Skip to content

chore(deps): update dependency arxiv-mcp-server to v0.6.1 - #803

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/arxiv-mcp-server-0.x
Open

chore(deps): update dependency arxiv-mcp-server to v0.6.1#803
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/arxiv-mcp-server-0.x

Conversation

@renovate

@renovate renovate Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
arxiv-mcp-server 0.5.00.6.1 age confidence

Release Notes

blazickjp/arxiv-mcp-server (arxiv-mcp-server)

v0.6.1

Compare Source

What's Changed

New Contributors

Full Changelog: blazickjp/arxiv-mcp-server@v0.6.0...v0.6.1

v0.6.0

Compare Source

What's Changed

Full Changelog: blazickjp/arxiv-mcp-server@v0.5.1...v0.6.0

v0.5.1

Compare Source

v0.5.1

Maintenance release restoring dependency and distribution consistency.

Fixed
  • Constrains the upstream arxiv dependency to supported releases below 4.0, preventing fresh installs from resolving an incompatible major version.
  • Keeps package, lockfile, and official MCP Registry metadata synchronized.
  • Replaces the retired Intel macOS MCPB runner.
Distribution
  • Publishes PyPI and official MCP Registry metadata sequentially through GitHub OIDC.
  • Updates the MCP Registry manifest to the current schema.
Validation
  • 92 tests passed across the local suite.
  • GitHub Actions lint and Python 3.11/3.12 test matrix passed on Linux, macOS, and Windows.
  • Clean wheel install resolved arxiv==3.0.0.
  • Official mcp-publisher validate passed.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@toolhive-release-app

Copy link
Copy Markdown
Contributor

🔒 MCP Security Scan Results

❌ arxiv-mcp-server

  • Status: Failed
  • Tools scanned: 14
  • Vulnerabilities found: 1

Security issues detected:

  • [AITech-8.2] Unintentional and/or unauthorized exposure or exfiltration of sensitive information, such as private or sensitive data, intellectual property, and proprietary algorithms through exploitation of agent tools, integrations, or capabilities, where the agent is manipulated to use legitimate tools for malicious data exfiltration purposes.

Allowed issues (not blocking):

  • [AITech-1.1] Explicit attempts to override, replace, or modify the model's system instructions, operational directives, or behavioral guidelines through direct user input, causing the model to follow attacker-controlled instructions instead of its intended programming (e.g., "Ignore previous instructions"). (Allowed: False positive - YARA flags the tool description for coercive workflow
    language ("IMPORTANT: only searches your local downloaded collection",
    "Use search_papers ... then download_paper ... before using this tool").
    These are legitimate operational instructions about tool ordering and
    local-vs-remote scope, not attempts to override the model's system
    prompt. The description does not contain "ignore previous instructions"
    or any system-prompt-override pattern. Verified in v0.4.12.
    )

Summary: Scanned 1 MCP server(s), found 1 security issue(s).

⚠️ Action Required: Security issues were detected. Please review and address them before merging.

@renovate
renovate Bot force-pushed the renovate/arxiv-mcp-server-0.x branch from afd6f31 to e4ab97a Compare July 27, 2026 09:43
@renovate
renovate Bot force-pushed the renovate/arxiv-mcp-server-0.x branch from e4ab97a to 1a7c5a9 Compare July 27, 2026 10:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants