chore(deps): update dependency mcp-neo4j-cypher to v0.6.0 - #528
chore(deps): update dependency mcp-neo4j-cypher to v0.6.0#528renovate[bot] wants to merge 1 commit into
Conversation
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
🔒 MCP Security Scan Results✅ mcp-neo4j-cypher
Summary: Scanned 1 MCP server(s), all passed security checks. ✅ |
ba50f61 to
0d0dff1
Compare
|
@renovatebot rebase |
0d0dff1 to
0bd1a6b
Compare
Triage: build-containers blocked by genuine upstream CVEsLocal Grype scan (DB 2026-04-27) of the 0.6.0 image surfaces these HIGH/CRITICAL findings (severity-cutoff: high, only-fixed: true):
These are genuine upstream CVEs, not false positives. The fastmcp findings are blocked by the package's own constraint Recommendation: Hold this bump. Upstream needs to widen |
ae3c9f0 to
699d441
Compare
fb2e78a to
93a6379
Compare
5a0e17a to
078abb5
Compare
078abb5 to
5f1fbb8
Compare
13e9d89 to
2edb9e4
Compare
2edb9e4 to
d35d2eb
Compare
|
Heads up: this bump would make the security posture worse, not better, and #668 lists it as a case the new override mechanism would fix. That is no longer accurate.
Today 0.5.3 resolves fastmcp 2.14.7. Forcing below 2.14 re-exposes two high advisories that the current version escapes:
So this goes from 2 findings to 4. The existing two, GHSA-vv7q-7jx5-f767 (critical) and GHSA-rww4-4w9c-7733 (high), are patched only at fastmcp 3.2.0 and cannot be fixed at either version, because forcing 3.x breaks the server: all three neo4j servers pass Suggest holding this until upstream releases a version that drops the |
This PR contains the following updates:
0.5.3→0.6.0Configuration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.