chore(deps): update mcp requirement from <2,>=1.28.1 to >=2.1.1,<3 - #2288
chore(deps): update mcp requirement from <2,>=1.28.1 to >=2.1.1,<3#2288dependabot[bot] wants to merge 1 commit into
Conversation
ReviewThis PR (dependabot) bumps Bug: contradicts the pin's own explanatory comment (
|
Updates the requirements on [mcp](https://github.com/modelcontextprotocol/python-sdk) to permit the latest version. - [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases) - [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md) - [Commits](modelcontextprotocol/python-sdk@v1.28.1...v2.1.1) --- updated-dependencies: - dependency-name: mcp dependency-version: 2.1.1 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
205eae7 to
96d597d
Compare
|
Automated review This is a Dependabot bump of
I confirmed both halves of that concern are still true on this branch:
Given the diff is just the version bump (the comment block explaining the constraint wasn't updated/removed), this looks like it hasn't accounted for that guardrail yet. Suggest closing/blocking until:
No other files are touched by this PR, so there's nothing else to review code-quality/test-coverage-wise — the only concern is that merging it breaks the app per the codebase's own documented constraint. |
Investigation notesThe pip-resolution blocker documented in But the actual code migration is substantial, not a rename.
This is a full API-surface migration of the MCP server, not a mechanical bump. Holding this PR open pending a dedicated migration effort (tracked separately) rather than merging as part of a routine dependabot pass. Whoever picks it up: also bump the |
Updates the requirements on mcp to permit the latest version.
Release notes
Sourced from mcp's releases.
Commits
0921d94Point imports of mcp.server.fastmcp at the migration guide (#3388)4d6f87eBuild releases with the pinned hatchling and a publish action that accepts Me...c5d7d0bdocs: refresh translations for recent English changes (#3379)d8b6383Give recursive tool return types an object-rooted output schema (#3376)56af447Log MCPServer handler exceptions by kind and keep crash details off the wire ...f1c40b0Accept boolean sub-schemas in 2025-11-25 tool schema properties (#3354)57394b0Apply the request body limit to the SSE and OAuth endpoints (#3336)0cee624Hand TypedDict tool results to pydantic natively (#3331)0d92192Shorten stdio test comments (#3329)b2025abAcknowledge notification POSTs with 202 on the 2026-07-28 HTTP entry (#3326)