Skip to content

chore(deps): update dependency mcp-searxng to v2.3.0 - #982

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/mcp-searxng-2.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/mcp-searxng-2.x

Conversation

@renovate

@renovate renovate Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
mcp-searxng 2.1.02.3.0 age confidence

Release Notes

ihor-sokoliuk/mcp-searxng (mcp-searxng)

v2.3.0

Compare Source

Added
  • Conform retained stateful HTTP sessions to the Streamable HTTP lifecycle: missing identifiers return JSON HTTP 400, unknown or terminated identifiers return JSON HTTP 404, successful DELETE termination returns an empty 204, protocol-version validation remains enforced, and clients can reconnect with a fresh session after termination. Failed transport closure remains retryable. (#​289)
Fixed and security
  • Align MCP error classification across STDIO and HTTP transports. Malformed protocol input uses -32602, expected tool failures return isError: true, unexpected internal failures use a sanitized -32603, cancellation stays distinct, and resource errors no longer expose credentials. (#​288)
  • Update Undici to its supported security release and strengthen packed-runtime verification. (#​279)
  • Update Zod with single-source dependency verification. (#​280)
Documentation
  • Correct transport and client examples, clarify proxy trust and Linux/container networking, and validate published setup commands. (#​281)
  • Reorganize client setup and troubleshooting around common tasks with validated navigation and anchors. (#​282)
Dependencies and CI
  • Refresh compatible runtime and development dependencies, including jose 6.2.12, Zod 4.6.5, fast-check 4.10.0 and Node.js type definitions 22.20.2; update CodeQL workflow pins to v4.38.0. (#​287)
Contributors
  • @​ihor-sokoliuk — HTTP lifecycle conformance, error-contract repairs, dependency maintenance, documentation and release work.

v2.2.0

Compare Source

Added
  • Optional MCP OAuth protected-resource mode with resource discovery, signed access-token validation and authenticated legacy-session ownership. Static-token deployments and STDIO remain available. See the OAuth configuration guide for provider and HTTPS routing requirements. (#​277)
Fixed and security
  • Block private IPv4 destinations embedded in IPv6 and native non-global IPv6 URL targets. (#​266, #​268)
  • Preserve successful search results when upstream metadata contains malformed entries, and prevent metadata from injecting misleading result-shaped lines. Thanks to @​shauneccles. (#​271)
  • Refresh the vulnerable query-parser dependency. (#​269)
Dependencies and CI
  • Update tested runtime/development dependencies and CodeQL/QEMU action pins. The production dependency audit is clean; the documented Node.js 22+ requirement remains unchanged. (#​276)
Contributors

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@toolhive-release-app

Copy link
Copy Markdown
Contributor

🔒 MCP Security Scan Results

✅ mcp-searxng

  • Status: Passed
  • Tools scanned: 4
  • Result: No security issues detected

Summary: Scanned 1 MCP server(s), all passed security checks. ✅

@renovate
renovate Bot force-pushed the renovate/mcp-searxng-2.x branch from b3d5fa0 to f53cc2f Compare September 15, 2026 18:16
@renovate renovate Bot changed the title chore(deps): update dependency mcp-searxng to v2.2.0 chore(deps): update dependency mcp-searxng to v2.3.0 Sep 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants