Repository navigation
fix(deps): update toolhive - #1089
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Contributor
Author
ℹ️ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
Contributor
🔒 MCP Security Scan Results |
renovate
Bot
force-pushed
the
renovate/toolhive
branch
from
October 8, 2026 19:33
729545d to
666d66a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.42.1→v0.51.4v0.0.38→v0.0.51Release Notes
stacklok/toolhive (github.com/stacklok/toolhive)
v0.51.4Compare Source
What's Changed
Full Changelog: stacklok/toolhive@v0.51.3...v0.51.4
v0.51.3Compare Source
Security
Embedded authorization server: upstream callback bound to the initiating browser (GHSA-2gjv-f568-6cxp, High)
/oauth/callbackcompleted a login for whichever browser arrived with a valid upstreamstate. An attacker who started an authorization for their own client could hand the upstream identity provider URL to a victim and receive an authorization code minted for the victim's identity. The device flow's verification-page login shared the same gap.Both flows now bind the login to the browser that started it:
/oauth/authorizeandPOST /oauth/deviceset a per-flow cookie whose hash is stored on the pending record, and the callback completes only when the same browser presents it. The device verification form additionally requires an anti-forgery token, so a cross-site page cannot start a device login from a victim's browser.What changes for operators and tooling
/oauth/authorizeor the device verification page, with cookies enabled for that host. Headless drivers that walk the flow with a plain HTTP client must carry cookies between steps, and must load the device verification form before posting auser_code.redirect_uri, defaulting to{resourceUrl}/oauth/callbackin the operator) must share a hostname with the browser-facing authorize URL (authorizationEndpointBaseUrl, elseissuer). If the authorize URL ishttps, a non-loopback callback must behttpstoo. Mismatched deployments log aWARNat startup naming the upstream, and every browser login through it is rejected until fixed.authorizationEndpointBaseUrlis set, the device flow'sverification_uriis now advertised from that base URL instead of the issuer.What's Changed
Full Changelog: stacklok/toolhive@v0.51.2...v0.51.3
v0.51.2Compare Source
What's Changed
Full Changelog: stacklok/toolhive@v0.51.1...v0.51.2
v0.51.1Compare Source
What's Changed
Full Changelog: stacklok/toolhive@v0.51.0...v0.51.1
v0.51.0Compare Source
What's Changed
New Contributors
Full Changelog: stacklok/toolhive@v0.50.0...v0.51.0
v0.50.0Compare Source
What's Changed
New Contributors
Full Changelog: stacklok/toolhive@v0.49.0...v0.50.0
v0.49.0Compare Source
🚀 Toolhive v0.49.0 is live!
A security- and auth-correctness release: a signer-pin bypass in
thv skill upgradeis closed, the embedded auth server's documented zero-downtime key rotation finally works, and AWS STS role claims now fail closed instead of silently handing out the fallback role. This release also ships a dependency-light generated Go client for the management API, and moves the project to Go 1.27.pkg/vmcp/session.WithDialControlremoved — vMCP embedders who set a dial-control hook on the session factory get a compile error; wrap the hook in the newWithDialControlResolver(migration guide below).oauth2upstreams with a client secret and no explicittokenEndpointAuthMethodgo back to sending credentials in the POST body instead of HTTP Basic; setclient_secret_basicexplicitly if your IdP requires it (migration guide below).go://workloads default togolang:1.27-alpine— builds pinned to Go 1.26 withGOTOOLCHAIN=localfail, andgo://servers that do not compile under Go 1.27 need an explicit image pin (migration guide below).Migration guide:
session.WithDialControl→session.WithDialControlResolverAffects Go embedders of vMCP that called
session.WithDialControl— the option added in v0.48.0 by #6547. The option was address-blind, so every backend received the samenet.Dialer.Controlhook and a per-backend dial policy could not be expressed. It is replaced in place rather than deprecated alongside a second option.On v0.49.0 the old call fails to compile with
undefined: session.WithDialControl.pkg/vmcp/client.WithDialControlis unchanged. Only thepkg/vmcp/sessionoption was renamed — do not migrateclient.WithDialControlcall sites.Before
After
Per-backend policy — the capability this unlocks. Returning
nilfor a workload leaves that backend onhttp.DefaultTransport, byte-for-byte identical to the no-hook path:Migration steps
session.WithDialControl(call site in thepkg/vmcp/sessionpackage — notpkg/vmcp/client, whose identically-named option is unchanged.session.WithDialControlResolver.func(workloadID string) func(network, address string, c syscall.RawConn) error { return hook }to preserve v0.48.0 semantics exactly.workloadIDto vary policy per backend; returnnilto leave a backend untouched.address— deciding allow/deny fromworkloadIDalone provides no network-level protection.PR: #6567
Migration guide: OAuth2 upstream
tokenEndpointAuthMethoddefaultAffects anyone on v0.48.0 with a pure
oauth2-type upstream provider that uses a pre-registeredclientIdplus a client secret and leavestokenEndpointAuthMethodunset.#6543 (shipped in v0.48.0, and only in v0.48.0) added the
token_endpoint_auth_methodfield, but also made an unset field silently default toclient_secret_basicwhenever a secret was configured — flipping every existing pre-registered upstream from POST-body credentials to HTTP Basic with no opt-in. v0.49.0 restores the historical default while keeping the new field.The auth style is strict, not probing: an unset method sends credentials in the token-request POST body and does not retry with Basic. Against a Basic-only IdP the exchange fails with
invalid_client— on both initial login and token refresh.OIDC-type upstreams and Dynamic Client Registration upstreams are unaffected.
Before
After
Raw auth-server run config:
Migration steps
oauth2upstream with a client secret.token_endpoint_auth_methods_supportedin its discovery document, or its client registration. If onlyclient_secret_basicis accepted, act.tokenEndpointAuthMethod: client_secret_basicon every affectedupstreamProviders[].oauth2Config(spec.embeddedAuthServer.upstreamProviders[]forMCPExternalAuthConfig,spec.authServerConfig.upstreamProviders[]forVirtualMCPServer), ortoken_endpoint_auth_methodunderupstreams[].oauth2_configin a raw run config.The CRD schema is unchanged apart from doc text, so there is no CRD upgrade ordering concern.
PR: #6648
Migration guide: AWS STS role claim shapes now fail closed
Affects deployments using an
awsStsexternal auth config with claim-basedroleMappings. Matcher-expression-only configurations are unaffected.Role mappings are evaluated with the CEL expression
claim_value in claims[role_claim_key], and CEL'sinonly has list and map overloads. Two bugs followed: a string role claim raised a swallowed "no such overload" error and silently produced the fallback role even on an exact match, and an object role claim madeintest map-key membership, matching spuriously. Both are now corrected, and unsupported shapes fail closed rather than quietly granting a role.Two behavior changes, both deliberate:
claimnow selects its mapped role instead offallbackRoleArn. Strings that merely contain the value still do not match.Failed to determine IAM rolefrom theaws_stsmiddleware, or a failed backend call withfailed to select IAM rolein vMCP outbound auth.A missing role claim still falls back exactly as before.
Before
{ "sub": "user1", "groups": { "admins": true } } { "sub": "user2", "groups": 7 }After
{ "sub": "user1", "groups": ["admins"] } { "sub": "user1", "groups": "admins" }Migration steps
awsStsconfig and inspect the claim named byawsSts.roleClaim(defaultgroups).fallbackRoleArn. Verify the mapped role's IAM trust policy accepts these subjects and that its permissions suit that population.realm_access.rolesto a top-level key —roleClaimis a flat lookup, not a dot path). Alternatively pointroleClaimat a correctly-shaped claim, or convert those mappings tomatcherCEL expressions, which are evaluated against the raw claims and are unaffected.role claim has unsupported shape, failing closedandclaim-based role mapping evaluation failed, failing closed— they name the offendingrole_arn. Note thatCEL expression evaluation failed, skipping mappingwas promoted from Debug to Warn, so pre-existing matcher-expression bugs will now appear at default log level.PR: #6306 — Closes #6305
Migration guide: Go 1.27 toolchain and
go://builder imageTwo separate audiences.
go://workload users. The default builder image forgo://workloads moved fromgolang:1.26-alpinetogolang:1.27-alpine. Only freshly builtgo://workloads with no override are affected. Go's compatibility promise makes a failure unlikely, but a server relying on a removed deprecated API will not compile.Downstream Go importers of the root module.
github.com/stacklok/toolhivenow declaresgo 1.27.0with notoolchaindirective. Under the defaultGOTOOLCHAIN=autoGo downloads 1.27 transparently; underGOTOOLCHAIN=local, a pinned-toolchain CI, an air-gapped build, or a distro-packaged Go, the build fails hard withgo: go.mod requires go >= 1.27. The nestedgithub.com/stacklok/toolhive/sdk/gomodule deliberately keeps itsgo 1.26.0floor and is not affected.Before
After
Migration steps
go://run, pin per invocation:thv run go://github.com/example/server --runtime-image golang:1.26-alpine.runtime_configs.go.builder_imagein~/.toolhive/config.yamlas above.additional_packagesreplaces rather than appends to the built-in["ca-certificates", "git"], so list them explicitly. Only the builder stage is customizable for Go workloads; the runtime stage is alwaysalpine:3.23.GOTOOLCHAIN=autoand allow Go to fetch the toolchain on demand.github.com/stacklok/toolhive/sdk/goinstead — it retains thego 1.26.0floor.setup-goat the rootgo-version-file: go.modrather than pinning a version.PR: #6639
🆕 New Features
github.com/stacklok/toolhive/sdk/gomodule provides a typed, generated client covering all 77 documented management API operations, with safe default timeout and response-size handling, without pulling in ToolHive's full application dependency graph (#6637).skills/getmaps toAction::"get_skill"on the skill's exact URI, andskills/listresponses are filtered to the skills the caller may get — previously both methods were refused outright by default-deny, andskills/listwithout aget_skillpermit now returns an empty list instead of a 403 (#6512).thv ai-plugin push --key <cosign.key>is available again for publishers using automatic local server discovery, now that key-signed plugins can be verified at install time withthv ai-plugin install --public-keyand pinned intoolhive.lock.yamlfor latersync/upgrade; remote or manually configured API URLs must still sign keylessly (#6528).WARNthat names the store so an unintended downgrade stays visible (#6551).🐛 Bug Fixes
thv skill upgrade --allow-signer-changeno longer doubles as unsigned consent — it previously succeeded against an unsigned candidate, silently dropping a signer-pinned skill's recorded identity and rewriting the lock entry asunsigned: true; boththv skill upgradeandthv ai-plugin upgradenow reportfailed [unsigned-rejected]and name theuninstall … --scope projecttheninstall … --scope project --allow-unsignedsequence that records the exception explicitly (#6629)./.well-known/jwks.jsonnow publishes configured fallback keys alongside the signing key (primary first, de-duplicated bykid), making the documented three-step zero-downtime signing-key rotation actually work instead of a hard cutover that invalidated every outstanding JWT (#6638 — Closes #6451).notifications/progressframes are flushed to the SSE stream, in backend order, before the response closes it (#6491 — Closes #6349).spec.podTemplateSpecno longer get ametadata.generationbump and a spuriousDeploymentUpdatedevent on everystatusReportingIntervaltick, including the 30s default — pod-template drift detection was comparing user-merged label maps for exact equality (#6377 — Fixes #6340).invalid_client,invalid_grant, …) where a wrapped error could previously degrade to a genericserver_error(#6639).🧹 Misc
miniredisimport that broke typecheck — and therefore every test — inpkg/authserver/runneronmain(#6636).📦 Dependencies
github.com/stacklok/toolhive-coreAlso migrates all Redis call sites from the now-deprecated
toolhive-core/rediscompatibility facade toredisconndirectly (#6646).👋 Welcome to our newest contributor: @isaacgao4396 🎉
Full commit log
What's Changed
New Contributors
Full Changelog: stacklok/toolhive@v0.48.0...v0.49.0
🔗 Full changelog: stacklok/toolhive@v0.48.0...v0.49.0
v0.48.0Compare Source
What's Changed
89a6a09by @renovate[bot] in #577985c1c22by @renovate[bot] in #6172Full Changelog: stacklok/toolhive@v0.47.1...v0.48.0
v0.47.1Compare Source
What's Changed
Full Changelog: stacklok/toolhive@v0.47.0...v0.47.1
v0.47.0Compare Source
What's Changed
Configuration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.