Skip to content

[dependencies]: Bump @modelcontextprotocol/inspector from 0.17.2 to 0.19.0#890

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/modelcontextprotocol/inspector-0.19.0
Open

[dependencies]: Bump @modelcontextprotocol/inspector from 0.17.2 to 0.19.0#890
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/modelcontextprotocol/inspector-0.19.0

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 6, 2026

Bumps @modelcontextprotocol/inspector from 0.17.2 to 0.19.0.

Release notes

Sourced from @​modelcontextprotocol/inspector's releases.

0.19.0

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/inspector@0.17.5...0.19.0-hotfix

0.18.0

What's Changed

... (truncated)

Commits
  • 3adaf39 Merge pull request #1029 from modelcontextprotocol/claude/issue-1028-20260121...
  • edbe2f8 Merge branch 'main' into claude/issue-1028-20260121-1235
  • 7ef0971 Add Tasks support (#1013)
  • 7f6e579 Bump version to 0.19.0 across all packages
  • 6dc5d1a Merge pull request #937 from olaservo/add-mcp-docs-server-to-claude
  • 6247e67 Merge branch 'main' into add-mcp-docs-server-to-claude
  • da684d0 Update LICENSE and package.json for Linux Foundation transition (#1018)
  • 44d0e58 Converted CLI tests to use vitest (#1012)
  • ea82eff Merge branch 'main' into add-mcp-docs-server-to-claude
  • 4835b73 Fix allowedTools config to include mcp-docs MCP server tools
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by pcarleton, a new releaser for @​modelcontextprotocol/inspector since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@modelcontextprotocol/inspector](https://github.com/modelcontextprotocol/inspector) from 0.17.2 to 0.19.0.
- [Release notes](https://github.com/modelcontextprotocol/inspector/releases)
- [Commits](modelcontextprotocol/inspector@0.17.2...0.19.0)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/inspector"
  dependency-version: 0.19.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies pull requests that update a dependency file javascript Pull requests that update javascript code minor Tag aimed to create a MINOR version for the project. labels Feb 6, 2026
@dependabot dependabot bot requested a review from a team as a code owner February 6, 2026 10:55
@dependabot dependabot bot added dependencies pull requests that update a dependency file javascript Pull requests that update javascript code minor Tag aimed to create a MINOR version for the project. labels Feb 6, 2026
@github-actions
Copy link

github-actions bot commented Feb 6, 2026

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses.
  • ⚠️ 1 packages with OpenSSF Scorecard issues.
See the Details below.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/@floating-ui/core 1.7.4 UnknownUnknown
npm/@floating-ui/dom 1.7.5 UnknownUnknown
npm/@floating-ui/react-dom 2.1.7 UnknownUnknown
npm/@modelcontextprotocol/inspector 0.19.0 UnknownUnknown
npm/@modelcontextprotocol/inspector-cli 0.19.0 UnknownUnknown
npm/@modelcontextprotocol/inspector-client 0.19.0 UnknownUnknown
npm/@modelcontextprotocol/inspector-server 0.19.0 UnknownUnknown
npm/react-remove-scroll 2.7.2 ⚠️ 2.3
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Token-Permissions⚠️ -1No tokens found
Dangerous-Workflow⚠️ -1no workflows found
Code-Review⚠️ 2Found 6/23 approved changesets -- score normalized to 2
Maintained⚠️ 23 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 2
Pinned-Dependencies⚠️ -1no dependencies found
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy⚠️ 0security policy file not detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities⚠️ 063 existing vulnerabilities detected
npm/tailwind-merge 2.6.1 🟢 7
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 9 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Security-Policy🟢 10security policy file detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
Packaging🟢 10packaging workflow detected
SAST🟢 7SAST tool detected but not run on all commits
Vulnerabilities🟢 82 existing vulnerabilities detected
npm/ws 8.19.0 🟢 6.1
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Security-Policy🟢 10security policy file detected
Code-Review⚠️ 2Found 6/30 approved changesets -- score normalized to 2
Binary-Artifacts🟢 10no binaries found in the repo
Maintained🟢 106 commit(s) and 6 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Vulnerabilities🟢 100 existing vulnerabilities detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Signed-Releases⚠️ -1no releases found
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • package-lock.json

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies pull requests that update a dependency file javascript Pull requests that update javascript code minor Tag aimed to create a MINOR version for the project.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants