feat(deps)!: Update mcp-server-kubernetes ( 3.9.1 ➔ 4.1.4 ) - #1147
Open
mortyops[bot] wants to merge 1 commit into
Open
feat(deps)!: Update mcp-server-kubernetes ( 3.9.1 ➔ 4.1.4 )#1147mortyops[bot] wants to merge 1 commit into
mortyops[bot] wants to merge 1 commit into
Conversation
mortyops
Bot
force-pushed
the
renovate/mcp-server-kubernetes-4.x
branch
2 times, most recently
from
July 15, 2026 20:31
33410cf to
59154b5
Compare
mortyops
Bot
force-pushed
the
renovate/mcp-server-kubernetes-4.x
branch
from
July 18, 2026 20:18
59154b5 to
c68ac85
Compare
mortyops
Bot
force-pushed
the
renovate/mcp-server-kubernetes-4.x
branch
from
July 23, 2026 20:29
c68ac85 to
241cb42
Compare
mortyops
Bot
force-pushed
the
renovate/mcp-server-kubernetes-4.x
branch
from
July 24, 2026 00:31
241cb42 to
e960545
Compare
mortyops
Bot
force-pushed
the
renovate/mcp-server-kubernetes-4.x
branch
from
July 26, 2026 05:13
e960545 to
08cda3e
Compare
mortyops
Bot
force-pushed
the
renovate/mcp-server-kubernetes-4.x
branch
from
July 27, 2026 20:36
08cda3e to
63f2e00
Compare
mortyops
Bot
force-pushed
the
renovate/mcp-server-kubernetes-4.x
branch
from
July 29, 2026 00:30
63f2e00 to
5f38f5d
Compare
mortyops
Bot
force-pushed
the
renovate/mcp-server-kubernetes-4.x
branch
from
August 7, 2026 20:41
5f38f5d to
06c034f
Compare
| datasource | package | from | to | | ---------- | --------------------- | ----- | ----- | | npm | mcp-server-kubernetes | 3.9.1 | 4.1.4 |
mortyops
Bot
force-pushed
the
renovate/mcp-server-kubernetes-4.x
branch
from
August 8, 2026 20:24
06c034f to
482d2d9
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.9.1→4.1.4Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
Flux159/mcp-server-kubernetes (mcp-server-kubernetes)
v4.1.4Compare Source
Dependency bump for js-yaml.
v4.1.3Compare Source
Dependency bump for express (#360).
v4.1.2Compare Source
Updating ALLOWED_TOOLS to fail early if misspelled tool in list. Thanks to @cyb3ralbert!
v4.1.1Compare Source
Bugfix for kubectl_patch's patch_file argument.
v4.1.0Compare Source
Bug fixes for shortflag quirks.
v4.0.9Compare Source
Dependency bump.
v4.0.8Compare Source
Updating SSE dns rebinding protection and adding support for exec_in_pod error outputs.
Thanks to @KaloyanNaumov for the exec_in_pod updates.
v4.0.7Compare Source
Add security.mcpAuthToken to the Helm chart and warn at install time when http/sse transport runs without authentication (#348).
v4.0.6Compare Source
Harden the kubectl/helm dangerous-flag guard against the attached short-flag token form (#347).
v4.0.5Compare Source
Restrict server-side path reads (filename/valuesFile) to the stdio transport in kubectl_apply, kubectl_delete, and Helm chart tools (#346)
v4.0.4Compare Source
Readme cleanup: badges down to one line, replace Gemini CLI install directions with Codex (#340)
v4.0.3Compare Source
Fix kubectl_get
output: "custom"failing under shell-less execFileSync by unquoting the custom-columns argument (#339)v4.0.2Compare Source
Security hardening for remote (SSE / Streamable HTTP) deployments: restrict the kubectl_create
filenameandfromFileparameters — which resolve paths on the machine running the server — to the stdio transport, and add afromFileContentparameter to populate ConfigMaps/Secrets from client-supplied content on any transport (#332).v4.0.1Compare Source
Security fix: mask Kubernetes Secret values regardless of the resourceType syntax used to request them (e.g.
secret/<name>), closing a masking bypass in kubectl_get (GHSA-w23h-64x4-22h9).v4.0.0Compare Source
Security fix: guard the port_forward tool's argv against kubectl flag injection, closing the last unguarded exec path from the argument-injection report (#328).
v3.9.3Compare Source
Updating kubectl generic to take allNamespaces flag and release cleanup.
v3.9.2Compare Source
Dependency version bump to remove protobuf 8.0.0 dependency.
Configuration
📅 Schedule: (in timezone America/New_York)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.