Skip to content

chore(deps): bump the minor-and-patch group across 1 directory with 13 updates - #5933

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-165ac7e0a8
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-165ac7e0a8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 13 updates in the / directory:

Package From To
@electron/asar 4.3.0 4.3.1
@modelcontextprotocol/client 2.1.0 2.2.0
@modelcontextprotocol/sdk 1.30.1 1.31.0
@modelcontextprotocol/server 2.1.0 2.2.0
@modelcontextprotocol/server-legacy 2.0.0 2.2.0
@ai-sdk/openai 4.0.80 4.0.81
ws 8.21.3 8.22.0
@types/ws 8.18.1 8.18.2
@types/ws 8.18.1 8.18.2
@agentclientprotocol/sdk 1.5.0 1.5.1
systeminformation 5.33.13 5.33.14
virtua 0.52.7 0.52.9
opencli-mcp 0.0.22 0.0.25
simple-icons 16.32.0 16.33.0

Updates @electron/asar from 4.3.0 to 4.3.1

Release notes

Sourced from @​electron/asar's releases.

v4.3.1

4.3.1 (2026-09-26)

Bug Fixes

  • compute stream package integrity from stream content, not from the destination path (#447) (02c5b08)
Commits
  • 02c5b08 fix: compute stream package integrity from stream content, not from the desti...
  • 08d5657 build(deps-dev): upgrade vitest to v5 (#471)
  • 00dd716 build(deps-dev): bump vitest from 4.1.5 to 4.1.11 (#470)
  • aeb0af5 build(deps): bump lint-staged to 17.4.1 (#468)
  • 7002ac5 build(deps): bump brace-expansion from 5.0.8 to 5.0.9 (#467)
  • cee1398 build(deps): bump azure/login from 3.0.0 to 3.0.1 (#466)
  • See full diff in compare view

Updates @modelcontextprotocol/client from 2.1.0 to 2.2.0

Release notes

Sourced from @​modelcontextprotocol/client's releases.

@​modelcontextprotocol/client@​2.2.0

Minor Changes

  • #2887 edd12e2 Thanks @​maxisbey! - Constructing ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider or CrossAppAccessProvider without expectedIssuer is deprecated: the constructor logs one console.warn and that call signature is marked @deprecated. Behaviour is otherwise unchanged. Pass the issuer of the authorization server the credentials were registered with.

    fetchToken() throws AuthorizationServerMismatchError, before sending anything, when the provider's client information is bound to a different authorization server than the one it is called with. The AuthorizationServerMismatchError message no longer assumes the authorization-code callback; its fields are unchanged.

    OAuthTokensSchema and OAuthClientInformationSchema accept the optional issuer stamp, so a provider that reads storage back through them keeps it. auth() overwrites it on every save.

Patch Changes

  • #2885 9dd722f Thanks @​claude! - Sending a notification on a closed connection no longer produces a briefly unhandled promise rejection (seen as unhandledrejection on Cloudflare Workers) in addition to the returned rejection.

  • #2883 c0f7aec Thanks @​claude! - Fix a type-check failure for CommonJS TypeScript projects introduced in 2.1.0: dist/index.d.cts imported types from jose, which is ESM-only, so tsc with module: node16/node18 and skipLibCheck: false failed with TS1479. The two jose types used by the DPoP API (CryptoKey, JWK) are now inlined into the declaration files. No runtime change.

  • #2768 efebf5b Thanks @​web-abin! - Correct the JSDoc for insecure OAuth token endpoints. The TLS requirement comes from the MCP authorization specification's OAuth 2.1 communication-security rules, not SEP-2207, which covers OIDC-flavored refresh-token guidance. Documentation only; no runtime behavior change.

  • #2729 a4ae2f9 Thanks @​claude! - Correct the registerClient @deprecated notice: Dynamic Client Registration was deprecated by spec PR modelcontextprotocol#2858 (Client ID Metadata Documents), not SEP-2577 (which deprecates roots, sampling, and logging). The notice now also names the earliest possible removal date under the feature lifecycle policy (2027-07-28) and clarifies that the client_id_metadata_document_supported gating lives in the built-in auth() flow — registerClient called directly always sends the registration request. Documentation only; no runtime behavior change.

  • #2862 e780e13 Thanks @​SyedTashfin! - Preserve _meta on input_required results. The 2026-07-28 decode seam rebuilt the payload from inputRequests and requestState only, so result-level metadata a server sent on an input_required result (including io.modelcontextprotocol/serverInfo) was dropped before an allowInputRequired: true caller could see it. Result._meta is a result-level field, so input_required carries it exactly like any other result.

  • #2886 ef39308 Thanks @​claude! - listTools(), listPrompts(), listResources() and listResourceTemplates() called without a cursor now follow nextCursor until the server stops sending one, instead of stopping silently with a short list when a cursor repeats; a page that has the same items and the same nextCursor as the page before it ends the walk and is not added twice, and listMaxPages still caps the walk.

  • #2642 cfa09db Thanks @​claude! - Fix Client.listen() rejections escaping as process-level unhandled rejections. The internal opening promise could reject (ack timeout, transport close, server cancel, caller abort) while listen() was still serially awaiting transport.send(...), so no rejection handler was attached yet — the rejection surfaced as an unhandledRejection that caller-side handling cannot prevent, and a send that never settles (e.g. a stdio write parked on 'drain') left listen() suspended forever even though the ack timer had already fired. listen() now suspends on the opening state machine directly and routes send failures into it, so every termination path rejects the returned promise and nothing escapes.

  • #2597 7f7a94c Thanks @​arimu1! - Treat hostnames ending in .localhost as loopback for the SEP-2207 token-endpoint https guard (RFC 6761 §6.3), so host-based multi-tenant local OAuth works. The SDK does not resolve the name itself: *.localhost reaches the local machine only if the system resolver follows RFC 6761.

  • Updated dependencies [edd12e2]:

    • @​modelcontextprotocol/core@​2.2.0
Commits
  • dd22ba2 Version Packages (#2849)
  • c55efa6 fix(server): close a listen stream that has honored nothing (#2651)
  • edd12e2 fix(client): deprecate omitting expectedIssuer and apply the SEP-2352 issuer ...
  • ef39308 fix(client): follow nextCursor until it is absent; stop on a repeated page (#...
  • 9dd722f fix(core): await the notification send so a failed send is never briefly unha...
  • e780e13 fix(client): preserve _meta on input_required results (#2862)
  • a4ae2f9 docs(client): correct the registerClient deprecation citation to spec PR #285...
  • efebf5b docs(client): correct token endpoint TLS citation (#2768)
  • d992df7 chore: remove CODEOWNERS patterns that match nothing on main (#2884)
  • c0f7aec fix(client): inline jose types in the CommonJS declaration file (#2883)
  • Additional commits viewable in compare view

Updates @modelcontextprotocol/sdk from 1.30.1 to 1.31.0

Release notes

Sourced from @​modelcontextprotocol/sdk's releases.

1.31.0

Upgrade notes

  • Stored OAuth tokens and client information now include an issuer field. Storage that rejects unknown fields needs to allow it.
  • Pass expectedIssuer when constructing ClientCredentialsProvider, PrivateKeyJwtProvider or StaticPrivateKeyJwtProvider. Constructing them without it is deprecated.

What's Changed

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.1...1.31.0

Commits
  • 4b0051f chore: bump version to 1.31.0 (#2890)
  • 51ad4f0 [v1.x] Bind stored OAuth credentials to the authorization server that issued ...
  • See full diff in compare view

Updates @modelcontextprotocol/server from 2.1.0 to 2.2.0

Release notes

Sourced from @​modelcontextprotocol/server's releases.

@​modelcontextprotocol/server-legacy@​2.2.0

Patch Changes

  • Updated dependencies [edd12e2]:
    • @​modelcontextprotocol/core@​2.2.0

@​modelcontextprotocol/server@​2.2.0

Patch Changes

  • #2885 9dd722f Thanks @​claude! - Sending a notification on a closed connection no longer produces a briefly unhandled promise rejection (seen as unhandledrejection on Cloudflare Workers) in addition to the returned rejection.

  • #2778 e3fb9ed Thanks @​vjymisal0! - Fix a stack overflow in createMcpHandler when the factory returns the same server instance for more than one request. Returning a fresh instance per request is still required.

  • #2651 c55efa6 Thanks @​sushantkumar23! - createMcpHandler now ends a subscriptions/listen stream right after the acknowledgement when it honored none of the requested notification types, instead of holding the stream open with nothing to deliver. The client receives the acknowledgement and then the resultType: "complete" result. Streams that honor at least one type are unchanged.

  • Updated dependencies [edd12e2]:

    • @​modelcontextprotocol/core@​2.2.0
Commits
  • dd22ba2 Version Packages (#2849)
  • c55efa6 fix(server): close a listen stream that has honored nothing (#2651)
  • edd12e2 fix(client): deprecate omitting expectedIssuer and apply the SEP-2352 issuer ...
  • ef39308 fix(client): follow nextCursor until it is absent; stop on a repeated page (#...
  • 9dd722f fix(core): await the notification send so a failed send is never briefly unha...
  • e780e13 fix(client): preserve _meta on input_required results (#2862)
  • a4ae2f9 docs(client): correct the registerClient deprecation citation to spec PR #285...
  • efebf5b docs(client): correct token endpoint TLS citation (#2768)
  • d992df7 chore: remove CODEOWNERS patterns that match nothing on main (#2884)
  • c0f7aec fix(client): inline jose types in the CommonJS declaration file (#2883)
  • Additional commits viewable in compare view

Updates @modelcontextprotocol/server-legacy from 2.0.0 to 2.2.0

Release notes

Sourced from @​modelcontextprotocol/server-legacy's releases.

@​modelcontextprotocol/server-legacy@​2.2.0

Patch Changes

  • Updated dependencies [edd12e2]:
    • @​modelcontextprotocol/core@​2.2.0

@​modelcontextprotocol/server-legacy@​2.1.0

Patch Changes

  • Updated dependencies [dcc0102]:
    • @​modelcontextprotocol/core@​2.1.0
Commits
  • dd22ba2 Version Packages (#2849)
  • c55efa6 fix(server): close a listen stream that has honored nothing (#2651)
  • edd12e2 fix(client): deprecate omitting expectedIssuer and apply the SEP-2352 issuer ...
  • ef39308 fix(client): follow nextCursor until it is absent; stop on a repeated page (#...
  • 9dd722f fix(core): await the notification send so a failed send is never briefly unha...
  • e780e13 fix(client): preserve _meta on input_required results (#2862)
  • a4ae2f9 docs(client): correct the registerClient deprecation citation to spec PR #285...
  • efebf5b docs(client): correct token endpoint TLS citation (#2768)
  • d992df7 chore: remove CODEOWNERS patterns that match nothing on main (#2884)
  • c0f7aec fix(client): inline jose types in the CommonJS declaration file (#2883)
  • Additional commits viewable in compare view

Updates @ai-sdk/openai from 4.0.80 to 4.0.81

Changelog

Sourced from @​ai-sdk/openai's changelog.

4.0.81

Patch Changes

  • 4e94782: fix(openai): rewrite recursive Zod schemas that use allOf wrappers
Commits

Updates ws from 8.21.3 to 8.22.0

Release notes

Sourced from ws's releases.

8.22.0

Features

  • Introduced the protocols option (8b918b01).

Bug fixes

  • Calling websocket.close() with invalid arguments no longer transitions the state to WebSocket.CLOSING (#2337).
Commits
  • 297202c [dist] 8.22.0
  • 8b918b0 [feature] Introduce the protocols option
  • 73e03eb [ci] Update actions/setup-node action to v7
  • d9b8954 [fix] Change the ready state after validating the arguments (#2337)
  • See full diff in compare view

Updates @types/ws from 8.18.1 to 8.18.2

Commits

Updates @types/ws from 8.18.1 to 8.18.2

Commits

Updates @agentclientprotocol/sdk from 1.5.0 to 1.5.1

Release notes

Sourced from @​agentclientprotocol/sdk's releases.

v1.5.1

1.5.1 (2026-09-28)

Bug Fixes

  • bound incoming transport message sizes (#259) (69fda37)
  • bound per-connection memory in AcpServer (#261) (4356253)
Changelog

Sourced from @​agentclientprotocol/sdk's changelog.

1.5.1 (2026-09-28)

Bug Fixes

  • bound incoming transport message sizes (#259) (69fda37)
  • bound per-connection memory in AcpServer (#261) (4356253)
Commits

Updates systeminformation from 5.33.13 to 5.33.14

Release notes

Sourced from systeminformation's releases.

v5.33.14

Full Changelog: sebhildebrandt/systeminformation@v5.33.13...v5.33.14

Changelog

Sourced from systeminformation's changelog.

Changelog

Major Changes - Version 5

New Functions

  • audio() detailed audio information
  • bluetoothDevices() detailed information detected bluetooth devices
  • dockerImages() detailed information docker images
  • dockerVolumes() detailed information docker volumes
  • printers() detailed printer information
  • usb() detailed USB information
  • wifiInterfaces() detected Wi-Fi interfaces
  • wifiConnections() active Wi-Fi connections

Breaking Changes

Be aware, that the new version 5.x is NOT fully backward compatible to version 4.x ...

We had to make several interface changes to keep systeminformation as consistent as possible. We highly recommend to go through the complete list and adapt your own code to be again compatible to the new version 5.

Function Old New (V5) Comments
unsupported values -1 null values which are unknown orunsupported on platform
battery() hasbatterycyclecountischargingdesignedcapacitymaxcapacityacconnectedtimeremaining hasBatterycycleCountisChargingdesignedCapacitymaxCapacityacConnectedtimeRemaining pascalCase conformity
blockDevices() fstype fsType pascalCase conformity
cpu() speedminspeedmax speedMinspeedMax pascalCase conformity
cpu().speedcpu().speedMincpu().speedMax string values now returningnumerical values better value handling
cpuCurrentspeed() cpuCurrentSpeed() function name changedpascalCase conformity
currentLoad() avgloadcurrentloadcurrentload_usercurrentload_systemcurrentload_nicecurrentload_idlecurrentload_irqraw_currentload avgLoadcurrentLoadcurrentLoadUsercurrentLoadSystemcurrentLoadNicecurrentLoadIdlecurrentLoadIrqrawCurrentLoad pascalCase conformity
dockerContainerStats() mem_usagemem_limitmem_percentcpu_percentcpu_statsprecpu_statsmemory_stats memUsagememLimitmemPercentcpuPercentcpuStatsprecpuStatsmemoryStats pascalCase conformity
dockerContainerProcesses() pid_host pidHost pascalCase conformity
graphics().display pixeldepthresolutionxresolutionysizexsizey pixelDepthresolutionXresolutionYsizeXsizeY pascalCase conformity
networkConnections() localaddresslocalportpeeraddresspeerport localAddresslocalPortpeerAddresspeerPort pascalCase conformity
networkInterfaces() carrier_changes carrierChanges pascalCase conformity
processes() mem_vszmem_rsspcpupcpuupcpuspmem memVszmemRsscpucpuucpusmem pascalCase conformityrenamed attributes
processLoad() result as object result as array of objects function now allows to provide more thanone process (as a comma separated list)
services() pcpupmem cpumem renamed attributes
vbox() HPETPAEAPICX2APICACPIIOAPICbiosAPICmodeTRC hpetpaeapicx2ApicacpiioApicbiosApicModertc pascalCase conformity

Other Improvements and Changes

  • baseboard(): added memMax, memSlots
  • bios(): added language and features (linux)
  • blockDevices() added raid group member (linux)
  • cpu(): extended AMD processor list

... (truncated)

Commits
  • 6159e0a 5.33.14
  • 9c5802d docs: updated relase date 5.33.14
  • 77e8210 updated docs
  • 8d294b3 networkStats() prevent path traversal via interface name (linux)
  • 88f2fa6 use C.UTF-8 locale for commands (linux)
  • d387daa networkStats() - reject interface names starting with a dash
  • 4d3445e docs: updated v6
  • See full diff in compare view

Updates virtua from 0.52.7 to 0.52.9

Release notes

Sourced from virtua's releases.

0.52.9

What's Changed

Full Changelog: inokawa/virtua@0.52.8...0.52.9

0.52.8

What's Changed

Full Changelog: inokawa/virtua@0.52.7...0.52.8

Commits

Updates opencli-mcp from 0.0.22 to 0.0.25

Release notes

Sourced from opencli-mcp's releases.

opencli-mcp 0.0.25

  • Fix JavaScript execution on Node 26 while retaining Node 22+ support, using one V8 Inspector REPL implementation across Node 22, 24 and 26.
  • Preserve bindings after ordinary errors, correctly report falsy exceptions, and support redeclaring top-level bindings across calls.
  • Drain dispatched API work within the call timeout; handle unobserved RPC failures and prevent late callbacks from affecting later calls.
  • Validate persistent JavaScript execution through the native host and MCP, with Node 22/24/26 release checks.
  • Chrome extension remains at 0.0.18; this release changes the local host only.

Manual Chrome extension installation

Download opencli-mcp-extension-manual-install-0.0.18.zip, extract it, then open chrome://extensions, enable Developer mode, and choose Load unpacked on the extracted folder. Disable the Chrome Web Store copy first if it is installed.

opencli-mcp 0.0.24

  • Expose native Chrome APIs with on-demand signatures, direct CDP commands, and bounded event streams in the REPL.
  • Support writable Main World evaluation with frame targeting and explicit uncertain outcomes without replaying dispatched commands.
  • Add page console and extension log capture, and improve native tab/window ownership and session cleanup.
  • Add frame-aware ARIA/DOM observations and exact DOM reads across nested and cross-origin frames.
  • Ship Chrome extension 0.0.18 with updated runtime documentation and Chrome API reference attribution.

Manual Chrome extension installation

Download opencli-mcp-extension-manual-install-0.0.18.zip, extract it, then open chrome://extensions, enable Developer mode, and choose Load unpacked on the extracted folder. Disable the Chrome Web Store copy first if it is installed.

opencli-mcp 0.0.23

  • Make js the primary browser workspace with seven default MCP tools; browser actions and adapter authoring use the shared object API.
  • Use a persistent Node REPL for variables, functions, classes and top-level await, with interruptible worker execution and explicit timeout/reset/cancellation outcomes.
  • Return compact browser handles, bounded output and MCP images, and expose focused API documentation directly through docs_get.
  • Keep the adapter draft → trial → activation lifecycle and preserve action validation at the object API boundary.
  • Fix live Chrome tab identity and adapter capture during initial navigation; report host/extension protocol drift as a warning.
  • Bundle Chrome extension 0.0.17.

Migration: typed browser and adapter-authoring tools have been removed. Use js with browser, tab, tools and recon; use docs_get without arguments for the quickstart. Await every API call. Reset or timeout clears JavaScript bindings but does not undo already dispatched browser operations.

Manual Chrome extension installation

Download opencli-mcp-extension-manual-install-0.0.17.zip, extract it, then open chrome://extensions, enable Developer mode, and choose Load unpacked on the extracted folder. Disable the Chrome Web Store copy first if it is installed.

Changelog

Sourced from opencli-mcp's changelog.

0.0.25 — 2026-09-28

  • Fix JavaScript execution on Node 26 while retaining Node 22+ support, using one V8 Inspector REPL implementation across Node 22, 24 and 26.
  • Preserve bindings after ordinary errors, correctly report falsy exceptions, and support redeclaring top-level bindings across calls.
  • Drain dispatched API work within the call timeout; handle unobserved RPC failures and prevent late callbacks from affecting later calls.
  • Validate persistent JavaScript execution through the native host and MCP, with Node 22/24/26 release checks.
  • Chrome extension remains at 0.0.18; this release changes the local host only.

0.0.24 — 2026-09-28

  • Expose native Chrome APIs with on-demand signatures, direct CDP commands, and bounded event streams in the REPL.
  • Support writable Main World evaluation with frame targeting and explicit uncertain outcomes without replaying dispatched commands.
  • Add page console and extension log capture, and improve native tab/window ownership and session cleanup.
  • Add frame-aware ARIA/DOM observations and exact DOM reads across nested and cross-origin frames.
  • Ship Chrome extension 0.0.18 with updated runtime documentation and Chrome API reference attribution.

0.0.23 — 2026-09-28

  • Make js the primary browser workspace with seven default MCP tools; browser actions and adapter authoring use the shared object API.
  • Use a persistent Node REPL for variables, functions, classes and top-level await, with interruptible worker execution and explicit timeout/reset/cancellation outcomes.
  • Return compact browser handles, bounded output and MCP images, and expose focused API documentation directly through docs_get.
  • Keep the adapter draft → trial → activation lifecycle and preserve action validation at the object API boundary.
  • Fix live Chrome tab identity and adapter capture during initial navigation; report host/extension protocol drift as a warning.
  • Bundle Chrome extension 0.0.17.

Migration: typed browser and adapter-authoring tools have been removed. Use js with browser, tab, tools and recon; use docs_get without arguments for the quickstart. Await every API call. Reset or timeout clears JavaScript bindings but does not undo already dispatched browser operations.

Commits
  • 5f1edea chore: release opencli-mcp 0.0.25
  • 86745c7 fix: unify REPL execution across Node versions
  • 016ff6e chore: release opencli-mcp 0.0.24
  • 89704c1 chore: bump extension to 0.0.18
  • 56f85b0 feat: expose native Chrome APIs and event streams in the REPL
  • 63a85d6 feat: add frame-aware observations and exact DOM reads (#12)
  • 1e75e64 chore: release opencli-mcp 0.0.23
  • 0320b8f feat: make browser workflows REPL-first
  • 8d50fe6 fix: keep adapter commands bound to live Chrome tabs
  • 51096d6 fix: warn on extension protocol drift without blocking browser
  • See full diff in compare view

Updates simple-icons from 16.32.0 to 16.33.0

Release notes

Sourced from simple-icons's releases.

Release 16.33.0

1 new icon

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…3 updates

Bumps the minor-and-patch group with 13 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@electron/asar](https://github.com/electron/asar) | `4.3.0` | `4.3.1` |
| [@modelcontextprotocol/client](https://github.com/modelcontextprotocol/typescript-sdk) | `2.1.0` | `2.2.0` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.30.1` | `1.31.0` |
| [@modelcontextprotocol/server](https://github.com/modelcontextprotocol/typescript-sdk) | `2.1.0` | `2.2.0` |
| [@modelcontextprotocol/server-legacy](https://github.com/modelcontextprotocol/typescript-sdk) | `2.0.0` | `2.2.0` |
| [@ai-sdk/openai](https://github.com/vercel/ai/tree/HEAD/packages/openai) | `4.0.80` | `4.0.81` |
| [ws](https://github.com/websockets/ws) | `8.21.3` | `8.22.0` |
| [@types/ws](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/ws) | `8.18.1` | `8.18.2` |
| [@types/ws](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/ws) | `8.18.1` | `8.18.2` |
| [@agentclientprotocol/sdk](https://github.com/agentclientprotocol/typescript-sdk) | `1.5.0` | `1.5.1` |
| [systeminformation](https://github.com/sebhildebrandt/systeminformation) | `5.33.13` | `5.33.14` |
| [virtua](https://github.com/inokawa/virtua) | `0.52.7` | `0.52.9` |
| [opencli-mcp](https://github.com/jackwener/opencli-mcp) | `0.0.22` | `0.0.25` |
| [simple-icons](https://github.com/simple-icons/simple-icons) | `16.32.0` | `16.33.0` |



Updates `@electron/asar` from 4.3.0 to 4.3.1
- [Release notes](https://github.com/electron/asar/releases)
- [Changelog](https://github.com/electron/asar/blob/main/CHANGELOG.md)
- [Commits](electron/asar@v4.3.0...v4.3.1)

Updates `@modelcontextprotocol/client` from 2.1.0 to 2.2.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/client@2.1.0...@modelcontextprotocol/client@2.2.0)

Updates `@modelcontextprotocol/sdk` from 1.30.1 to 1.31.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@1.30.1...1.31.0)

Updates `@modelcontextprotocol/server` from 2.1.0 to 2.2.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/server@2.1.0...@modelcontextprotocol/server@2.2.0)

Updates `@modelcontextprotocol/server-legacy` from 2.0.0 to 2.2.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/server-legacy@2.0.0...@modelcontextprotocol/server-legacy@2.2.0)

Updates `@ai-sdk/openai` from 4.0.80 to 4.0.81
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/packages/openai/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/@ai-sdk/openai@4.0.81/packages/openai)

Updates `ws` from 8.21.3 to 8.22.0
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.21.3...8.22.0)

Updates `@types/ws` from 8.18.1 to 8.18.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/ws)

Updates `@types/ws` from 8.18.1 to 8.18.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/ws)

Updates `@agentclientprotocol/sdk` from 1.5.0 to 1.5.1
- [Release notes](https://github.com/agentclientprotocol/typescript-sdk/releases)
- [Changelog](https://github.com/agentclientprotocol/typescript-sdk/blob/main/CHANGELOG.md)
- [Commits](agentclientprotocol/typescript-sdk@v1.5.0...v1.5.1)

Updates `systeminformation` from 5.33.13 to 5.33.14
- [Release notes](https://github.com/sebhildebrandt/systeminformation/releases)
- [Changelog](https://github.com/sebhildebrandt/systeminformation/blob/master/CHANGELOG.md)
- [Commits](sebhildebrandt/systeminformation@v5.33.13...v5.33.14)

Updates `virtua` from 0.52.7 to 0.52.9
- [Release notes](https://github.com/inokawa/virtua/releases)
- [Commits](inokawa/virtua@0.52.7...0.52.9)

Updates `opencli-mcp` from 0.0.22 to 0.0.25
- [Release notes](https://github.com/jackwener/opencli-mcp/releases)
- [Changelog](https://github.com/jackwener/opencli-mcp/blob/main/CHANGELOG.md)
- [Commits](jackwener/opencli-mcp@v0.0.22...v0.0.25)

Updates `simple-icons` from 16.32.0 to 16.33.0
- [Release notes](https://github.com/simple-icons/simple-icons/releases)
- [Commits](simple-icons/simple-icons@16.32.0...16.33.0)

---
updated-dependencies:
- dependency-name: "@electron/asar"
  dependency-version: 4.3.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@modelcontextprotocol/client"
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.31.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@modelcontextprotocol/server"
  dependency-version: 2.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@modelcontextprotocol/server-legacy"
  dependency-version: 2.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@ai-sdk/openai"
  dependency-version: 4.0.81
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: ws
  dependency-version: 8.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@types/ws"
  dependency-version: 8.18.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@types/ws"
  dependency-version: 8.18.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@agentclientprotocol/sdk"
  dependency-version: 1.5.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: systeminformation
  dependency-version: 5.33.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: virtua
  dependency-version: 0.52.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: opencli-mcp
  dependency-version: 0.0.25
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: simple-icons
  dependency-version: 16.33.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 2, 2026
@github-actions github-actions Bot added the effort/S Under 100 readable lines label Oct 2, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file effort/S Under 100 readable lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants