Skip to content

fix(sdk): install the dependency required by SDK types - #1139

Merged
mldangelo-oai merged 2 commits into
mdangelo/codex/pr939-stack-19-native-lifetimefrom
mdangelo/codex/pr939-split-20-installed-types
Oct 4, 2026
Merged

mldangelo-oai merged 2 commits into
mdangelo/codex/pr939-stack-19-native-lifetimefrom
mdangelo/codex/pr939-split-20-installed-types

Conversation

@mldangelo-oai

@mldangelo-oai mldangelo-oai commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Part 20 of 46. Previous: #1124 · Next: #1140 · Stack index

Summary

The SDK declarations reference @modelcontextprotocol/sdk. Add it as a runtime dependency so a separate TypeScript project can resolve the installed SDK types without this repository's development dependencies.

Changes

  • Add @modelcontextprotocol/sdk version 1.30.0 to the SDK manifest and lockfile.

Testing

SDK and MCP typechecks and the SDK CI build passed with the declared dependency installed. The rebuilt plugin bundle and all nine portable source compatibility tests also passed.

Risk and rollout

This changes the installed dependency tree immediately. It does not depend on the later scan-entrypoint activation.

Public disclosure review

  • No customer, partner, prospect, or user identities, data, or identifying details are included.
  • No credentials, personal data, private source, scan findings, or nonpublic links or tickets are included.
  • I reviewed the branch name, title, description, commits, changes, comments, logs, screenshots, attachments, and links for public disclosure.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ⚠️ Failed 2026-10-04T17:48:54.207902Z 51cfc35 New commits
🔒 Security Review ⚠️ Failed 2026-10-04T17:48:56.553816Z 51cfc35 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🚀

Reviewed commit: 718d2f8e6f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The manifest and lockfile changes are consistent and resolve the installed declaration dependency.

Review effort: Balanced
Findings: None

What changed in this PR

Adds the MCP SDK dependency required by published TypeScript declarations.

Changes:

  • Adds @modelcontextprotocol/sdk as a runtime dependency.
  • Updates the pnpm lockfile with its resolved dependency graph.
File Description
sdk/​typescript/​package.json Declares the missing dependency.
sdk/​typescript/​pnpm-lock.yaml Locks the dependency and transitive packages.
Files not reviewed (1)
  • sdk/typescript/pnpm-lock.yaml: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@faizan-oai faizan-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the dependency addition at 718d2f8. SDK/MCP typechecking passes on the integrated stack, and this PR's current-head CI has a successful run. No new issue found in this increment.

@alandelong-oai alandelong-oai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the runtime dependency and lockfile change at 718d2f8e6f79586b83f613ff03cd3fd9a6861771 with three independent passes and root inspection. No actionable findings. Frozen-lockfile installation and the SDK CI type check pass.

@mldangelo-oai
mldangelo-oai force-pushed the mdangelo/codex/pr939-split-20-installed-types branch from 718d2f8 to dc9dfec Compare October 1, 2026 23:44

@alandelong-oai alandelong-oai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Three independent re-review passes and root reconciliation are complete for this restacked head.

No serious outstanding finding was identified in this change. The scoped prior review and current diff remain consistent.

Approval is for this change. Integrated-tip validation passed 1,357 SDK tests (31 skipped), 105 MCP tests (2 skipped), portable checks, types/builds and installed-package smoke. Other stack findings and known CI fixture failures still prevent the stack from being mergeable.

@mldangelo-oai
mldangelo-oai force-pushed the mdangelo/codex/pr939-split-20-installed-types branch from dc9dfec to d9bc13e Compare October 2, 2026 00:36
@mldangelo-oai
mldangelo-oai force-pushed the mdangelo/codex/pr939-stack-19-native-lifetime branch from 177fcc1 to 9bc4841 Compare October 2, 2026 00:36

@alandelong-oai alandelong-oai left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed the real PR diff at d9bc13e3bd9713cc4522a270634cff401a0d45fe. The patch is unchanged from the prior three-pass review. I reconciled the inherited changes in touched files and retained the prior verified findings and tests.

No serious outstanding finding identified in this patch; prior conclusions remain consistent with the unchanged change or the current re-review.

Validation across touched paths at branch tip 06e75cfe: 1,356 SDK tests, 867 Python tests plus 100 subtests, and 108 MCP tests passed; builds, types, portable checks and installed-package checks passed. These are integration checks at the branch tip, not a claim that every intermediate PR or its CI is clean. Latest workflow runs for this unchanged head were verified successful at 2026-10-02 01:26 UTC. Earlier failed or canceled job records are superseded; this CI status correction does not alter the review decision.

@mldangelo-oai
mldangelo-oai force-pushed the mdangelo/codex/pr939-split-20-installed-types branch from d9bc13e to c3f46fd Compare October 2, 2026 01:37
@mldangelo-oai
mldangelo-oai force-pushed the mdangelo/codex/pr939-stack-19-native-lifetime branch from 5fe3f32 to d4eb058 Compare October 2, 2026 01:56
@mldangelo-oai
mldangelo-oai force-pushed the mdangelo/codex/pr939-split-20-installed-types branch from c3f46fd to a3f0652 Compare October 2, 2026 01:56

@alandelong-oai alandelong-oai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Retained the three independent passes for the identical patch and reconciled inherited touched-file changes at a3f0652c9ebb.

No actionable introduced finding survives the independent reviews and root reconciliation of this exact patch, touched-file changes, and current integration checks.

Current tip 355ec321 passed 75 report-projection tests, portable source checks, SDK build:ci and plugin build. The immediately preceding tip fec36f1d passed 1,360 SDK tests, 873 Python tests plus 100 subtests, 109 MCP tests, builds/types and the clean 600-entry installed-package check. Only report_projection.py and its test changed between those tips; SDK/MCP runtime files are byte-identical. Both descend from main 008a8b4d. These are integration checks, separate from own-head probes. No native Windows local run.

No serious outstanding finding introduced by this PR. Code review approval does not establish CI or merge readiness.

@mldangelo-oai
mldangelo-oai force-pushed the mdangelo/codex/pr939-stack-19-native-lifetime branch from d4eb058 to b68f49a Compare October 2, 2026 02:47
@mldangelo-oai
mldangelo-oai force-pushed the mdangelo/codex/pr939-split-20-installed-types branch from a3f0652 to 27f214e Compare October 2, 2026 02:47

@alandelong-oai alandelong-oai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Retained the three independent passes for the verified identical patch and reconciled inherited touched-file changes at 27f214e96951.

No actionable introduced finding survives the independent reviews and root reconciliation of this exact patch and inherited changes in touched files.

Integrated tip 6ef8cbb8, based on 008a8b4d, passed 1,388 SDK tests, 879 Python tests plus 100 subtests, 109 MCP tests, portable checks, builds and the clean 600-entry installed-package check. These are branch-tip integration checks, separate from own-head probes; no local Windows execution was performed.

No serious outstanding finding introduced by this PR. Code approval is separate from CI and merge readiness.

@mldangelo-oai
mldangelo-oai force-pushed the mdangelo/codex/pr939-stack-19-native-lifetime branch from b68f49a to e20ef28 Compare October 2, 2026 03:52
@mldangelo-oai
mldangelo-oai force-pushed the mdangelo/codex/pr939-split-20-installed-types branch from 27f214e to 45a4b91 Compare October 2, 2026 03:52

@alandelong-oai alandelong-oai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Retained three prior independent passes for the verified identical patch and reconciled inherited touched-file changes at 45a4b9139123.

No actionable introduced finding survives the independent reviews and root reconciliation of this exact patch and inherited changes in touched files.

Branch tip 3e0083d9, based on 008a8b4d, passed 1,392 SDK tests, 881 Python tests plus 100 subtests, 109 MCP tests, builds, portable source checks and the 600-entry installed-package check. These are tip checks, separate from own-head probes. No local Windows run was performed. The tip excludes the dependency update merged separately in #1184; combined validation remains outstanding.

No serious outstanding finding introduced by this PR. Code approval is separate from CI and merge readiness.

@mldangelo-oai
mldangelo-oai force-pushed the mdangelo/codex/pr939-stack-19-native-lifetime branch from e20ef28 to 8828b65 Compare October 4, 2026 13:19
@mldangelo-oai
mldangelo-oai force-pushed the mdangelo/codex/pr939-split-20-installed-types branch from 45a4b91 to e863285 Compare October 4, 2026 13:27

@alandelong-oai alandelong-oai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed exact head e8632855b945645edc4ae39a7fdc2948f9407c1d against base 8828b651cdb9daec9853852ad2c7d4cb1c2b16f2.

Three historical independent HIGH reviews are retained after reconciling the full actual 1,050-line contribution, both touched package/lock files, captured instructions and inherited package/lock context. Original reviewer timestamps are absent from the historical records; no new timestamps or fresh source passes are claimed. No changed tests or fixtures are present. No actionable introduced finding was established in this contribution.

This head still inherits the separate #1123 source findings: saved replay can import the current ambient knowledge base when the saved selection is empty, and native preparation rejects a redundant absolute glob allow grant despite required root read. This approval covers this PR contribution; those inherited findings remain open.

Hosted CI for this exact head was green in the observation from 2026-10-04 13:55:27.631308 UTC to 13:55:51.281423 UTC. Completed raw job evidence retains its original collection times. No local tests, builds, model calls, native execution, Windows/Linux execution, clean install, whole-stack integration or deployment validation was performed in this review. Source approval, hosted CI and whole-stack integration remain separate.

Consolidate approved Deep Scan changes into the parent topic branch.
@mldangelo-oai
mldangelo-oai merged commit 43cf620 into mdangelo/codex/pr939-stack-19-native-lifetime Oct 4, 2026
@mldangelo-oai
mldangelo-oai deleted the mdangelo/codex/pr939-split-20-installed-types branch October 4, 2026 17:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants