Skip to content

chore(deps): require fastmcp 4.1.0 and mcp 2.3.0 - #53

Merged
christianclaudio merged 1 commit into
mainfrom
cursor/fastmcp-4.1.0-floor
Oct 10, 2026
Merged

christianclaudio merged 1 commit into
mainfrom
cursor/fastmcp-4.1.0-floor

Conversation

@christianclaudio

@christianclaudio christianclaudio commented Oct 10, 2026 •

Copy link
Copy Markdown
Owner

Why

Template v1.7.0 (#82) raised the FastMCP floor to 4.1.0 and mcp to 2.3.0. This copies both floors here so the product matches the template. Nothing in src/ or tests/ needed to change.

Changes

  • pyproject.toml (core), fastmcp.json: fastmcp>=4.0.11 becomes >=4.1.0 and mcp>=2.2.0 becomes >=2.3.0.
  • uv.lock: refreshed with uv lock --upgrade-package fastmcp --upgrade-package mcp only. No other package was upgraded.
  • README.md: the template's idle-session line, added as a paragraph after the endpoint line in the HTTP transport section, because this README documents serving Streamable HTTP in the default stateful mode.

No source or test changes. No version bump.

Audit (src, tests, docs, README)

  • Tool Search (#5467): RegexSearchTransform() is opt-in (src/espn_mcp/server.py:185); no test or doc passes a pattern. The lookarounds and backreferences in errors.py belong to the redaction patterns. Python's re compiles them, not Tool Search, so they are unaffected.
  • Code Mode: No Code Mode in this repo; no CodeMode( or max_duration_secs.
  • HTTP idle expiry (#5229): session_idle_timeout is not set anywhere, so stateful HTTP deployments now expire sessions after 30 idle minutes (HTTP 404, and the client starts a new session). The HTTP tests build stateless apps, and the stateless_http=False assertions only check the arguments passed to run(), so the tests are unaffected. The README line documents this.
  • No x-mcp-header annotations (#3620), no ctx.meta / ctx.params reads (#3628), no MultiAuth, no skills, and no OpenAPI ./.. path parameters.

FastMCP 4.1.0 (release) and mcp 2.3.0 (release)

The items that apply here are the Tool Search engine change, the 30-minute idle expiry and the Monty 1.1 rename above. The other breaking items in 4.1.0 (MultiAuth client IDs, skill file paths, OpenAPI path parameters, Python 3.15) touch nothing used here. In mcp 2.3.0, httpx2>=2.10.0 (#3600) was already satisfied. #3630 (Mcp-Param-* lookup by name) and #3635 (OAuth login vs request timeouts, client side) need nothing here.

Lock changes

Package Before After
fastmcp 4.0.11 4.1.0
fastmcp-slim 4.0.11 4.1.0
mcp 2.2.0 2.3.0
mcp-types 2.2.0 2.3.0
beartype 0.22.9 0.22.9 (Python < 3.15) and 0.23.0 (Python >= 3.15)

Why beartype is locked twice: this is deliberate, not drift, and it matches template v1.7.0. fastmcp-slim 4.1.0 adds beartype>=0.23.0rc2; python_version >= "3.15" (#5558), so uv forks the resolution at 3.15. Below 3.15, only py-key-value-aio's beartype>=0.20.0 applies, and uv keeps the 0.22.9 already locked because beartype wasn't upgraded. Python 3.10 to 3.13, the versions CI runs, still install 0.22.9.

Tests

No test changes. On Python 3.10, 3.11, 3.12 and 3.13, with CI=true and --extra dev, 474 passed, 1 deselected (the deselected one is the opt-in e2e test), at 100% coverage. The 3.12 run gave the same result with ESPN_MCP_AUTH_TOKEN and ESPN_MCP_ALLOW_UNAUTHENTICATED_BIND exported in the shell.

Gates

  • ruff check . and ruff format --check .: clean
  • mypy --strict src: clean
  • uv lock --check: clean
  • scripts/check_tool_contract.py: passed
  • scripts/check_openapi_drift.py: passed
  • scripts/check_version.py (on a fresh uv build): passed
  • scripts/check_conformance.sh: the baseline check passed (12 passed; all 20 failures are expected and in the baseline)
  • Raised minimum dependencies to FastMCP 4.1.0 and MCP 2.3.0 in pyproject.toml and fastmcp.json, and updated uv.lock.
  • Documented the default 30-minute idle timeout for stateful HTTP sessions, the resulting HTTP 404, and how to configure or disable the timeout.

Tool surface: none
Config: Documented FASTMCP_HTTP_SESSION_IDLE_TIMEOUT (seconds; none disables expiry).

## Why

Template v1.7.0 (#82) raised the FastMCP floor to 4.1.0 and mcp to 2.3.0. This copies both floors here so the product matches the template. Nothing in `src/` or `tests/` needed to change.

## Changes

- `pyproject.toml` (core), `fastmcp.json`: `fastmcp>=4.0.11` becomes `>=4.1.0` and `mcp>=2.2.0` becomes `>=2.3.0`.
- `uv.lock`: refreshed with `uv lock --upgrade-package fastmcp --upgrade-package mcp` only. No other package was upgraded.
- `README.md`: the template's idle-session line, added as a paragraph after the endpoint line in the HTTP transport section, because this README documents serving Streamable HTTP in the default stateful mode.

No source or test changes. No version bump.

## Audit (src, tests, docs, README)

- Tool Search ([#5467](PrefectHQ/fastmcp#5467)): `RegexSearchTransform()` is opt-in (`src/espn_mcp/server.py:185`); no test or doc passes a pattern. The lookarounds and backreferences in `errors.py` belong to the redaction patterns. Python's `re` compiles them, not Tool Search, so they are unaffected.
- Code Mode: No Code Mode in this repo; no `CodeMode(` or `max_duration_secs`.
- HTTP idle expiry ([#5229](PrefectHQ/fastmcp#5229)): `session_idle_timeout` is not set anywhere, so stateful HTTP deployments now expire sessions after 30 idle minutes (HTTP 404, and the client starts a new session). The HTTP tests build stateless apps, and the `stateless_http=False` assertions only check the arguments passed to `run()`, so the tests are unaffected. The README line documents this.
- No `x-mcp-header` annotations ([#3620](modelcontextprotocol/python-sdk#3620)), no `ctx.meta` / `ctx.params` reads ([#3628](modelcontextprotocol/python-sdk#3628)), no `MultiAuth`, no skills, and no OpenAPI `.`/`..` path parameters.

## FastMCP 4.1.0 ([release](https://github.com/PrefectHQ/fastmcp/releases/tag/v4.1.0)) and mcp 2.3.0 ([release](https://github.com/modelcontextprotocol/python-sdk/releases/tag/v2.3.0))

The items that apply here are the Tool Search engine change, the 30-minute idle expiry and the Monty 1.1 rename above. The other breaking items in 4.1.0 (MultiAuth client IDs, skill file paths, OpenAPI path parameters, Python 3.15) touch nothing used here. In mcp 2.3.0, `httpx2>=2.10.0` ([#3600](modelcontextprotocol/python-sdk#3600)) was already satisfied. [#3630](modelcontextprotocol/python-sdk#3630) (`Mcp-Param-*` lookup by name) and [#3635](modelcontextprotocol/python-sdk#3635) (OAuth login vs request timeouts, client side) need nothing here.

## Lock changes

| Package | Before | After |
|---|---|---|
| fastmcp | 4.0.11 | 4.1.0 |
| fastmcp-slim | 4.0.11 | 4.1.0 |
| mcp | 2.2.0 | 2.3.0 |
| mcp-types | 2.2.0 | 2.3.0 |
| beartype | 0.22.9 | 0.22.9 (Python < 3.15) and 0.23.0 (Python >= 3.15) |

**Why beartype is locked twice:** this is deliberate, not drift, and it matches template v1.7.0. `fastmcp-slim` 4.1.0 adds `beartype>=0.23.0rc2; python_version >= "3.15"` ([#5558](PrefectHQ/fastmcp#5558)), so uv forks the resolution at 3.15. Below 3.15, only `py-key-value-aio`'s `beartype>=0.20.0` applies, and uv keeps the 0.22.9 already locked because beartype wasn't upgraded. Python 3.10 to 3.13, the versions CI runs, still install 0.22.9.

## Tests

No test changes. On Python 3.10, 3.11, 3.12 and 3.13, with `CI=true` and `--extra dev`, 474 passed, 1 deselected (the deselected one is the opt-in e2e test), at 100% coverage. The 3.12 run gave the same result with `ESPN_MCP_AUTH_TOKEN` and `ESPN_MCP_ALLOW_UNAUTHENTICATED_BIND` exported in the shell.

## Gates

- `ruff check .` and `ruff format --check .`: clean
- `mypy --strict src`: clean
- `uv lock --check`: clean
- `scripts/check_tool_contract.py`: passed
- `scripts/check_openapi_drift.py`: passed
- `scripts/check_version.py` (on a fresh `uv build`): passed
- `scripts/check_conformance.sh`: the baseline check passed (12 passed; all 20 failures are expected and in the baseline)
@coderabbitai

coderabbitai Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: QUIET
  • Plan: Advanced
  • Run ID: 6b0471f0-4afa-41ab-8985-86ef109b55f7

📥 Commits

Reviewing files that changed from the base of the PR and between c28acac and f6281ee.


⛔ Files ignored due to path filters (1)
  • uv.lock is excluded by !**/*.lock

📒 Files selected for processing (3)
  • README.md
  • fastmcp.json
  • pyproject.toml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📜 Recent review details
⏰ Context from checks skipped due to timeout. (8)
  • GitHub Check: Tests (py3.13)
  • GitHub Check: Tool contract assertions
  • GitHub Check: Build and package check
  • GitHub Check: Tests (py3.12)
  • GitHub Check: Lint and types
  • GitHub Check: Tests (py3.11)
  • GitHub Check: Tests (py3.10)
  • GitHub Check: CodeQL Security Scan

🧰 Additional context used
📚 Code guidelines (2)
AGENTS.md — configured
README.md — auto-discovered

📓 Path-based instructions (4)
Dependency floors.

⚙️ CodeRabbit configuration file

Files:

  • pyproject.toml
  • fastmcp.json

README is the user contract for env vars, tool lists, and install steps: flag text that contradicts the code in this PR (renamed or removed tools, env vars, defaults).

⚙️ CodeRabbit configuration file

Files:

  • README.md

Source excerpt: **Git Safety & Releases**: Never commit secrets.

📄 CodeRabbit inference engine (AGENTS.md)

Files:

  • pyproject.toml
  • README.md

Source excerpt: When developing, hardening, or extending MCP servers, consult the official framework and protocol references: Source excerpt: After an upgrade, reload the MCP host so the live process start time is after the new binary mtime...

📄 CodeRabbit inference engine (README.md)

Files:

  • README.md

🔇 Additional comments (3)
pyproject.toml (1)

29-30: LGTM!


fastmcp.json (1)

9-10: LGTM!


README.md (1)

313-313: LGTM!



📝 Walkthrough

Walkthrough

The minimum FastMCP and MCP dependency versions increase. The README now documents stateful HTTP session expiration after 30 minutes of inactivity, the resulting HTTP 404, and timeout configuration options.

Changes

HTTP session timeout documentation and dependency minimums

Layer / File(s) Summary
Dependency minimums and timeout documentation
pyproject.toml, fastmcp.json, README.md
The minimum versions for fastmcp and mcp increase to 4.1.0 and 2.3.0. The README documents the 30-minute idle timeout, HTTP 404 behavior, and configuration options, including disabling expiration with none.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Suggested labels: dependencies


Merge Risk: ⚪ Minimal · up to f6281

The dependency minimums and timeout documentation have no identified merge-blocking issue; the documented session behavior matches the specified versions.

Pre-merge checks | Passed 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly and concisely describes the main change: increasing the minimum required FastMCP and MCP versions.
Docstring Coverage Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@christianclaudio
christianclaudio merged commit c641edc into main Oct 10, 2026
11 checks passed
@christianclaudio
christianclaudio deleted the cursor/fastmcp-4.1.0-floor branch October 10, 2026 13:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant