Upgrade to ynab SDK v4, add new tools, fix version/coverage/security - #6
Conversation
…urity Upgrade ynab SDK 2.10.0 -> 4.4.0 (internal budgets->plans rename; MCP tool surface unchanged) and @modelcontextprotocol/sdk 1.25.3 -> 1.29.0 (clears a HIGH cross-client data-leak advisory). New tools unlocked by the v4 surface: - ynab_update_payee, ynab_create_payee - ynab_create_category, ynab_create_category_group, ynab_update_category_group - ynab_update_transactions (bulk) - ynab_list_money_movements (read) Fixes: - Server now reports its real version (was hardcoded 0.1.0; reads package.json) - Re-enable the Vitest coverage gate (pre-1.0 thresholds.global.* shape was silently ignored); enforce as a floor - create-account now offers only API-creatable account types (SaveAccountType) - Correct README tool counts/listings and replace the stale, partly-fictional server.json tools list with the real registry; add server.json version - Add CHANGELOG.md Bump version to 0.2.0 (additive, no MCP-client breaking changes). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016PgWfscEzb25EXrgJg1Mt5
|
Warning Review limit reached
Next review available in: 38 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (1)
WalkthroughThis PR upgrades the ynab SDK to v4 and MCP SDK, renaming budget-related response fields from ChangesYNAB v4 migration and new tools
Estimated code review effort🎯 4 (Complex) | ⏱️ ~60 minutes Possibly related PRs
Security Note 🔒Flagging for visibility: the new write-path wrappers (
🚥 Pre-merge checks | ✅ 5 | ❌ 4❌ Failed checks (4 inconclusive)
✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@package.json`:
- Around line 45-47: Add npm overrides to force patched versions of the
vulnerable transitive dependencies introduced by
`@modelcontextprotocol/sdk`@1.29.0. Update the package.json dependency
configuration so the lockfile resolves safe versions for fast-uri, hono,
ip-address, and express-rate-limit, then regenerate the lockfile to ensure npm
audit --audit-level=high passes.
In `@README.md`:
- Line 19: The README tool-count wording is ambiguous because “66 tools ... plus
23 custom analytics tools” implies an extra 23 beyond the total shown elsewhere.
Update the marketing copy in the README’s “Access everything” line to make clear
that the 23 custom analytics tools are part of the 66 total, and keep the
wording consistent with the “Available Tools (66 Total)” section and the
Features table.
In `@src/services/ynab-client.ts`:
- Around line 938-941: The getMoneyMovements method is calling the wrong YNAB
SDK member, so the request will fail at runtime. Update
YNABClient.getMoneyMovements to use the correct API shape on this.api, replacing
the underscored property access with the camelCase moneyMovements member while
keeping the existing rateLimiter.acquire flow intact.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 43d0783e-0089-4626-940f-2d422c502455
⛔ Files ignored due to path filters (1)
package-lock.jsonis excluded by!**/package-lock.json
📒 Files selected for processing (24)
CHANGELOG.mdREADME.mdpackage.jsonserver.jsonsrc/index.tssrc/server.tssrc/services/ynab-client.tssrc/tools/accounts/create-account.tssrc/tools/analytics/age-of-money.tssrc/tools/budgets/get-budget-settings.tssrc/tools/budgets/get-budget.tssrc/tools/budgets/list-budgets.tssrc/tools/categories/create-category-group.tssrc/tools/categories/create-category.tssrc/tools/categories/update-category-group.tssrc/tools/index.tssrc/tools/money-movements/list-money-movements.tssrc/tools/payees/create-payee.tssrc/tools/payees/update-payee.tssrc/tools/transactions/create-transaction.tssrc/tools/transactions/create-transactions.tssrc/tools/transactions/update-transaction.tssrc/tools/transactions/update-transactions.tsvitest.config.ts
The "66 tools ... plus 23 custom analytics" phrasing read as additive (66+23). Reword to make clear the breakdown sums to 66 (40 core API + 23 analytics + 3 system). Addresses a CodeRabbit review note. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016PgWfscEzb25EXrgJg1Mt5
Summary
A review pass over the server plus the approved ynab SDK v4 upgrade. The SDK jump is an internal-only refactor (the
Budget→Planrename); MCP tool names, parameters, and output shapes are unchanged, so existing clients are unaffected. New tools are purely additive. Version bumped to 0.2.0 accordingly.Dependencies
ynab^2.10.0→^4.4.0. Internal migration:api.budgets→api.plans,getBudget*→getPlan*,Budget*Responsetypes →Plan*Response, and the three response-shape consumers updated (.data.budgets→.data.plans,.data.budget→.data.plan).@modelcontextprotocol/sdk^1.25.3→^1.29.0, resolving a HIGH-severity cross-client data-leak advisory.npm audit fixtook advisories 19 → 5; the remaining 5 are dev-only (vitest/vite/esbuild) and are not shipped.New tools (59 → 66)
Write (gated by
YNAB_READ_ONLY=false):ynab_update_payee,ynab_create_payee,ynab_create_category,ynab_create_category_group,ynab_update_category_group,ynab_update_transactions(bulk). Read:ynab_list_money_movements. Each write tool follows the existing audit-log + cache-invalidation + read-only-guard pattern.Fixes
0.1.0; readspackage.json).thresholds.global.*shape that Vitest 1.x silently ignored. Now enforced as a floor.ynab_create_accountnow offers only the account types the YNAB API can actually create (SaveAccountType); previously-offered loan/mortgage types always failed at the API.toolslist inserver.jsonwith the actual registered names; added aversionfield.CHANGELOG.md.Verification
npm run lint,npm run typecheck,npm run test:coverage(209 tests, gate passes), andnpm run buildall pass locally. A stdio smoke test confirmed the server advertises0.2.0and lists all 7 new tools. The live YNAB API path (budgets→plans round-trip, an actual payee rename) was not exercised — it needs a realYNAB_ACCESS_TOKEN.🤖 Generated with Claude Code
https://claude.ai/code/session_016PgWfscEzb25EXrgJg1Mt5
Generated by Claude Code
Summary by CodeRabbit
New Features
Bug Fixes