chore(deps): bump undici, @release-it/conventional-changelog and release-it in /mcp-server - #159
Conversation
…ase-it Bumps [undici](https://github.com/nodejs/undici) to 7.29.0 and updates ancestor dependencies [undici](https://github.com/nodejs/undici), [@release-it/conventional-changelog](https://github.com/release-it/conventional-changelog) and [release-it](https://github.com/release-it/release-it). These dependencies need to be updated together. Updates `undici` from 7.28.0 to 7.29.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v7.28.0...v7.29.0) Updates `@release-it/conventional-changelog` from 11.0.0 to 12.0.0 - [Release notes](https://github.com/release-it/conventional-changelog/releases) - [Commits](release-it/conventional-changelog@11.0.0...12.0.0) Updates `release-it` from 20.2.1 to 21.0.1 - [Release notes](https://github.com/release-it/release-it/releases) - [Changelog](https://github.com/release-it/release-it/blob/main/CHANGELOG.md) - [Commits](release-it/release-it@20.2.1...21.0.1) --- updated-dependencies: - dependency-name: undici dependency-version: 7.29.0 dependency-type: indirect - dependency-name: "@release-it/conventional-changelog" dependency-version: 12.0.0 dependency-type: direct:development - dependency-name: release-it dependency-version: 21.0.1 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
🤖 Dependabot PR Review — Automated AnalysisDependencies Changed
Build Result✅ Passed — Test Result✅ All tests passed — 407 tests across 15 files. Execution Check✅ Starts successfully — Risk AssessmentMEDIUM — All three packages are release-tooling only (devDependencies / transitive); no runtime MCP server impact. Build, tests, and startup are unaffected. However, Code Changes ProposedNone — no source or test changes required. Decision
|
Bumps undici to 7.29.0 and updates ancestor dependencies undici, @release-it/conventional-changelog and release-it. These dependencies need to be updated together.
Updates
undicifrom 7.28.0 to 7.29.0Release notes
Sourced from undici's releases.
Commits
9e38fc1Bumped v7.29.0 (#5590)d887e34fix: validate coerced header values for CRLF (#5579)33928bcfix: validate blob body content type98011a8fix(cache): harden cache directive parsing4a9dafbtest(retry): correct broken content-range fixtures in retry-handler.js1b5a531fix(retry): reject partial content length mismatch466e99dtest: cover crash on mixed unqualified and qualified private cache directives9f10f1efix: handle empty qualified private cache directive3bf91ddfix: harden cookie domain, path, and unparsed attribute validationUpdates
@release-it/conventional-changelogfrom 11.0.0 to 12.0.0Release notes
Sourced from @release-it/conventional-changelog's releases.
Commits
ee8b92eRelease 12.0.041b3201Upgrade dependencies9fa21deDocument stable prerelease promotion (resolve #152)d7cce4dUse resolved tag as recommended bump boundary (resolve #99)dbaba1cAvoid shell interpolation when staging changelogs (resolve #149)3451b9dSkip prereleases without a recommended bump (resolve #151)82f88c9Release 11.0.17481298Run tests on Node 26f3461f1Document transform override and parseCommits resolution (resolve #78, resolve...8947320Derive tag prefix from resolved tag for recommended bump (resolve #80)Updates
release-itfrom 20.2.1 to 21.0.1Release notes
Sourced from release-it's releases.
Changelog
Sourced from release-it's changelog.
... (truncated)
Commits
2a1d141Release 21.0.1a8888b4Fix regression and support --no-hooks to skip all hooks5e9c193Release 21.0.02637e8aUpdate changelog for v21c381a2dVerify GitLab server certificates by defaultdf94838Raise Node 22 requirement to 22.21ba4326fMake GitLab CA tests platform-independent52c89a7Simplify git-cliff recipe (resolve #1195)daab846Document v21 runtime requirements5c55139Refresh GitHub Actions and package preview runtimeDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.