Repository navigation
chore(deps): require fastmcp 4.1.0 and mcp 2.3.0 - #53
Conversation
## Why Template v1.7.0 (#82) raised the FastMCP floor to 4.1.0 and mcp to 2.3.0. This copies both floors here so the product matches the template. Nothing in `src/` or `tests/` needed to change. ## Changes - `pyproject.toml` (core), `fastmcp.json`: `fastmcp>=4.0.11` becomes `>=4.1.0` and `mcp>=2.2.0` becomes `>=2.3.0`. - `uv.lock`: refreshed with `uv lock --upgrade-package fastmcp --upgrade-package mcp` only. No other package was upgraded. - `README.md`: the template's idle-session line, added as a paragraph after the endpoint line in the HTTP transport section, because this README documents serving Streamable HTTP in the default stateful mode. No source or test changes. No version bump. ## Audit (src, tests, docs, README) - Tool Search ([#5467](PrefectHQ/fastmcp#5467)): `RegexSearchTransform()` is opt-in (`src/espn_mcp/server.py:185`); no test or doc passes a pattern. The lookarounds and backreferences in `errors.py` belong to the redaction patterns. Python's `re` compiles them, not Tool Search, so they are unaffected. - Code Mode: No Code Mode in this repo; no `CodeMode(` or `max_duration_secs`. - HTTP idle expiry ([#5229](PrefectHQ/fastmcp#5229)): `session_idle_timeout` is not set anywhere, so stateful HTTP deployments now expire sessions after 30 idle minutes (HTTP 404, and the client starts a new session). The HTTP tests build stateless apps, and the `stateless_http=False` assertions only check the arguments passed to `run()`, so the tests are unaffected. The README line documents this. - No `x-mcp-header` annotations ([#3620](modelcontextprotocol/python-sdk#3620)), no `ctx.meta` / `ctx.params` reads ([#3628](modelcontextprotocol/python-sdk#3628)), no `MultiAuth`, no skills, and no OpenAPI `.`/`..` path parameters. ## FastMCP 4.1.0 ([release](https://github.com/PrefectHQ/fastmcp/releases/tag/v4.1.0)) and mcp 2.3.0 ([release](https://github.com/modelcontextprotocol/python-sdk/releases/tag/v2.3.0)) The items that apply here are the Tool Search engine change, the 30-minute idle expiry and the Monty 1.1 rename above. The other breaking items in 4.1.0 (MultiAuth client IDs, skill file paths, OpenAPI path parameters, Python 3.15) touch nothing used here. In mcp 2.3.0, `httpx2>=2.10.0` ([#3600](modelcontextprotocol/python-sdk#3600)) was already satisfied. [#3630](modelcontextprotocol/python-sdk#3630) (`Mcp-Param-*` lookup by name) and [#3635](modelcontextprotocol/python-sdk#3635) (OAuth login vs request timeouts, client side) need nothing here. ## Lock changes | Package | Before | After | |---|---|---| | fastmcp | 4.0.11 | 4.1.0 | | fastmcp-slim | 4.0.11 | 4.1.0 | | mcp | 2.2.0 | 2.3.0 | | mcp-types | 2.2.0 | 2.3.0 | | beartype | 0.22.9 | 0.22.9 (Python < 3.15) and 0.23.0 (Python >= 3.15) | **Why beartype is locked twice:** this is deliberate, not drift, and it matches template v1.7.0. `fastmcp-slim` 4.1.0 adds `beartype>=0.23.0rc2; python_version >= "3.15"` ([#5558](PrefectHQ/fastmcp#5558)), so uv forks the resolution at 3.15. Below 3.15, only `py-key-value-aio`'s `beartype>=0.20.0` applies, and uv keeps the 0.22.9 already locked because beartype wasn't upgraded. Python 3.10 to 3.13, the versions CI runs, still install 0.22.9. ## Tests No test changes. On Python 3.10, 3.11, 3.12 and 3.13, with `CI=true` and `--extra dev`, 474 passed, 1 deselected (the deselected one is the opt-in e2e test), at 100% coverage. The 3.12 run gave the same result with `ESPN_MCP_AUTH_TOKEN` and `ESPN_MCP_ALLOW_UNAUTHENTICATED_BIND` exported in the shell. ## Gates - `ruff check .` and `ruff format --check .`: clean - `mypy --strict src`: clean - `uv lock --check`: clean - `scripts/check_tool_contract.py`: passed - `scripts/check_openapi_drift.py`: passed - `scripts/check_version.py` (on a fresh `uv build`): passed - `scripts/check_conformance.sh`: the baseline check passed (12 passed; all 20 failures are expected and in the baseline)
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info
📜 Recent review details
📝 Walkthrough
Merge Risk: ⚪ Minimal · up to The dependency minimums and timeout documentation have no identified merge-blocking issue; the documented session behavior matches the specified versions. Pre-merge checks |
|
Why
Template v1.7.0 (#82) raised the FastMCP floor to 4.1.0 and mcp to 2.3.0. This copies both floors here so the product matches the template. Nothing in
src/ortests/needed to change.Changes
pyproject.toml(core),fastmcp.json:fastmcp>=4.0.11becomes>=4.1.0andmcp>=2.2.0becomes>=2.3.0.uv.lock: refreshed withuv lock --upgrade-package fastmcp --upgrade-package mcponly. No other package was upgraded.README.md: the template's idle-session line, added as a paragraph after the endpoint line in the HTTP transport section, because this README documents serving Streamable HTTP in the default stateful mode.No source or test changes. No version bump.
Audit (src, tests, docs, README)
RegexSearchTransform()is opt-in (src/espn_mcp/server.py:185); no test or doc passes a pattern. The lookarounds and backreferences inerrors.pybelong to the redaction patterns. Python'srecompiles them, not Tool Search, so they are unaffected.CodeMode(ormax_duration_secs.session_idle_timeoutis not set anywhere, so stateful HTTP deployments now expire sessions after 30 idle minutes (HTTP 404, and the client starts a new session). The HTTP tests build stateless apps, and thestateless_http=Falseassertions only check the arguments passed torun(), so the tests are unaffected. The README line documents this.x-mcp-headerannotations (#3620), noctx.meta/ctx.paramsreads (#3628), noMultiAuth, no skills, and no OpenAPI./..path parameters.FastMCP 4.1.0 (release) and mcp 2.3.0 (release)
The items that apply here are the Tool Search engine change, the 30-minute idle expiry and the Monty 1.1 rename above. The other breaking items in 4.1.0 (MultiAuth client IDs, skill file paths, OpenAPI path parameters, Python 3.15) touch nothing used here. In mcp 2.3.0,
httpx2>=2.10.0(#3600) was already satisfied. #3630 (Mcp-Param-*lookup by name) and #3635 (OAuth login vs request timeouts, client side) need nothing here.Lock changes
Why beartype is locked twice: this is deliberate, not drift, and it matches template v1.7.0.
fastmcp-slim4.1.0 addsbeartype>=0.23.0rc2; python_version >= "3.15"(#5558), so uv forks the resolution at 3.15. Below 3.15, onlypy-key-value-aio'sbeartype>=0.20.0applies, and uv keeps the 0.22.9 already locked because beartype wasn't upgraded. Python 3.10 to 3.13, the versions CI runs, still install 0.22.9.Tests
No test changes. On Python 3.10, 3.11, 3.12 and 3.13, with
CI=trueand--extra dev, 474 passed, 1 deselected (the deselected one is the opt-in e2e test), at 100% coverage. The 3.12 run gave the same result withESPN_MCP_AUTH_TOKENandESPN_MCP_ALLOW_UNAUTHENTICATED_BINDexported in the shell.Gates
ruff check .andruff format --check .: cleanmypy --strict src: cleanuv lock --check: cleanscripts/check_tool_contract.py: passedscripts/check_openapi_drift.py: passedscripts/check_version.py(on a freshuv build): passedscripts/check_conformance.sh: the baseline check passed (12 passed; all 20 failures are expected and in the baseline)pyproject.tomlandfastmcp.json, and updateduv.lock.Tool surface: none
Config: Documented
FASTMCP_HTTP_SESSION_IDLE_TIMEOUT(seconds;nonedisables expiry).