Skip to content

chore(deps): Bump the compatible-updates group across 1 directory with 2 updates - #117

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/main/compatible-updates-91afedee37
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/main/compatible-updates-91afedee37

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown

Bumps the compatible-updates group with 2 updates in the / directory: @composio/core and @modelcontextprotocol/sdk.

Updates @composio/core from 0.19.0 to 0.21.0

Release notes

Sourced from @​composio/core's releases.

@​composio/core@​0.21.0

Minor Changes

  • 461c6c3: Add experimental premiumUsage support when creating and updating Tool Router Sessions.
  • 0833c1b: Expose hostedAccount.allowedToolSlugs on session.search() toolkit connection statuses for toolkits served by a Composio hosted account.
  • de5e3f6: Add experimental support for saved Session configs. composio.sessionConfigs.list() and composio.sessionConfigs.get() read the project's saved sc_… configs, and experimental.sessionConfigId on composio.sessions.create() starts a session from one. Combining sessionConfigId with inline access fields now fails before any request: on create with toolkits, tools, tags, experimental.customTools or experimental.customToolkits, and on session.update() with toolkits, tools or tags (including null). TypeScript reports the mix at compile time and the SDK throws ValidationError at runtime; other invalid inputs keep throwing ZodError. session.experimental.sourceSessionConfig exposes the last config applied to the session after create(), sessions.use() and update(). A 409 while update() applies a config now says that the session or the config changed and to re-fetch and retry, instead of reporting a stale version.

Patch Changes

  • 3721d04: Validate the server-supplied mount path before RemoteFile.save() turns it into a filename. A mountRelativePath of "", ".", "sub/.", "foo/.." or ".." made the default save path equal the download directory or its parent, which surfaced as an unhandled EISDIR from writeFileSync after the directory had already been created. These now throw a ValidationError naming the offending mount path, before any mkdir or write. An explicit path passed by the caller is unaffected.

    The new safeBasename helper applies the filename safety checks used by the Python SDK: both / and \ count as separators, and NUL or control characters, Windows-reserved characters and device names, trailing spaces or dots, invalid Unicode and names over 128 UTF-8 bytes are rejected. RemoteFile.filename now also splits on both separators, so a Windows-style mount path reduces to the same display name on every platform.

    Drive-relative paths such as C:report.txt reduce to report.txt. Whitespace stripping follows Python rules, preserving U+FEFF. Both SDKs also reject trailing dots exposed by stripping Unicode whitespace.

  • 5ec0bdf: Validate the default destination in RemoteFile.save() before downloading content. Invalid mount paths now raise ValidationError without a network request, even when the download would fail.

  • de5e3f6: Remove experimental annotations from the top-level Session config read methods. Applying a config and reading its source metadata remain under experimental.

  • 5d07582: session.update() no longer sends expected_config_version by default. Since 0.20.0 it sent the session's last observed configVersion on every call, and the API rejects that field with a 400 (Unrecognized key(s) in object: 'expected_config_version'), so every default update() failed. The default is now last writer wins. Pass expectedConfigVersion (for example session.configVersion) to make an update conditional where the API supports it; expectedConfigVersion: false is the same as omitting it.

@​composio/core@​0.20.0

Minor Changes

  • a4a40a1: Fix project API key resolution so the SDK never sends a Composio user API key (uak_..., as stored by composio login) as the x-api-key project credential. When that stored key is the only candidate, the constructor now throws a redacted ComposioAPIKeyKindError that explains the mismatch instead of making requests that fail with 401. apiKey: null now disables project-key authentication entirely, including the COMPOSIO_API_KEY and ~/.composio/user_data.json fallbacks, and is accepted when the instance holds another credential: userApiKey or orgApiKey (explicit or from their environment variables), or an x-user-api-key entry in defaultHeaders. Requests then carry only that credential. Malformed or unexpectedly shaped user config files produce a diagnostic that names the file without echoing its contents, and cloned instances keep the credential they were resolved with instead of re-reading the environment. Code that resolves the key with apiKey: process.env.COMPOSIO_API_KEY ?? null (or any expression that yields null when the variable is unset) is affected: it used to fall back to the environment and the CLI config file and now throws unless another credential is configured; omit apiKey (or pass undefined) to keep the fallbacks. With apiKey: null, an x-api-key entry in defaultHeaders is rejected as well, including on createSession() clones: pass the project key as apiKey instead of a raw header.

  • 6c56b73: Add userApiKey and orgApiKey to ComposioConfig. Both are forwarded to the underlying API client, which sends each one only on operations whose security scheme requires it (organization, consumer, and user-scoped endpoints reached through getClient()), never alongside the project key. They fall back to COMPOSIO_USER_API_KEY and COMPOSIO_ORG_API_KEY. A project apiKey is still required unless it is set to null, which opts into user-only authentication.

  • 6c56b73: Expose the rest of the owned client surface on the Composio class:

    • composio.webhooks.subscriptions (list, get, set, update, delete, rotateSecret, listEventTypes) and composio.webhooks.endpoints (list, get, create, replace, update). composio.triggers.setWebhookSubscription() now delegates to the same upsert as webhooks.subscriptions.set(). Its behaviour for well-formed API responses is unchanged; malformed responses are now rejected with a ValidationError instead of being read leniently.
    • composio.logs.search() and composio.logs.get() for tool-execution logs.
    • composio.connectedAccounts.revoke(), which surfaces the API's 400/409 as ComposioConnectedAccountRevocationNotSupportedError / ComposioConnectedAccountNotRevokableError. connectedAccounts.refresh() is marked @deprecated (the endpoint is deprecated upstream).
    • composio.toolkits.getMany(slugs) and composio.toolkits.changelog().
    • session.listConfigHistory() on sessions.
    • composio.experimental.usage.summary() and composio.experimental.usage.breakdown() (experimental, shape may change).
    • composio.toolkits.recommendScopes(toolkitSlug, { tools, ... }) and composio.toolkits.listGrantContexts(toolkitSlug) for OAuth scope recommendations (the API marks both beta).
    • composio.connectedAccounts.completeAuth({ userId, sessionUri }), which completes a deferred OAuth connection after your OAuth callback verifier has confirmed the user's identity.
    • composio.keyring.listTransferKeys(), which returns the public JWKs of the organization's customer-managed keyring.
    • composio.experimental.customToolkits (upsert, sync, delete) for project-owned custom toolkits (in pilot, shape may change).
    • CIMD_OAUTH joins AuthSchemeTypes.
    • triggers.listActive() returns {} for state and triggerConfig when the API sends null.
    • ToolkitAuthField gains userVisible (from user_visible) and ToolkitAuthConfigDetails gains requiredScopes (from required_scopes), both omitted when the API does not send them.
    • @composio/client moves from the old autogenerated client to the new handrolled client. The API removed validate_credentials from the connected-account refresh, so connectedAccounts.refresh() now ignores validateCredentials and logs a warning when it is set.
    • logger and logLevel options on new Composio({...}). logger accepts any { error, warn, info, debug } sink (console, pino, winston, ...) and receives the SDK's formatted, credential-redacted output; logLevel ('silent' | 'error' | 'warn' | 'info' | 'debug') overrides COMPOSIO_LOG_LEVEL. The owned client's runtime deprecation warnings (response Deprecation/Sunset headers and deprecated request inputs) are now routed through that SDK logger instead of console. The client's per-request lifecycle logs are emitted only at 'debug'. tools.get/getRawComposioTools send the API's query parameter in place of the deprecated search wire parameter; the SDK's public search option is unchanged.
  • a4a40a1: Sessions now export their MCP config from the auth context the session request was actually made with: the project key as x-api-key when one is configured, otherwise the user API key (userApiKey or the x-user-api-key default header) as x-user-api-key, plus x-org-id / x-project-id when the instance is scoped. No other default header and no ambient COMPOSIO_API_KEY is ever copied. The headers are only attached when the MCP URL shares the origin of the configured API base URL (whatever its scheme). Any other destination (a different origin, an opaque origin such as a data: URL, or a URL that does not parse) never receives them: with mcp: true, create() / use() throw ComposioMCPDestinationError, which names both origins and never includes a key; without mcp: true the session is returned with session.mcp.headers empty and a warning naming both origins is logged, so native tools keep working. The SDK never connects to the MCP URL itself and does not follow redirects for it. Trigger subscriptions (Pusher channel auth) follow the same rule instead of falling back to the environment when the project key is disabled.

    ComposioConfig gains orgId and projectId: the organization and consumer project nano IDs, sent together as the x-org-id / x-project-id headers on every request and with the session MCP config. They may also be supplied through defaultHeaders; a half-configured or disagreeing scope throws ComposioScopeConfigError. Without a scope, a user API key keeps addressing the API default project.

    session.update() now sends the session's last observed configVersion as the expected_config_version precondition by default and never retries that request, so a concurrent change surfaces as ComposioSessionConfigConflictError (HTTP 409; re-fetch the session, then retry) while the local session object stays unchanged. Pass expectedConfigVersion to send another version or expectedConfigVersion: false to opt out (last writer wins). Every policy block (toolkits, tools, tags, authConfigs, connectedAccounts, preload, manageConnections, multiAccount, search, execute, experimental) accepts null to remove the stored override, manageConnections.callbackUrl: null removes only the stored callback URL, multiAccount.maxAccountsPerToolkit: null removes the stored maximum, and an empty toolkit allowlist (toolkits: []) is sent as-is so it denies every app toolkit.

  • 6c56b73: Replace the old autogenerated @composio/client with the new handrolled client.

Changelog

Sourced from @​composio/core's changelog.

0.21.0

Minor Changes

  • 461c6c3: Add experimental premiumUsage support when creating and updating Tool Router Sessions.
  • 0833c1b: Expose hostedAccount.allowedToolSlugs on session.search() toolkit connection statuses for toolkits served by a Composio hosted account.
  • de5e3f6: Add experimental support for saved Session configs. composio.sessionConfigs.list() and composio.sessionConfigs.get() read the project's saved sc_… configs, and experimental.sessionConfigId on composio.sessions.create() starts a session from one. Combining sessionConfigId with inline access fields now fails before any request: on create with toolkits, tools, tags, experimental.customTools or experimental.customToolkits, and on session.update() with toolkits, tools or tags (including null). TypeScript reports the mix at compile time and the SDK throws ValidationError at runtime; other invalid inputs keep throwing ZodError. session.experimental.sourceSessionConfig exposes the last config applied to the session after create(), sessions.use() and update(). A 409 while update() applies a config now says that the session or the config changed and to re-fetch and retry, instead of reporting a stale version.

Patch Changes

  • 3721d04: Validate the server-supplied mount path before RemoteFile.save() turns it into a filename. A mountRelativePath of "", ".", "sub/.", "foo/.." or ".." made the default save path equal the download directory or its parent, which surfaced as an unhandled EISDIR from writeFileSync after the directory had already been created. These now throw a ValidationError naming the offending mount path, before any mkdir or write. An explicit path passed by the caller is unaffected.

    The new safeBasename helper applies the filename safety checks used by the Python SDK: both / and \ count as separators, and NUL or control characters, Windows-reserved characters and device names, trailing spaces or dots, invalid Unicode and names over 128 UTF-8 bytes are rejected. RemoteFile.filename now also splits on both separators, so a Windows-style mount path reduces to the same display name on every platform.

    Drive-relative paths such as C:report.txt reduce to report.txt. Whitespace stripping follows Python rules, preserving U+FEFF. Both SDKs also reject trailing dots exposed by stripping Unicode whitespace.

  • 5ec0bdf: Validate the default destination in RemoteFile.save() before downloading content. Invalid mount paths now raise ValidationError without a network request, even when the download would fail.

  • de5e3f6: Remove experimental annotations from the top-level Session config read methods. Applying a config and reading its source metadata remain under experimental.

  • 5d07582: session.update() no longer sends expected_config_version by default. Since 0.20.0 it sent the session's last observed configVersion on every call, and the API rejects that field with a 400 (Unrecognized key(s) in object: 'expected_config_version'), so every default update() failed. The default is now last writer wins. Pass expectedConfigVersion (for example session.configVersion) to make an update conditional where the API supports it; expectedConfigVersion: false is the same as omitting it.

0.20.0

Minor Changes

  • a4a40a1: Fix project API key resolution so the SDK never sends a Composio user API key (uak_..., as stored by composio login) as the x-api-key project credential. When that stored key is the only candidate, the constructor now throws a redacted ComposioAPIKeyKindError that explains the mismatch instead of making requests that fail with 401. apiKey: null now disables project-key authentication entirely, including the COMPOSIO_API_KEY and ~/.composio/user_data.json fallbacks, and is accepted when the instance holds another credential: userApiKey or orgApiKey (explicit or from their environment variables), or an x-user-api-key entry in defaultHeaders. Requests then carry only that credential. Malformed or unexpectedly shaped user config files produce a diagnostic that names the file without echoing its contents, and cloned instances keep the credential they were resolved with instead of re-reading the environment. Code that resolves the key with apiKey: process.env.COMPOSIO_API_KEY ?? null (or any expression that yields null when the variable is unset) is affected: it used to fall back to the environment and the CLI config file and now throws unless another credential is configured; omit apiKey (or pass undefined) to keep the fallbacks. With apiKey: null, an x-api-key entry in defaultHeaders is rejected as well, including on createSession() clones: pass the project key as apiKey instead of a raw header.

  • 6c56b73: Add userApiKey and orgApiKey to ComposioConfig. Both are forwarded to the underlying API client, which sends each one only on operations whose security scheme requires it (organization, consumer, and user-scoped endpoints reached through getClient()), never alongside the project key. They fall back to COMPOSIO_USER_API_KEY and COMPOSIO_ORG_API_KEY. A project apiKey is still required unless it is set to null, which opts into user-only authentication.

  • 6c56b73: Expose the rest of the owned client surface on the Composio class:

    • composio.webhooks.subscriptions (list, get, set, update, delete, rotateSecret, listEventTypes) and composio.webhooks.endpoints (list, get, create, replace, update). composio.triggers.setWebhookSubscription() now delegates to the same upsert as webhooks.subscriptions.set(). Its behaviour for well-formed API responses is unchanged; malformed responses are now rejected with a ValidationError instead of being read leniently.
    • composio.logs.search() and composio.logs.get() for tool-execution logs.
    • composio.connectedAccounts.revoke(), which surfaces the API's 400/409 as ComposioConnectedAccountRevocationNotSupportedError / ComposioConnectedAccountNotRevokableError. connectedAccounts.refresh() is marked @deprecated (the endpoint is deprecated upstream).
    • composio.toolkits.getMany(slugs) and composio.toolkits.changelog().
    • session.listConfigHistory() on sessions.
    • composio.experimental.usage.summary() and composio.experimental.usage.breakdown() (experimental, shape may change).
    • composio.toolkits.recommendScopes(toolkitSlug, { tools, ... }) and composio.toolkits.listGrantContexts(toolkitSlug) for OAuth scope recommendations (the API marks both beta).
    • composio.connectedAccounts.completeAuth({ userId, sessionUri }), which completes a deferred OAuth connection after your OAuth callback verifier has confirmed the user's identity.
    • composio.keyring.listTransferKeys(), which returns the public JWKs of the organization's customer-managed keyring.
    • composio.experimental.customToolkits (upsert, sync, delete) for project-owned custom toolkits (in pilot, shape may change).
    • CIMD_OAUTH joins AuthSchemeTypes.
    • triggers.listActive() returns {} for state and triggerConfig when the API sends null.
    • ToolkitAuthField gains userVisible (from user_visible) and ToolkitAuthConfigDetails gains requiredScopes (from required_scopes), both omitted when the API does not send them.
    • @composio/client moves from the old autogenerated client to the new handrolled client. The API removed validate_credentials from the connected-account refresh, so connectedAccounts.refresh() now ignores validateCredentials and logs a warning when it is set.
    • logger and logLevel options on new Composio({...}). logger accepts any { error, warn, info, debug } sink (console, pino, winston, ...) and receives the SDK's formatted, credential-redacted output; logLevel ('silent' | 'error' | 'warn' | 'info' | 'debug') overrides COMPOSIO_LOG_LEVEL. The owned client's runtime deprecation warnings (response Deprecation/Sunset headers and deprecated request inputs) are now routed through that SDK logger instead of console. The client's per-request lifecycle logs are emitted only at 'debug'. tools.get/getRawComposioTools send the API's query parameter in place of the deprecated search wire parameter; the SDK's public search option is unchanged.
  • a4a40a1: Sessions now export their MCP config from the auth context the session request was actually made with: the project key as x-api-key when one is configured, otherwise the user API key (userApiKey or the x-user-api-key default header) as x-user-api-key, plus x-org-id / x-project-id when the instance is scoped. No other default header and no ambient COMPOSIO_API_KEY is ever copied. The headers are only attached when the MCP URL shares the origin of the configured API base URL (whatever its scheme). Any other destination (a different origin, an opaque origin such as a data: URL, or a URL that does not parse) never receives them: with mcp: true, create() / use() throw ComposioMCPDestinationError, which names both origins and never includes a key; without mcp: true the session is returned with session.mcp.headers empty and a warning naming both origins is logged, so native tools keep working. The SDK never connects to the MCP URL itself and does not follow redirects for it. Trigger subscriptions (Pusher channel auth) follow the same rule instead of falling back to the environment when the project key is disabled.

    ComposioConfig gains orgId and projectId: the organization and consumer project nano IDs, sent together as the x-org-id / x-project-id headers on every request and with the session MCP config. They may also be supplied through defaultHeaders; a half-configured or disagreeing scope throws ComposioScopeConfigError. Without a scope, a user API key keeps addressing the API default project.

    session.update() now sends the session's last observed configVersion as the expected_config_version precondition by default and never retries that request, so a concurrent change surfaces as ComposioSessionConfigConflictError (HTTP 409; re-fetch the session, then retry) while the local session object stays unchanged. Pass expectedConfigVersion to send another version or expectedConfigVersion: false to opt out (last writer wins). Every policy block (toolkits, tools, tags, authConfigs, connectedAccounts, preload, manageConnections, multiAccount, search, execute, experimental) accepts null to remove the stored override, manageConnections.callbackUrl: null removes only the stored callback URL, multiAccount.maxAccountsPerToolkit: null removes the stored maximum, and an empty toolkit allowlist (toolkits: []) is sent as-is so it denies every app toolkit.

... (truncated)

Commits
  • 9822a7e Release: update version (#4609)
  • 5ec0bdf fix(core): validate remote file destinations before downloading (#4621)
  • de5e3f6 feat(core): support saved Session configs (#4601)
  • 3721d04 fix(core): reject unsafe mount paths in RemoteFile.save() in both SDKs (#4487)
  • 0833c1b Add hosted account support and premium charge tracking (#4617)
  • 461c6c3 feat(sdk): experimental premium usage policy for Sessions (#4599)
  • 5d07582 fix(sdk): stop sending expected_config_version by default on session update (...
  • 75f3c75 Release: update version (#4576)
  • cd9ee74 docs: clarify tool discovery and direct execution guidance (#4583)
  • a4a40a1 fix(core): credential intent, MCP auth context, and update preconditions (#4579)
  • Additional commits viewable in compare view

Updates @modelcontextprotocol/sdk from 1.30.0 to 1.30.1

Release notes

Sourced from @​modelcontextprotocol/sdk's releases.

1.30.1

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.0...1.30.1

Commits
  • 289ac2c chore: bump version to 1.30.1 (#2848)
  • 12b4256 fix(auth): preserve resource URI without trailing slash (#1968) (#1972)
  • a9f6eb7 [v1.x] fix(server): read HTTP request bodies with a size limit and bound JSON...
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…h 2 updates

Bumps the compatible-updates group with 2 updates in the / directory: [@composio/core](https://github.com/ComposioHQ/composio/tree/HEAD/ts/packages/core) and [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk).


Updates `@composio/core` from 0.19.0 to 0.21.0
- [Release notes](https://github.com/ComposioHQ/composio/releases)
- [Changelog](https://github.com/ComposioHQ/composio/blob/next/ts/packages/core/CHANGELOG.md)
- [Commits](https://github.com/ComposioHQ/composio/commits/@composio/core@0.21.0/ts/packages/core)

Updates `@modelcontextprotocol/sdk` from 1.30.0 to 1.30.1
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@1.30.0...1.30.1)

---
updated-dependencies:
- dependency-name: "@composio/core"
  dependency-version: 0.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: compatible-updates
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.30.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: compatible-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants