chore(deps): bump mcp from 1.26.0 to 1.28.1 in the uv group across 1 directory#173
chore(deps): bump mcp from 1.26.0 to 1.28.1 in the uv group across 1 directory#173dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the uv group with 1 update in the / directory: [mcp](https://github.com/modelcontextprotocol/python-sdk). Updates `mcp` from 1.26.0 to 1.28.1 - [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases) - [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md) - [Commits](modelcontextprotocol/python-sdk@v1.26.0...v1.28.1) --- updated-dependencies: - dependency-name: mcp dependency-version: 1.28.1 dependency-type: indirect dependency-group: uv ... Signed-off-by: dependabot[bot] <support@github.com>
Security Scan ResultsASH Security Scan Report
Scan Metadata
SummaryScanner ResultsThe table below shows findings by scanner, with status based on severity thresholds and dependencies:
Top 7 HotspotsFiles with the highest number of security findings:
Detailed FindingsShow 19 actionable findingsFinding 1: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
Description: Code Snippet: Finding 2: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
Description: Code Snippet: Finding 3: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
Description: Code Snippet: Finding 4: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
Description: Code Snippet: Finding 5: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
Description: Code Snippet: Finding 6: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
Description: Code Snippet: Finding 7: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
Description: Code Snippet: Finding 8: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
Description: Code Snippet: Finding 9: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
Description: Code Snippet: Finding 10: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
Description: Code Snippet: Finding 11: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
Description: Code Snippet: Finding 12: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
Description: Code Snippet: Finding 13: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
Description: Code Snippet: Finding 14: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
Description: Code Snippet: Finding 15: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
Description: Code Snippet: Finding 16: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
Description: Code Snippet: Finding 17: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
Description: Code Snippet: Finding 18: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
Description: Code Snippet: Finding 19: package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown
Description: Code Snippet: Report generated by Automated Security Helper (ASH) at 2026-07-16T21:05:46+00:00 |
Bumps the uv group with 1 update in the / directory: mcp.
Updates
mcpfrom 1.26.0 to 1.28.1Release notes
Sourced from mcp's releases.
... (truncated)
Commits
777b8d0[v1.x] Support TransportSecuritySettings in the WebSocket server transport (#...4720467[v1.x] Set Development Status classifier to Production/Stable (#2976)6df3d73[v1.x] Buffer per-request StreamableHTTP streams; store priming event before ...32d3290[v1.x] Pass a list to parametrize in test_docs_examples (pytest 9.1.0 compat)...0dca751[v1.x] Deflake the child process cleanup tests (#2839)52258a9[v1.x] Add a v2 status banner to the README (#2835)b8f4917[v1.x] Deprecate the WebSocket transport and the experimental tasks entry poi...2309e5efix: omit null optional fields from task result payloads (#2809)494eb11[v1.x] Support Python 3.14 (#2769)6213787[v1.x] Scope experimental tasks to the session that created them (#2720)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.