Skip to content

chore: bump the npm-minor-patch group across 1 directory with 9 updates - #9

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-minor-patch-4dd2dea614
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-minor-patch-4dd2dea614

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown

Bumps the npm-minor-patch group with 9 updates in the / directory:

Package From To
@joplin/turndown-plugin-gfm 1.0.67 1.0.68
@modelcontextprotocol/server 2.0.0 2.1.0
@napi-rs/canvas 1.0.2 1.0.9
encoding-japanese 2.2.0 2.4.0
pdfjs-dist 6.2.108 6.3.289
zod 4.4.3 4.6.5
@modelcontextprotocol/client 2.0.0 2.1.0
@types/node 26.1.1 26.6.2
tsx 4.23.0 4.23.15

Updates @joplin/turndown-plugin-gfm from 1.0.67 to 1.0.68

Commits

Updates @modelcontextprotocol/server from 2.0.0 to 2.1.0

Release notes

Sourced from @​modelcontextprotocol/server's releases.

@​modelcontextprotocol/server-legacy@​2.1.0

Patch Changes

  • Updated dependencies [dcc0102]:
    • @​modelcontextprotocol/core@​2.1.0

@​modelcontextprotocol/server@​2.1.0

Minor Changes

  • #1624 6032170 Thanks @​SamMorrowDrums! - Add request-time OAuth scope challenges for tools, resources, resource templates, and prompts. Each primitive's scopeChallenge callback receives the parsed request and verified authentication info, then either continues or returns the exact scope set for an insufficient_scope response. requireScopes provides a small helper for static all-of checks.

    createMcpHandler and Streamable HTTP transports return HTTP 403 with an insufficient_scope challenge before handler execution or SSE setup. The preflight is active whenever a registered primitive carries a scopeChallenge callback — there is no handler- or transport-level configuration. The challenge's WWW-Authenticate header is built by the same formatter as the bearer-auth 401/403 answers, and its resource_metadata parameter is derived from the verified AuthInfo: requireBearerAuth / verifyBearerToken now stamp their configured resourceMetadataUrl onto the AuthInfo they return (new optional AuthInfo.resourceMetadataUrl field), with a fallback to the well-known location for an HTTP(S) RFC 8707 resource identifier; the parameter is omitted when neither is available.

Patch Changes

  • #2726 6fa4227 Thanks @​LuckTerence! - SdkError and SdkHttpError accept standard ErrorOptions as an optional fourth constructor argument and forward it to Error, so a wrapped error is reachable through the standard Error.cause chain. Version-negotiation probe failures (SdkErrorCode.EraNegotiationFailed) now use it: the underlying TypeError: fetch failed and the DNS or socket error beneath it surface via error.cause, so pino, Sentry, and util.inspect render ENOTFOUND / ECONNREFUSED / ETIMEDOUT instead of stopping at the SdkError (#2657). The previous error.data.cause slot is still populated for compatibility but is deprecated and slated for removal; read error.cause instead.

  • #2654 03842cd Thanks @​pshah19! - Treat request id 0 as a real id. Two guards tested a RequestId for truthiness, so the legal JSON-RPC ids 0 and '' were read as absent. Id 0 is not a corner case: the outbound request counter is zero-based, so it is the first id every peer assigns, which on the server→client leg is the first sampling/createMessage, elicitation/create, or roots/list a server sends.

    • notifications/cancelled carrying id 0 was ignored, and the in-flight handler ran to completion with its AbortSignal never fired.
    • A notification sent with relatedRequestId: 0 wrongly passed the debounce gate (for methods opted into debouncedNotificationMethods). Because the pending set is keyed by method alone, a second such notification in the same tick was silently dropped rather than sent.

    Absent is now the only value that means "no id".

  • #2668 3e90449 Thanks @​KKonstantinov! - Stop sending notifications/cancelled for the initialize handshake. The spec is explicit that a client MUST NOT attempt to cancel its initialize request, but the outbound cancel path fired for any in-flight request: aborting the AbortSignal passed to connect(), or letting the handshake hit its timeout, put a forbidden cancellation on the wire naming the initialize request id.

    The local behaviour is unchanged — the caller's promise still rejects with the same abort/timeout error, and connect() still tears the connection down. Only the wire notification is suppressed. Every other method keeps the existing cancellation path.

  • #2698 7b781ed Thanks @​maxisbey! - Read Streamable HTTP request bodies with a size limit. Every SDK-owned body read — WebStandardStreamableHTTPServerTransport (and the Node transport built on it), createMcpHandler, toNodeHandler, and createMcpHonoApp's JSON pre-parse — now stops at 4 MiB by default (the limit the legacy SSE transport already uses; the Express adapter and stdio bound their reads too) and answers 413 Payload Too Large before anything is parsed. toWebRequest (when it reads the Node stream itself) now rejects once the body exceeds the limit with an error whose name is 'RequestBodyTooLargeError' and status is 413, and toNodeHandler answers that with 413; hand-wired callers of toWebRequest should handle the rejection or pass a pre-parsed body, and isLegacyRequest reports such a request as non-legacy

... (truncated)

Commits
  • 9517506 Version Packages (#2808)
  • 6a05402 fix(server): close StdioServerTransport when stdin ends or closes (#2494)
  • c4248a9 fix(client): add missing Windows env vars to DEFAULT_INHERITED_ENV_VARS (#2043)
  • 0b403f0 chore(changesets): only bump peer dependents when out of range (#2819)
  • 6032170 feat(server): add request-time OAuth scope challenges (#1624)
  • b654261 fix(client): let OAuth-derived Authorization override caller-supplied header ...
  • 5ecc791 fix(codemod): only count real module specifiers in project-type inference (#2...
  • 5119ee7 fix: preserve exact OAuth resource indicators (#2581)
  • 6fa4227 fix(client): surface underlying network error via Error.cause on probe failur...
  • dcc0102 feat(client): add DPoP (RFC 9449) sender-constrained token support (#2629)
  • Additional commits viewable in compare view

Updates @napi-rs/canvas from 1.0.2 to 1.0.9

Release notes

Sourced from @​napi-rs/canvas's releases.

v1.0.9

What's Changed

Full Changelog: Brooooooklyn/canvas@v1.0.8...v1.0.9

v1.0.8

What's Changed

Full Changelog: Brooooooklyn/canvas@v1.0.7...v1.0.8

v1.0.7

What's Changed

Full Changelog: Brooooooklyn/canvas@v1.0.6...v1.0.7

v1.0.6

What's Changed

Full Changelog: Brooooooklyn/canvas@v1.0.5...v1.0.6

v1.0.5

What's Changed

Full Changelog: Brooooooklyn/canvas@v1.0.4...v1.0.5

v1.0.4

What's Changed

... (truncated)

Changelog

Sourced from @​napi-rs/canvas's changelog.

1.0.9 (2026-09-09)

Bug Fixes

  • deps: update cssparser to 0.38 and cssparser-color to 0.6 (#1335) (caec867)
  • invalidate FontCollection typeface cache on font registration (#1334) (9e4fbec)

Features

1.0.8 (2026-08-24)

Bug Fixes

  • capture call-time snapshot in async encode APIs (#1313) (#1323) (18c52bf)
  • snapshot canvas source in drawImage to avoid per-call pixel copy (#1325) (d98574c)

1.0.7 (2026-08-18)

Bug Fixes

  • putImageData no longer inherits transform/clip after getImageData (#1320) (8ed2b59)

Performance Improvements

  • fast getImageData readback with runtime-dispatched SIMD unpremultiply (#1319) (196bff9)

1.0.6 (2026-08-13)

Bug Fixes

1.0.5 (2026-08-09)

Bug Fixes

1.0.4 (2026-08-01)

Bug Fixes

  • shadow: restore blur rendering performance (#1305) (4dddd0d)

1.0.3 (2026-07-28)

... (truncated)

Commits
  • b2723ff 1.0.9
  • 70f3022 docs(skill): fold the m154 run experience into upgrade-skia
  • 1b3e054 docs(skill): record the m154 failure classes in upgrade-skia
  • 7257dc9 chore: add repo-level upgrade-skia skill
  • c68eea9 feat: chrome/m154 (#1337)
  • 22eb20d chore: commit Cargo.lock, build with --locked, fix the cargo cache key (#1336)
  • caec867 fix(deps): update cssparser to 0.38 and cssparser-color to 0.6 (#1335)
  • 9e4fbec fix: invalidate FontCollection typeface cache on font registration (#1334)
  • fe11ee0 ci: repair armv7 apt sources and musl builder image (#1331)
  • c7e9ac0 chore(deps): update dependency electron to v44 (#1326)
  • Additional commits viewable in compare view

Updates encoding-japanese from 2.2.0 to 2.4.0

Release notes

Sourced from encoding-japanese's releases.

2.4.0

What's Changed

Include TypeScript definitions (index.d.ts) migrated from DefinitelyTyped. Installing @types/encoding-japanese separately is no longer required. Thanks to DefinitelyTyped contributors!

Features

  • feat(types): bundle TypeScript definitions (migrated from DefinitelyTyped) in polygonplanet/encoding.js#68
    • Add index.d.ts and the "types" field to package.json
    • The definitions are imported unchanged from @types/encoding-japanese 2.2.1.
  • feat(convert): support Unicode characters that differ between CP932 and JIS X 0208 mappings when converting to SJIS, EUCJP and JIS in polygonplanet/encoding.js#67

Bug Fixes

  • Fix U+301C (〜) being mapped to JIS X 0212 instead of JIS X 0208 when converting to EUCJP and JIS (e.g., 0x8FA1C1 instead of 0xA1C1 in EUCJP) in polygonplanet/encoding.js#67
  • Fix invalid SJIS trail byte 0x7F being converted as 0x7E instead of falling back to ? on conversion from SJIS (b848595)

CI

Maintenance

Full Changelog: polygonplanet/encoding.js@2.3.0...2.4.0

2.3.0

What's Changed

Features

  • feat: add CP932 extensions in SJIS detection and conversion (#65) (Resolves #54, #22)
    • Detect CP932 extended character areas as SJIS
    • Convert CP932 IBM extended characters (0xFA40 - 0xFC4B)
    • Remap duplicate codes for CP932 NEC special characters and 0xEEF9 to their JIS X 0208 counterparts

Bug Fixes

Changes

  • Update engines.node to >=18.0.0 to match the tested versions (c6008d0)

CI

... (truncated)

Changelog

Sourced from encoding-japanese's changelog.

2.4.0 (2026-09-14)

Features

  • Include TypeScript definitions (index.d.ts) migrated from DefinitelyTyped. Installing @types/encoding-japanese separately is no longer required. Thanks to DefinitelyTyped contributors! (#68)
  • Support Unicode characters that differ between CP932 and JIS X 0208 mappings when converting to SJIS, EUCJP and JIS (e.g., U+301C (〜) is now converted to 0x8160 in SJIS and 0xA1C1 in EUCJP). (#67)

Bug Fixes

  • Fix U+301C (〜) being mapped to JIS X 0212 instead of JIS X 0208 when converting to EUCJP and JIS (e.g., 0x8FA1C1 instead of 0xA1C1 in EUCJP). (#67)
  • Fix invalid SJIS trail byte 0x7F being converted as 0x7E instead of falling back to ? on conversion from SJIS. (b848595)

CI

  • Update GitHub Actions and split linting from tests. (6142ece)

Maintenance

  • Add type tests adapted from DefinitelyTyped to run with tsc, and include them in npm test.
  • Upgrade ESLint to v10 and migrate from .eslintrc.json to flat config with @stylistic/eslint-plugin. (1e98062)

2.3.0 (2026-08-30)

Features

  • Support CP932 (Windows-31J) extended character areas in SJIS detection and conversion. (#65, #54, #22)
    • Detect CP932 extended character areas as SJIS.
    • Convert CP932 IBM extended characters (0xFA40 - 0xFC4B).
    • Remap duplicate codes for CP932 NEC special characters and 0xEEF9 to their JIS X 0208 counterparts.

Bug Fixes

  • Fix conversion of wa-row voiced kana (U+30F8 / U+30F9) in toHiraganaCase and toKatakanaCase. (#62) Thanks @​mahirhir
  • Fix EUC-JP and ISO-2022-JP encoders to use the standard JIS X 0212 forms instead of unassigned JIS X 0208 rows. (#63) Thanks @​gaoflow
  • Fix Encoding.detect to treat C0 control characters as valid UTF-8. (#64, #49) Thanks @​hiros0921

Changes

  • Update engines.node to >=18.0.0 to match the tested versions. (c6008d0)

CI

Maintenance

  • Update devDependencies and remove unused power-assert and uglifyify. (4cf36da, 1142dd9)

Documentation

... (truncated)

Commits
  • 1cbb978 feat: v2.4.0
  • 3e1aa9d docs(changelog): update changelogs
  • 1769d2f docs(readme): update badge and minor doc fixes
  • 55e882a chore(package.json): update description and keywords, remove empty dependencies
  • dc62893 Merge pull request #68 from polygonplanet/feature/add-types
  • dec226e docs(license): add third-party notice for DefinitelyTyped type definitions
  • a90f8f9 test(types): update type tests to run with tsc
  • c7e645a Import TypeScript declarations and tests from DefinitelyTyped
  • 6f542af Merge pull request #67 from polygonplanet/fix/cp932-unicode-aliases
  • b848595 fix(convert): fallback on invalid SJIS trail byte 0x7F
  • Additional commits viewable in compare view

Updates pdfjs-dist from 6.2.108 to 6.3.289

Release notes

Sourced from pdfjs-dist's releases.

v6.3.289

This release contains improvements for accessibility, annotation editing, annotation rendering, font conversion, image decoding, performance, text selection and the viewer.

Changes since v6.2.108

... (truncated)

Commits
  • 1c8020a Merge pull request #21841 from Snuffleupagus/src-core-misc-fixes
  • 67c035f Inline the PDFDocument.prototype._parseHasJSActions method
  • c58a275 Move some WorkerTask class field definitions out of the constructor
  • d1725ab Merge pull request #21837 from Snuffleupagus/rm-ColorSpace-getoutputlength
  • 159dca9 Remove the unused getOutputLength method from the ColorSpace classes (PR ...
  • 8801a6a Merge pull request #21835 from Snuffleupagus/getViewerPreferences-tests
  • 08a0600 Merge pull request #21834 from Snuffleupagus/markInfo-Map
  • 2895922 Improve unit-test coverage for the getViewerPreferences functionality
  • 16b94d1 [api-minor] Convert markInfo to return data in a Map
  • c3257df Merge pull request #21833 from mozilla/update-locales
  • Additional commits viewable in compare view

Updates zod from 4.4.3 to 4.6.5

Release notes

Sourced from zod's releases.

v4.6.5

Commits:

  • d2b135cfb7a3582b9eb515756b9166bcb9521f4a docs: add the 4.6.x patch highlights to the 4.6 post
  • f1448f7cee00df9fe1e9ad84a000aa1828cc8bc1 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • de65a5cb39ed22a507fac935788f718fa88d104f docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • 56222cd1532c07bcb91b67df529cab4c0a215330 feat(instanceof): key the .properties() shape off the instance type (#6600)
  • ca0229a404818290e6cdcfefcd7eb2d04bcbb543 Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)"
  • cc4cd4ee9c52fcaa10964e48cc144541e41a5ed9 Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)""
  • 0f3f5ee3ca56c7574bf849e54f79e9a6e02562ee 4.6.5
  • 59bbc03e10c636b9eb3c393dfeb552819774ec21 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump

v4.6.4

A patch on top of 4.6.3.

  • d6bc1e30 feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)
  • ad32d751 perf: z.url() rejects an invalid URL with URL.canParse() instead of a throwing constructor, about 50x faster; fewer allocations on the validation path (#6588)
  • 2bb08717 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • f6e1701a chore(deps): bump next to 15.5.25 and vite to 7.3.6 (#6153)

v4.6.3

A patch on top of 4.6.2.

  • 413cce9a fix(v4): make z.properties() a check again (#6594) — removes the standalone z.properties() schema from 4.6.0; z.instanceof().properties() and .check(...z.properties()) are unchanged
  • 75d63ee1 docs: show only the .properties() method form in the 4.6 post
  • 46da9572 docs: match the error-message examples to what the parsers emit

v4.6.2

A patch on top of 4.6.1.

v4.6.1

A patch on top of 4.6.0.

v4.6.0

Zod 4.6 is now available.

npm install zod@latest

At a glance:

... (truncated)

Commits
  • 59bbc03 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump
  • 0f3f5ee 4.6.5
  • cc4cd4e Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, ref...
  • ca0229a Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed w...
  • 56222cd feat(instanceof): key the .properties() shape off the instance type (#6600)
  • de65a5c docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • f1448f7 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • d2b135c docs: add the 4.6.x patch highlights to the 4.6 post
  • 2bb0871 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • 743aedb 4.6.4
  • Additional commits viewable in compare view

Updates @modelcontextprotocol/client from 2.0.0 to 2.1.0

Release notes

Sourced from @​modelcontextprotocol/client's releases.

@​modelcontextprotocol/client@​2.1.0

Minor Changes

  • #2629 dcc0102 Thanks @​gbshankar! - Add DPoP (RFC 9449 / SEP-1932) sender-constrained access token support to the client.
    • Opt in by implementing OAuthClientProvider.dpop() returning a DpopSession (new, along with generateDpopKeyPair, accessTokenHash, isDpopNonceChallenge). auth() / exchangeAuthorization / refreshAuthorization / fetchToken then sign a DPoP proof into token requests (retrying once on an authorization-server use_dpop_nonce challenge, with client authentication re-applied per attempt), and StreamableHTTPClientTransport, SSEClientTransport and withOAuth present a token_type: "DPoP" access token as Authorization: DPoP <token> plus a fresh per-request proof, retry a resource-server use_dpop_nonce challenge once, and pick up a DPoP-Nonce delivered on any response. Tokens the AS issued as Bearer are still presented as Bearer.
    • DPoP is applied at the fetch layer: the transports wrap their resource-server fetch (including a caller-supplied fetch / eventSourceInit.fetch) with the new withDpopFromProvider(provider) middleware, so proofs are always bound to the request actually sent. withDpop(session, getToken) is exported for callers that manage tokens themselves (e.g. alongside a minimal AuthProvider); the AuthProvider interface itself is unchanged.
    • auth() now recovers from invalid_dpop_proof on refresh (e.g. a refresh token bound to a key that is no longer held) by discarding the tokens and re-authorizing, like invalid_grant. OAuthErrorCode gains InvalidDpopProof and UseDpopNonce; extractWWWAuthenticateParams recognizes the DPoP challenge scheme; OAuthMetadataSchema gains dpop_signing_alg_values_supported.

Patch Changes

  • #2726 6fa4227 Thanks @​LuckTerence! - SdkError and SdkHttpError accept standard ErrorOptions as an optional fourth constructor argument and forward it to Error, so a wrapped error is reachable through the standard Error.cause chain. Version-negotiation probe failures (SdkErrorCode.EraNegotiationFailed) now use it: the underlying TypeError: fetch failed and the DNS or socket error beneath it surface via error.cause, so pino, Sentry, and util.inspect render ENOTFOUND / ECONNREFUSED / ETIMEDOUT instead of stopping at the SdkError (#2657). The previous error.data.cause slot is still populated for compatibility but is deprecated and slated for removal; read error.cause instead.

  • #2654 03842cd Thanks @​pshah19! - Treat request id 0 as a real id. Two guards tested a RequestId for truthiness, so the legal JSON-RPC ids 0 and '' were read as absent. Id 0 is not a corner case: the outbound request counter is zero-based, so it is the first id every peer assigns, which on the server→client leg is the first sampling/createMessage, elicitation/create, or roots/list a server sends.

    • notifications/cancelled carrying id 0 was ignored, and the in-flight handler ran to completion with its AbortSignal never fired.
    • A notification sent with relatedRequestId: 0 wrongly passed the debounce gate (for methods opted into debouncedNotificationMethods). Because the pending set is keyed by method alone, a second such notification in the same tick was silently dropped rather than sent.

    Absent is now the only value that means "no id".

  • #2043 c4248a9 Thanks @​ChrisJr404! - On Windows, stdio servers spawned by StdioClientTransport now also inherit COMSPEC, PATHEXT, PROGRAMDATA, PROGRAMFILES(X86), PROGRAMW6432, and WINDIR (added to DEFAULT_INHERITED_ENV_VARS). Programs a server launches can depend on them: PowerShell finds no native executables without PATHEXT, and Windows OpenSSH exits 255 without ProgramData.

  • #2668 3e90449 Thanks @​KKonstantinov! - Stop sending notifications/cancelled for the initialize handshake. The spec is explicit that a client MUST NOT attempt to cancel its initialize request, but the outbound cancel path fired for any in-flight request: aborting the AbortSignal passed to connect(), or letting the handshake hit its timeout, put a forbidden cancellation on the wire naming the initialize request id.

    The local behaviour is unchanged — the caller's promise still rejects with the same abort/timeout error, and connect() still tears the connection down. Only the wire notification is suppressed. Every other method keeps the existing cancellation path.

  • #2475

Bumps the npm-minor-patch group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@joplin/turndown-plugin-gfm](https://github.com/laurent22/joplin-turndown-plugin-gfm) | `1.0.67` | `1.0.68` |
| [@modelcontextprotocol/server](https://github.com/modelcontextprotocol/typescript-sdk) | `2.0.0` | `2.1.0` |
| [@napi-rs/canvas](https://github.com/Brooooooklyn/canvas) | `1.0.2` | `1.0.9` |
| [encoding-japanese](https://github.com/polygonplanet/encoding.js) | `2.2.0` | `2.4.0` |
| [pdfjs-dist](https://github.com/mozilla/pdf.js) | `6.2.108` | `6.3.289` |
| [zod](https://github.com/colinhacks/zod) | `4.4.3` | `4.6.5` |
| [@modelcontextprotocol/client](https://github.com/modelcontextprotocol/typescript-sdk) | `2.0.0` | `2.1.0` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.1` | `26.6.2` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.0` | `4.23.15` |



Updates `@joplin/turndown-plugin-gfm` from 1.0.67 to 1.0.68
- [Commits](https://github.com/laurent22/joplin-turndown-plugin-gfm/commits)

Updates `@modelcontextprotocol/server` from 2.0.0 to 2.1.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/server@2.0.0...@modelcontextprotocol/server@2.1.0)

Updates `@napi-rs/canvas` from 1.0.2 to 1.0.9
- [Release notes](https://github.com/Brooooooklyn/canvas/releases)
- [Changelog](https://github.com/Brooooooklyn/canvas/blob/main/CHANGELOG.md)
- [Commits](Brooooooklyn/canvas@v1.0.2...v1.0.9)

Updates `encoding-japanese` from 2.2.0 to 2.4.0
- [Release notes](https://github.com/polygonplanet/encoding.js/releases)
- [Changelog](https://github.com/polygonplanet/encoding.js/blob/master/CHANGELOG.md)
- [Commits](polygonplanet/encoding.js@2.2.0...2.4.0)

Updates `pdfjs-dist` from 6.2.108 to 6.3.289
- [Release notes](https://github.com/mozilla/pdf.js/releases)
- [Commits](mozilla/pdf.js@v6.2.108...v6.3.289)

Updates `zod` from 4.4.3 to 4.6.5
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.4.3...v4.6.5)

Updates `@modelcontextprotocol/client` from 2.0.0 to 2.1.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/client@2.0.0...@modelcontextprotocol/client@2.1.0)

Updates `@types/node` from 26.1.1 to 26.6.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `tsx` from 4.23.0 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.0...v4.23.15)

---
updated-dependencies:
- dependency-name: "@joplin/turndown-plugin-gfm"
  dependency-version: 1.0.68
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@modelcontextprotocol/server"
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@napi-rs/canvas"
  dependency-version: 1.0.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: encoding-japanese
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: pdfjs-dist
  dependency-version: 6.3.289
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@modelcontextprotocol/client"
  dependency-version: 2.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@types/node"
  dependency-version: 26.6.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants