's fix (2.0.5; no patched 1.x exists). Widen to ^1.19.9 || ^2.0.5, matching the range merged for v1.x in modelcontextprotocol#2549 and shipped in 1.30.0 — that fix landed on a branch without changesets, so it could not propagate to the v2 monorepo. The lockfile resolution moves to 2.0.11, as the v1.x change did. getRequestListener is the only imported symbol and keeps the same signature and contract in 2.x; @hono/node-server@2 requires Node >= 20, which @modelcontextprotocol/node already declares. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
185a02f to
88fcc8b
Compare
|
One question for maintainers rather than a change request: is the It mirrors #2549, where it had a concrete job — v1.x declares If consistency with the v1.x range is the priority, this PR as-is is that. If closing the vulnerable resolution path matters more, I'm happy to narrow the catalog to |
Closes #2548, closes #2531 — the v1.x half shipped in 1.30.0 via #2549; this is the
mainhalf.What
Widen
@hono/node-serverfrom^1.19.9to^1.19.9 || ^2.0.5— the same range #2549 merged for v1.x — and move the lockfile resolution to 2.0.11, as that change did. Onmainthe range lives in theruntimeServerOnlycatalog inpnpm-workspace.yaml; that one line feeds@modelcontextprotocol/nodeand the examples. A changeset is included (patch on@modelcontextprotocol/node).Why a separate PR
#2549 merged to
v1.x, which doesn't version through changesets, so the fix structurally cannot propagate to the v2 monorepo:@modelcontextprotocol/node@2.0.0still declares^1.19.9, and GHSA-frvp-7c67-39w9 (Windows-only path traversal inserve-staticvia encoded backslash, moderate severity; fixed in 2.0.5, no patched 1.x exists) remains unreachable for every v2 consumer. #2548 covers why npm's suggested downstream remediation is unusable.Why 2.x is safe here
getRequestListeneris the only symbol@modelcontextprotocol/nodeimports (packages/middleware/node/src/streamableHttp.ts:12); it keeps the same signature and contract in 2.x (the implementation behind it was reworked upstream — the tests covering the affected disconnect and backpressure paths pass), and the.entry's exports are a superset of 1.x's (2.x adds the WebSocket API). What 2.x does change: the./vercelsubpath is removed, and declarations ship as.d.mts/.d.ctsonly (no plain.d.ts), withtypesnested per condition — nothing in this repo uses either, and there are no type-only imports from the package anywhere in the workspace.serve(19 files); they compile and build against 2.0.11 —pnpm -r typecheckandpnpm -r buildboth exit 0.@modelcontextprotocol/nodealready declaresengines.node >= 20— exactly@hono/node-server@2's floor, so the engines conflict discussed on the issue for v1.x does not arise onmain.serve-staticmodule is never imported by the package or the examples.Verification
pnpm install --frozen-lockfileexits 0; the lockfile diff contains only the@hono/node-serverentries.pnpm -r buildandpnpm -r typecheck(all packages + examples): exit 0.pnpm --filter @modelcontextprotocol/node test: 97 passed, 2 failed — the same two SSE tests (should handle batch request messages with SSE stream for responses,should store and replay MCP server tool notifications) fail identically on unmodifiedmainwith@hono/node-server@1.19.11in my environment (Node 26.5.0, macOS), so the delta from this change is zero.pnpm audit: the branch still reports GHSA-frvp-7c67-39w9 once, viaexamples/cli-client → @google/genai → @modelcontextprotocol/sdk@1.29.0— the published v1 SDK from before fix(deps): widen @hono/node-server past GHSA-frvp-7c67-39w9 #2549. That transitive path is outside this PR's reach and clears when@google/genaimoves to 1.30.0.🤖 Generated with Claude Code