dotnet-mcp-builder: pin sample dependency versions (#2699)

The MCP Apps sample HTML bundle imported ext-apps from esm.sh using an
unpinned major-version tag (@1), which Snyk flags as an unverifiable
external dependency / third-party content exposure risk (indirect
prompt-injection surface, since the imported module can call
app.updateModelContext and app.callServerTool). Pin it to the current
release (1.7.5).

Also pin the sample `dotnet add package` commands for the
ModelContextProtocol* and Microsoft.Extensions.Hosting packages to
their current exact versions (2.2.0 / 10.0.11), and correct a stale
"2.0.0 is current" note in packages.md.
This commit is contained in:
jeanpaulhassane-225
2026-08-21 02:19:47 +00:00
committed by GitHub
parent 927c1b5b38
commit 89e85e6060
5 changed files with 11 additions and 11 deletions
@@ -147,7 +147,7 @@ A minimum viable bundle: vanilla JS using `@modelcontextprotocol/ext-apps`. The
<body>
<div id="root">Loading…</div>
<script type="module">
import { App } from "https://esm.sh/@modelcontextprotocol/ext-apps@1";
import { App } from "https://esm.sh/@modelcontextprotocol/ext-apps@1.7.5";
const app = new App();
await app.connect();