Skip to content

chore(deps): update mcp requirement from <2,>=1.2.0 to >=2.3.0,<3 in /mcp-server - #51

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/mcp-server/mcp-gte-2.3.0-and-lt-3
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/mcp-server/mcp-gte-2.3.0-and-lt-3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on mcp to permit the latest version.

Release notes

Sourced from mcp's releases.

v2.3.0

pip install -U mcp. Docs: https://py.sdk.modelcontextprotocol.io/

Mostly fixes, plus three new options. A few things behave differently, so skim these first:

Behaviour changes

httpx2>=2.10.0 is now required (#3600)

  • It was >=2.5.0. The new max_sse_event_size option needs it.
  • Nothing to do unless you pin httpx2 below 2.10.

A tool with an invalid x-mcp-header annotation fails at registration (#3620)

  • @mcp.tool(), add_tool and Tool.from_function raise InvalidSignature, naming the tool and the problem.
  • Until now the server started, and 2026-07-28 clients silently dropped the tool from their listing.
  • Refused: anything other than a plain str, int or bool parameter (so also str | None, float, lists and enums), a header name that isn't a valid token, and two names that differ only by case.
  • For an optional header parameter, give the schema directly: Annotated[str | None, WithJsonSchema({"type": "string", "x-mcp-header": "Region"})] = None.

Empty _meta and params are no longer sent (#3628)

  • On 2025-11-25 and earlier connections, 2.x sent "_meta": {} on every request. Some servers reject that. It is now left out, as in v1.
  • ping and list requests without a cursor go out with no params member.
  • On the receiving side ctx.meta is None rather than {}, and middleware sees ctx.params as None for a request without params.
  • 2026-07-28 connections are unchanged.

initialize leaves out experimental when none is configured (#3614)

  • It used to send "experimental": {}. server/discover already left it out.
  • Client code reading capabilities.experimental on a legacy connection should handle None.

Mcp-Param-* validation looks the tool up by name (#3630)

  • MCPServer no longer runs tools/list for every tools/call, so middleware no longer sees that extra request.
  • The registered schema is what gets checked. Middleware that filters or rewrites tools/list no longer affects it.

An interactive OAuth login no longer counts against request timeouts (#3635)

  • The timeout pauses while OAuthClientProvider waits on redirect_handler and callback_handler.
  • This fixes Client(mode="auto") settling on 2025-11-25 when the login took longer than 10 seconds.
  • A request timeout no longer ends a login nobody finishes. Put a limit inside callback_handler if you need one.

New

  • max_sse_event_size= on streamable_http_client and StreamableHttpParameters. The default stays 1 MiB per SSE event; raise it, or pass None, for larger tool results (#3600).
  • MCPServer(subscriptions=False) stops serving subscriptions/listen and advertises listChanged and subscribe as false (#3626).
  • Server(get_tool_input_schema=...) lets a low-level server supply a tool's schema for header validation without running its tools/list handler (#3630).
  • Client.call_tool re-lists the tools and retries once after a HeaderMismatch (-32020) rejection (#3627).

Fixes

  • ctx: Context[AppState] works on prompts and resource templates, not only on tools (#3624).
  • An explicit "structuredContent": null is checked against the output schema instead of being treated as missing (#3621).
  • A progress_callback that raises no longer fails the call on an in-process Client(server) (#3623).
  • Client OpenTelemetry spans record JSON-RPC error responses. With mode="auto", connecting to a server without server/discover now shows one ERROR span for the probe (#3629).
  • stdio_client resolves the executable off the event loop on Windows (#3510).

... (truncated)

Commits
  • 2118f14 docs: refresh translations for recent English changes (#3636)
  • ed9b2d6 Stop counting an interactive OAuth login against request timeouts (#3635)
  • d5cebd1 Keep inline-snapshot disabled when pytest runs in a terminal (#3634)
  • c15566c Link What's new to the Header parameters page (#3632)
  • 4d29994 Let a newer Deploy Docs run cancel the one in progress (#3633)
  • 0acea60 Bump urllib3 from 2.7.0 to 2.8.0 (#3607)
  • c54075c Look the tool schema up by name for Mcp-Param-* validation instead of running...
  • 9afccae Retry a tool call once after a HeaderMismatch rejection (#3627)
  • cafa33b Record JSON-RPC error responses on the client OpenTelemetry span (#3629)
  • 0b2fd3e Omit an empty _meta and empty params from outbound requests (#3628)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [mcp](https://github.com/modelcontextprotocol/python-sdk) to permit the latest version.
- [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md)
- [Commits](modelcontextprotocol/python-sdk@v1.2.0...v2.3.0)

---
updated-dependencies:
- dependency-name: mcp
  dependency-version: 2.3.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 9, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedmcp@​1.30.0 ⏵ 2.3.099100100100100

View full report

@github-actions github-actions Bot added the mcp-server Python MCP server and data label Oct 9, 2026
@TMHSDigital

Copy link
Copy Markdown
Owner

@dependabot ignore this major version

@TMHSDigital

Copy link
Copy Markdown
Owner

Closing: mcp 2.x is a major upgrade. The server is pinned below 2 on purpose until it is migrated and tested separately.

@TMHSDigital TMHSDigital closed this Oct 9, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot @github

dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you about version 2.x.x again, unless you re-open this PR.

@dependabot
dependabot Bot deleted the dependabot/pip/mcp-server/mcp-gte-2.3.0-and-lt-3 branch October 9, 2026 03:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file mcp-server Python MCP server and data python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant