René's URL Explorer Experiment


Title: build(deps): bump esbuild from 0.27.2 to 0.28.1 in /tools/sep-automation in the npm_and_yarn group across 1 directory by dependabot[bot] · Pull Request #2911 · modelcontextprotocol/modelcontextprotocol · GitHub

Open Graph Title: build(deps): bump esbuild from 0.27.2 to 0.28.1 in /tools/sep-automation in the npm_and_yarn group across 1 directory by dependabot[bot] · Pull Request #2911 · modelcontextprotocol/modelcontextprotocol

X Title: build(deps): bump esbuild from 0.27.2 to 0.28.1 in /tools/sep-automation in the npm_and_yarn group across 1 directory by dependabot[bot] · Pull Request #2911 · modelcontextprotocol/modelcontextprotocol

Description: Bumps the npm_and_yarn group with 1 update in the /tools/sep-automation directory: esbuild. Updates esbuild from 0.27.2 to 0.28.1 Release notes Sourced from esbuild's releases. v0.28.1 Disallow \ in local development server HTTP requests (GHSA-g7r4-m6w7-qqqr) This release fixes a security issue where HTTP requests to esbuild's local development server could traverse outside of the serve directory on Windows using a \ backslash character. It happened due to the use of Go's path.Clean() function, which only handles Unix-style / characters. HTTP requests with paths containing \ are no longer allowed. Thanks to @​dellalibera for reporting this issue. Add integrity checks to the Deno API (GHSA-gv7w-rqvm-qjhr) The previous release of esbuild added integrity checks to esbuild's npm install script. This release also adds integrity checks to esbuild's Deno install script. Now esbuild's Deno API will also fail with an error if the downloaded esbuild binary contains something other than the expected content. Note that esbuild's Deno API installs from registry.npmjs.org by default, but allows the NPM_CONFIG_REGISTRY environment variable to override this with a custom package registry. This change means that the esbuild executable served by NPM_CONFIG_REGISTRY must now match the expected content. Thanks to @​sondt99 for reporting this issue. Avoid inlining using and await using declarations (#4482) Previously esbuild's minifier sometimes incorrectly inlined using and await using declarations into subsequent uses of that declaration, which then fails to dispose of the resource correctly. This bug happened because inlining was done for let and const declarations by avoiding doing it for var declarations, which no longer worked when more declaration types were added. Here's an example: // Original code { using x = new Resource() x.activate() } // Old output (with --minify) new Resource().activate(); // New output (with --minify) {using e=new Resource;e.activate()} Fix module evaluation when an error is thrown (#4461, #4467) If an error is thrown during module evaluation, esbuild previously didn't preserve the state of the module for subsequent module references. This was observable if import() or require() is used to import a module multiple times. The thrown error is supposed to be thrown by every call to import() or require(), not just the first. With this release, esbuild will now throw the same error every time you call import() or require() on a module that throws during its evaluation. Fix some edge cases around the new operator (#4477) Previously esbuild incorrectly printed certain edge cases involving complex expressions inside the target of a new expression (specifically an optional chain and/or a tagged template literal). The generated code for the new target was not correctly wrapped with parentheses, and either contained a syntax error or had different semantics. These edge cases have been fixed so that they now correctly wrap the new target in parentheses. Here is an example of some affected code: // Original code new (foo()`bar`)() new (foo()?.bar)() // Old output new foo()bar(); new (foo())?.bar(); ... (truncated) Changelog Sourced from esbuild's changelog. Changelog: 2025 This changelog documents all esbuild versions published in the year 2025 (versions 0.25.0 through 0.27.2). Commits bb9db84 publish 0.28.1 to npm 9ff053e security: add integrity checks to the Deno API 0a9bf21 enforce non-negative size in gzip parser e2a1a71 security: forbid \\ in local dev server requests 83a2cbf fix #4482: don't inline using declarations 308ad74 fix #4471: renaming of nested var declarations f013f5f fix some typos aafd6e4 chore: fix some minor issues in comments (#4462) 15300c3 follow up: cjs evaluation fixes 1bda0c3 fix #4461, fix #4467: esm evaluation fixes Additional commits viewable in compare view Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase. Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: @dependabot rebase will rebase this PR @dependabot recreate will recreate this PR, overwriting any edits that have been made to it @dependabot show ignore conditions will show all of the ignore conditions of the specified dependency @dependabot ignore major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) @dependabot ignore minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) @dependabot ignore will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) @dependabot unignore will remove all of the ignore conditions of the specified dependency @dependabot unignore will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the Security Alerts page.

Open Graph Description: Bumps the npm_and_yarn group with 1 update in the /tools/sep-automation directory: esbuild. Updates esbuild from 0.27.2 to 0.28.1 Release notes Sourced from esbuild's releases. v0.28.1 Disa...

X Description: Bumps the npm_and_yarn group with 1 update in the /tools/sep-automation directory: esbuild. Updates esbuild from 0.27.2 to 0.28.1 Release notes Sourced from esbuild's releases. v0.28.1 ...

Opengraph URL: https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911

X: @github

direct link

Domain: github.com

route-pattern/:user_id/:repository/pull/:id/files(.:format)
route-controllerpull_requests
route-actionfiles
fetch-noncev2:476aec7c-d8ab-8d96-64cf-6c0c75defa54
current-catalog-service-hashae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b
request-id997C:2DDB6E:5729FAF:785BA7F:6A5EA4BF
html-safe-nonce3340ac29d148c91777b15561f7c1108aa3fc9d041d171c72e415b18dfb3e07e4
visitor-payloadeyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI5OTdDOjJEREI2RTo1NzI5RkFGOjc4NUJBN0Y6NkE1RUE0QkYiLCJ2aXNpdG9yX2lkIjoiNDMzNDQ1MTIxNTYwNDU1Njk5MiIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9
visitor-hmacf38346a91ba740a6f364d49cad91b472e1e2fe8b8ce16cfe6691eb90ed5af4e1
hovercard-subject-tagpull_request:3859664772
github-keyboard-shortcutsrepository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot
google-site-verificationApib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I
octolytics-urlhttps://collector.github.com/github/collect
analytics-location///pull_requests/show/files
fb:app_id1401488693436528
apple-itunes-appapp-id=1477376905, app-argument=https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911/files
twitter:imagehttps://avatars.githubusercontent.com/in/29110?s=400&v=4
twitter:cardsummary_large_image
og:imagehttps://avatars.githubusercontent.com/in/29110?s=400&v=4
og:image:altBumps the npm_and_yarn group with 1 update in the /tools/sep-automation directory: esbuild. Updates esbuild from 0.27.2 to 0.28.1 Release notes Sourced from esbuild's releases. v0.28.1 Disa...
og:site_nameGitHub
og:typeobject
hostnamegithub.com
expected-hostnamegithub.com
None7c7e31acb6a895494e518b880f5ccf39604f7fa9a8f2f3c64145efc3b776256d
turbo-cache-controlno-preview
diff-viewunified
go-importgithub.com/modelcontextprotocol/modelcontextprotocol git https://github.com/modelcontextprotocol/modelcontextprotocol.git
octolytics-dimension-user_id182288589
octolytics-dimension-user_loginmodelcontextprotocol
octolytics-dimension-repository_id862570523
octolytics-dimension-repository_nwomodelcontextprotocol/modelcontextprotocol
octolytics-dimension-repository_publictrue
octolytics-dimension-repository_is_forkfalse
octolytics-dimension-repository_network_root_id862570523
octolytics-dimension-repository_network_root_nwomodelcontextprotocol/modelcontextprotocol
turbo-body-classeslogged-out env-production page-responsive full-width
disable-turbotrue
browser-stats-urlhttps://api.github.com/_private/browser/stats
browser-errors-urlhttps://api.github.com/_private/browser/errors
release2d2ac9bdd71d5f53f2b731c9330677e38624e301
ui-targetfull
theme-color#1e2327
color-schemelight dark

Links:

Skip to contenthttps://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911/files#start-of-content
https://github.com/
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fmodelcontextprotocol%2Fmodelcontextprotocol%2Fpull%2F2911%2Ffiles
GitHub CopilotWrite better code with AIhttps://github.com/features/copilot
GitHub Copilot appDirect agents from issue to mergehttps://github.com/features/ai/github-app
MCP RegistryNewIntegrate external toolshttps://github.com/mcp
ActionsAutomate any workflowhttps://github.com/features/actions
CodespacesInstant dev environmentshttps://github.com/features/codespaces
IssuesPlan and track workhttps://github.com/features/issues
Code ReviewManage code changeshttps://github.com/features/code-review
Code QualityEnforce quality at mergehttps://github.com/features/code-quality
GitHub Advanced SecurityFind and fix vulnerabilitieshttps://github.com/security/advanced-security
Code securitySecure your code as you buildhttps://github.com/security/advanced-security/code-security
Secret protectionStop leaks before they starthttps://github.com/security/advanced-security/secret-protection
Why GitHubhttps://github.com/why-github
Documentationhttps://docs.github.com
Bloghttps://github.blog
Changeloghttps://github.blog/changelog
Marketplacehttps://github.com/marketplace
View all featureshttps://github.com/features
Enterpriseshttps://github.com/enterprise
Small and medium teamshttps://github.com/team
Startupshttps://github.com/enterprise/startups
Nonprofitshttps://github.com/solutions/industry/nonprofits
App Modernizationhttps://github.com/solutions/use-case/app-modernization
DevSecOpshttps://github.com/solutions/use-case/devsecops
DevOpshttps://github.com/solutions/use-case/devops
CI/CDhttps://github.com/solutions/use-case/ci-cd
View all use caseshttps://github.com/solutions/use-case
Healthcarehttps://github.com/solutions/industry/healthcare
Financial serviceshttps://github.com/solutions/industry/financial-services
Manufacturinghttps://github.com/solutions/industry/manufacturing
Governmenthttps://github.com/solutions/industry/government
View all industrieshttps://github.com/solutions/industry
View all solutionshttps://github.com/solutions
AIhttps://github.com/resources/articles?topic=ai
Software Developmenthttps://github.com/resources/articles?topic=software-development
DevOpshttps://github.com/resources/articles?topic=devops
Securityhttps://github.com/resources/articles?topic=security
View all topicshttps://github.com/resources/articles
Customer storieshttps://github.com/customer-stories
Events & webinarshttps://github.com/resources/events
Ebooks & reportshttps://github.com/resources/whitepapers
Business insightshttps://github.com/solutions/executive-insights
GitHub Skillshttps://skills.github.com
Documentationhttps://docs.github.com
Customer supporthttps://support.github.com
Community forumhttps://github.com/orgs/community/discussions
Trust centerhttps://github.com/trust-center
Partnershttps://github.com/partners
View all resourceshttps://github.com/resources
GitHub SponsorsFund open source developershttps://github.com/open-source/sponsors
Security Labhttps://securitylab.github.com
Maintainer Communityhttps://maintainers.github.com
Acceleratorhttps://github.com/open-source/accelerator
GitHub Starshttps://stars.github.com
Archive Programhttps://archiveprogram.github.com
Topicshttps://github.com/topics
Trendinghttps://github.com/trending
Collectionshttps://github.com/collections
Enterprise platformAI-powered developer platformhttps://github.com/enterprise
GitHub Advanced SecurityEnterprise-grade security featureshttps://github.com/security/advanced-security
Copilot for BusinessEnterprise-grade AI featureshttps://github.com/features/copilot/copilot-business
Premium SupportEnterprise-grade 24/7 supporthttps://github.com/enterprise/premium-support
Pricinghttps://github.com/pricing
Search syntax tipshttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
documentationhttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fmodelcontextprotocol%2Fmodelcontextprotocol%2Fpull%2F2911%2Ffiles
Sign up https://github.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E%2Fpull_requests%2Fshow%2Ffiles&source=header-repo&source_repo=modelcontextprotocol%2Fmodelcontextprotocol
Reloadhttps://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911/files
Reloadhttps://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911/files
Reloadhttps://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911/files
Please reload this pagehttps://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911/files
modelcontextprotocol https://github.com/modelcontextprotocol
modelcontextprotocolhttps://github.com/modelcontextprotocol/modelcontextprotocol
Notifications https://github.com/login?return_to=%2Fmodelcontextprotocol%2Fmodelcontextprotocol
Fork 1.7k https://github.com/login?return_to=%2Fmodelcontextprotocol%2Fmodelcontextprotocol
Star 8.6k https://github.com/login?return_to=%2Fmodelcontextprotocol%2Fmodelcontextprotocol
Code https://github.com/modelcontextprotocol/modelcontextprotocol
Issues 112 https://github.com/modelcontextprotocol/modelcontextprotocol/issues
Pull requests 81 https://github.com/modelcontextprotocol/modelcontextprotocol/pulls
Discussions https://github.com/modelcontextprotocol/modelcontextprotocol/discussions
Actions https://github.com/modelcontextprotocol/modelcontextprotocol/actions
Projects https://github.com/modelcontextprotocol/modelcontextprotocol/projects
Models https://github.com/modelcontextprotocol/modelcontextprotocol/models
Security and quality 0 https://github.com/modelcontextprotocol/modelcontextprotocol/security
Insights https://github.com/modelcontextprotocol/modelcontextprotocol/pulse
Code https://github.com/modelcontextprotocol/modelcontextprotocol
Issues https://github.com/modelcontextprotocol/modelcontextprotocol/issues
Pull requests https://github.com/modelcontextprotocol/modelcontextprotocol/pulls
Discussions https://github.com/modelcontextprotocol/modelcontextprotocol/discussions
Actions https://github.com/modelcontextprotocol/modelcontextprotocol/actions
Projects https://github.com/modelcontextprotocol/modelcontextprotocol/projects
Models https://github.com/modelcontextprotocol/modelcontextprotocol/models
Security and quality https://github.com/modelcontextprotocol/modelcontextprotocol/security
Insights https://github.com/modelcontextprotocol/modelcontextprotocol/pulse
Sign up for GitHub https://github.com/signup?return_to=%2Fmodelcontextprotocol%2Fmodelcontextprotocol%2Fissues%2Fnew%2Fchoose
terms of servicehttps://docs.github.com/terms
privacy statementhttps://docs.github.com/privacy
Sign inhttps://github.com/login?return_to=%2Fmodelcontextprotocol%2Fmodelcontextprotocol%2Fissues%2Fnew%2Fchoose
mcp-commanderhttps://github.com/apps/mcp-commander
mainhttps://github.com/modelcontextprotocol/modelcontextprotocol/tree/main
dependabot/npm_and_yarn/tools/sep-automation/npm_and_yarn-53cbaf2a5bhttps://github.com/modelcontextprotocol/modelcontextprotocol/tree/dependabot/npm_and_yarn/tools/sep-automation/npm_and_yarn-53cbaf2a5b
Conversation 1 https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911
Commits 1 https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911/commits
Checks 16 https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911/checks
Files changed 2 https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911/files
build(deps): bump esbuild from 0.27.2 to 0.28.1 in /tools/sep-automation in the npm_and_yarn group across 1 directory https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911/files#top
Show all changes 1 commit https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911/files
84488cc build(deps): bump esbuild dependabot[bot] Jun 13, 2026 https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911/commits/84488cc30ad0f7634b22e51c582fdd102a231bbd
Clear filters https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911/files
Please reload this pagehttps://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911/files
Please reload this pagehttps://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911/files
package-lock.json https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911/files#diff-2f905fdf2a71eb803e8e4905556199c6b3f451e68ceff9d10b34191fa17a0af3
package.json https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911/files#diff-8194047dd289ce96d1eeab6cc81f16f555dd2f6166383499a2290b32aeb2c7cb
Please reload this pagehttps://github.com/modelcontextprotocol/modelcontextprotocol/pull/2911/files
https://github.com
Termshttps://docs.github.com/site-policy/github-terms/github-terms-of-service
Privacyhttps://docs.github.com/site-policy/privacy-policies/github-privacy-statement
Securityhttps://github.com/security
Statushttps://www.githubstatus.com/
Communityhttps://github.community/
Docshttps://docs.github.com/
Contacthttps://support.github.com?tags=dotcom-footer

Viewport: width=device-width


URLs of crawlers that visited me.