Skip to content

Version Packages - #2

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
changeset-release/main
Open

Version Packages#2
github-actions[bot] wants to merge 1 commit into
mainfrom
changeset-release/main

Conversation

@github-actions

@github-actions github-actions Bot commented Dec 21, 2025

Copy link
Copy Markdown

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and publish to npm yourself or setup this action to publish automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@modelcontextprotocol/client@2.0.1

Patch Changes

  • #2654 03842cd Thanks @pshah19! - Treat request id 0 as a real id. Two guards tested a RequestId for truthiness, so the legal JSON-RPC ids 0 and '' were read as absent. Id 0 is not a corner case: the outbound request counter is zero-based, so it is the first id every peer assigns, which on the server→client leg is the first sampling/createMessage, elicitation/create, or roots/list a server sends.

    • notifications/cancelled carrying id 0 was ignored, and the in-flight handler ran to completion with its AbortSignal never fired.
    • A notification sent with relatedRequestId: 0 wrongly passed the debounce gate (for methods opted into debouncedNotificationMethods). Because the pending set is keyed by method alone, a second such notification in the same tick was silently dropped rather than sent.

    Absent is now the only value that means "no id".

  • #2668 3e90449 Thanks @KKonstantinov! - Stop sending notifications/cancelled for the initialize handshake. The spec is explicit that a client MUST NOT attempt to cancel its initialize request, but the outbound cancel path fired for any in-flight request: aborting the AbortSignal passed to connect(), or letting the handshake hit its timeout, put a forbidden cancellation on the wire naming the initialize request id.

    The local behaviour is unchanged — the caller's promise still rejects with the same abort/timeout error, and connect() still tears the connection down. Only the wire notification is suppressed. Every other method keeps the existing cancellation path.

  • Updated dependencies []:

    • @modelcontextprotocol/core@2.0.1

@modelcontextprotocol/server@2.0.1

Patch Changes

  • #2654 03842cd Thanks @pshah19! - Treat request id 0 as a real id. Two guards tested a RequestId for truthiness, so the legal JSON-RPC ids 0 and '' were read as absent. Id 0 is not a corner case: the outbound request counter is zero-based, so it is the first id every peer assigns, which on the server→client leg is the first sampling/createMessage, elicitation/create, or roots/list a server sends.

    • notifications/cancelled carrying id 0 was ignored, and the in-flight handler ran to completion with its AbortSignal never fired.
    • A notification sent with relatedRequestId: 0 wrongly passed the debounce gate (for methods opted into debouncedNotificationMethods). Because the pending set is keyed by method alone, a second such notification in the same tick was silently dropped rather than sent.

    Absent is now the only value that means "no id".

  • #2668 3e90449 Thanks @KKonstantinov! - Stop sending notifications/cancelled for the initialize handshake. The spec is explicit that a client MUST NOT attempt to cancel its initialize request, but the outbound cancel path fired for any in-flight request: aborting the AbortSignal passed to connect(), or letting the handshake hit its timeout, put a forbidden cancellation on the wire naming the initialize request id.

    The local behaviour is unchanged — the caller's promise still rejects with the same abort/timeout error, and connect() still tears the connection down. Only the wire notification is suppressed. Every other method keeps the existing cancellation path.

  • #2590 75dc7ea Thanks @davidpavlovschi! - Reject a modern (2026-07-28) POST that omits the required MCP-Protocol-Version header.

    createMcpHandler accepted a request whose body carried a valid per-request _meta
    envelope but whose MCP-Protocol-Version header was absent: the request was classified
    modern, dispatched, and answered 200 — tool handlers ran. Only the mismatch case
    (header present, disagreeing with the body) was rejected, so of the standard headers
    SEP-2243 requires on a modern POST, presence was enforced for Mcp-Method (and for
    Mcp-Name on the methods that mirror params.name / params.uri) but not for
    MCP-Protocol-Version.

    Such a request is now refused with 400 Bad Request and JSON-RPC -32020
    (HeaderMismatch), matching the shape the sibling missing-header cells already emit and
    echoing the request id — per the Streamable HTTP spec, which requires the header on every
    POST and lists a missing required standard header as a HeaderMismatch failure. The
    spec's allowance to treat a header-less request as 2025-03-26 is available only to a
    server that also serves pre-2025-06-18 clients, and permits routing it to legacy
    handling — never serving it as 2026-07-28; under legacy: 'reject' the requirement is
    unconditional.

    Era classification is deliberately unchanged and stays body-primary: a proxy that strips
    the header still must not change the era, so such a request is still classified modern
    and is refused one rung later, at standard-header-validation — the same rung that
    already answers a missing Mcp-Method. Legacy-era traffic is untouched, notifications
    are unaffected, body-less GET / DELETE session operations are method-routed before
    any header validation, and stdio serving (which has no HTTP headers) is not involved.

    Clients built with this SDK always send the header, so no first-party client is affected;
    hand-rolled clients that omitted it must add it.

  • Updated dependencies []:

    • @modelcontextprotocol/core@2.0.1

@modelcontextprotocol/server-legacy@2.0.1

Patch Changes

  • Updated dependencies []:
    • @modelcontextprotocol/core@2.0.1

@modelcontextprotocol/codemod@2.0.1

@modelcontextprotocol/core@2.0.1

@modelcontextprotocol/core-internal@2.0.1

Patch Changes

  • #2654 03842cd Thanks @pshah19! - Treat request id 0 as a real id. Two guards tested a RequestId for truthiness, so the legal JSON-RPC ids 0 and '' were read as absent. Id 0 is not a corner case: the outbound request counter is zero-based, so it is the first id every peer assigns, which on the server→client leg is the first sampling/createMessage, elicitation/create, or roots/list a server sends.

    • notifications/cancelled carrying id 0 was ignored, and the in-flight handler ran to completion with its AbortSignal never fired.
    • A notification sent with relatedRequestId: 0 wrongly passed the debounce gate (for methods opted into debouncedNotificationMethods). Because the pending set is keyed by method alone, a second such notification in the same tick was silently dropped rather than sent.

    Absent is now the only value that means "no id".

  • #2668 3e90449 Thanks @KKonstantinov! - Stop sending notifications/cancelled for the initialize handshake. The spec is explicit that a client MUST NOT attempt to cancel its initialize request, but the outbound cancel path fired for any in-flight request: aborting the AbortSignal passed to connect(), or letting the handshake hit its timeout, put a forbidden cancellation on the wire naming the initialize request id.

    The local behaviour is unchanged — the caller's promise still rejects with the same abort/timeout error, and connect() still tears the connection down. Only the wire notification is suppressed. Every other method keeps the existing cancellation path.

  • #2590 75dc7ea Thanks @davidpavlovschi! - Reject a modern (2026-07-28) POST that omits the required MCP-Protocol-Version header.

    createMcpHandler accepted a request whose body carried a valid per-request _meta
    envelope but whose MCP-Protocol-Version header was absent: the request was classified
    modern, dispatched, and answered 200 — tool handlers ran. Only the mismatch case
    (header present, disagreeing with the body) was rejected, so of the standard headers
    SEP-2243 requires on a modern POST, presence was enforced for Mcp-Method (and for
    Mcp-Name on the methods that mirror params.name / params.uri) but not for
    MCP-Protocol-Version.

    Such a request is now refused with 400 Bad Request and JSON-RPC -32020
    (HeaderMismatch), matching the shape the sibling missing-header cells already emit and
    echoing the request id — per the Streamable HTTP spec, which requires the header on every
    POST and lists a missing required standard header as a HeaderMismatch failure. The
    spec's allowance to treat a header-less request as 2025-03-26 is available only to a
    server that also serves pre-2025-06-18 clients, and permits routing it to legacy
    handling — never serving it as 2026-07-28; under legacy: 'reject' the requirement is
    unconditional.

    Era classification is deliberately unchanged and stays body-primary: a proxy that strips
    the header still must not change the era, so such a request is still classified modern
    and is refused one rung later, at standard-header-validation — the same rung that
    already answers a missing Mcp-Method. Legacy-era traffic is untouched, notifications
    are unaffected, body-less GET / DELETE session operations are method-routed before
    any header validation, and stdio serving (which has no HTTP headers) is not involved.

    Clients built with this SDK always send the header, so no first-party client is affected;
    hand-rolled clients that omitted it must add it.

  • Updated dependencies []:

    • @modelcontextprotocol/core@2.0.1

@github-actions
github-actions Bot force-pushed the changeset-release/main branch from c4cef99 to 631250f Compare December 24, 2025 06:28
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 3 times, most recently from de5f0c3 to 38a94f4 Compare January 14, 2026 07:06
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 4 times, most recently from f402e81 to 98aa891 Compare January 23, 2026 08:40
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 3 times, most recently from 3bdc3fd to da3f07c Compare January 29, 2026 08:08
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 4 times, most recently from 3ed5d14 to d3065ed Compare February 7, 2026 07:59
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 4 times, most recently from c758c4c to 9ce9a06 Compare February 18, 2026 09:15
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 3 times, most recently from 307e9d3 to c089c80 Compare February 25, 2026 09:07
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 3 times, most recently from 4036f55 to c0ac63b Compare March 5, 2026 08:26
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 3 times, most recently from 0c6e599 to 53f40a7 Compare March 13, 2026 08:22
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 2 times, most recently from ce83af3 to d349e69 Compare March 16, 2026 07:09
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 5 times, most recently from f09a192 to 74bcc12 Compare March 28, 2026 09:34
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 74bcc12 to e7722ca Compare March 31, 2026 09:07
@github-actions github-actions Bot changed the title Version Packages Version Packages (alpha) Apr 1, 2026
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 2 times, most recently from f1cf569 to c4f04f6 Compare April 3, 2026 08:44
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 3 times, most recently from d7efb65 to 960d68c Compare May 23, 2026 09:58
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 3 times, most recently from c80fcfa to df8b6d4 Compare June 4, 2026 09:48
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 4 times, most recently from ab65bba to 2c15b18 Compare June 17, 2026 09:55
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 2c15b18 to 4b56324 Compare June 27, 2026 08:39
@github-actions github-actions Bot changed the title Version Packages (alpha) Version Packages (beta) Jul 3, 2026
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 3 times, most recently from 9785eca to 0db7676 Compare July 8, 2026 08:40
@github-actions
github-actions Bot force-pushed the changeset-release/main branch 2 times, most recently from 1ac49d1 to fdc9492 Compare July 21, 2026 09:01
@github-actions github-actions Bot changed the title Version Packages (beta) Version Packages Aug 17, 2026
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from fdc9492 to c018b10 Compare August 17, 2026 04:57
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from c018b10 to 01af9d7 Compare August 18, 2026 09:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants