Skip to content

chore(deps): require fastmcp 4.1.0 and mcp 2.3.0 - #45

Merged
christianclaudio merged 1 commit into
mainfrom
cursor/fastmcp-4.1.0-floor
Oct 10, 2026
Merged

christianclaudio merged 1 commit into
mainfrom
cursor/fastmcp-4.1.0-floor

Conversation

@christianclaudio

@christianclaudio christianclaudio commented Oct 10, 2026 •

Copy link
Copy Markdown
Owner

Why

Template v1.7.0 (#82) raised the FastMCP floor to 4.1.0 and mcp to 2.3.0. This copies both floors here so the product matches the template. Nothing in src/ or tests/ needed to change.

Changes

  • pyproject.toml (core and both code-mode / dev extras), fastmcp.json: fastmcp>=4.0.11 becomes >=4.1.0 and mcp>=2.2.0 becomes >=2.3.0.
  • uv.lock: refreshed with uv lock --upgrade-package fastmcp --upgrade-package mcp only. No other package was upgraded.
  • README.md: the template's idle-session line, added as a bullet under the HTTP authentication list, because this README documents serving Streamable HTTP in the default stateful mode.

No source or test changes. No version bump.

Audit (src, tests, docs, README)

  • Tool Search (#5467): Regex (default) or BM25 Tool Search is opt-in (src/sigma_mcp/server.py:415). Test patterns are plain words (workbooks_, workbooks_list) and \b<name>\b in tests/test_client_surface.py:204; the rust-regex engine supports \b, and that test passes on 4.1.0. The lookarounds and backreferences in errors.py belong to the redaction patterns. Python's re compiles them, not Tool Search, so they are unaffected.
  • Code Mode: CodeMode() is called with no arguments (src/sigma_mcp/server.py), and max_duration_secs appears nowhere, so the Monty 1.1 rename to max_feed_duration_secs (default 30.0) needs no change; Code Mode inherits the new default.
  • HTTP idle expiry (#5229): session_idle_timeout is not set anywhere, so stateful HTTP deployments now expire sessions after 30 idle minutes (HTTP 404, and the client starts a new session). The HTTP tests build stateless apps, and the stateless_http=False assertions only check the arguments passed to run(), so the tests are unaffected. The README line documents this.
  • No x-mcp-header annotations (#3620), no ctx.meta / ctx.params reads (#3628), no MultiAuth, no skills, and no OpenAPI ./.. path parameters.

FastMCP 4.1.0 (release) and mcp 2.3.0 (release)

The items that apply here are the Tool Search engine change, the 30-minute idle expiry and the Monty 1.1 rename above. The other breaking items in 4.1.0 (MultiAuth client IDs, skill file paths, OpenAPI path parameters, Python 3.15) touch nothing used here. In mcp 2.3.0, httpx2>=2.10.0 (#3600) was already satisfied. #3630 (Mcp-Param-* lookup by name) and #3635 (OAuth login vs request timeouts, client side) need nothing here.

Lock changes

Package Before After
fastmcp 4.0.11 4.1.0
fastmcp-slim 4.0.11 4.1.0
mcp 2.2.0 2.3.0
mcp-types 2.2.0 2.3.0
pydantic-monty 0.0.21 1.1.0
pydantic-monty-client 0.0.21 1.1.0
pydantic-monty-runtime 0.0.21 1.1.0
beartype 0.22.9 0.22.9 (Python < 3.15) and 0.23.0 (Python >= 3.15)

Why beartype is locked twice: this is deliberate, not drift, and it matches template v1.7.0. fastmcp-slim 4.1.0 adds beartype>=0.23.0rc2; python_version >= "3.15" (#5558), so uv forks the resolution at 3.15. Below 3.15, only py-key-value-aio's beartype>=0.20.0 applies, and uv keeps the 0.22.9 already locked because beartype wasn't upgraded. Python 3.10 to 3.13, the versions CI runs, still install 0.22.9.

Tests

No test changes. On Python 3.10, 3.11, 3.12 and 3.13, with CI=true and --extra dev --extra code-mode, 830 passed, 9 skipped, 1 deselected (the deselected one is the opt-in e2e test), at 100% coverage. The 3.12 run gave the same result with SIGMA_MCP_AUTH_TOKEN and SIGMA_MCP_ALLOW_UNAUTHENTICATED_BIND exported in the shell.

Gates

  • ruff check . and ruff format --check .: clean
  • mypy --strict src/: clean
  • uv lock --check: clean
  • scripts/check_tool_contract.py: passed
  • scripts/check_openapi_drift.py: the local HTTP 400 came from the review machine's network (DNS), not Sigma's servers. curl gets 200 from the spec URLs, and CI's drift job is green on this PR and on main.
  • scripts/check_version.py (on a fresh uv build): passed
  • scripts/check_conformance.sh: the baseline check passed (12 passed; all 20 failures are expected and in the baseline)
  • Raised the minimum fastmcp version to 4.1.0 and mcp version to 2.3.0 in project and FastMCP configuration; refreshed uv.lock.
  • Documented that stateful HTTP sessions expire after 30 minutes of inactivity by default and that FastMCP settings can change or disable this timeout.

Tool surface: none
Config: none

## Why

Template v1.7.0 (#82) raised the FastMCP floor to 4.1.0 and mcp to 2.3.0. This copies both floors here so the product matches the template. Nothing in `src/` or `tests/` needed to change.

## Changes

- `pyproject.toml` (core and both `code-mode` / `dev` extras), `fastmcp.json`: `fastmcp>=4.0.11` becomes `>=4.1.0` and `mcp>=2.2.0` becomes `>=2.3.0`.
- `uv.lock`: refreshed with `uv lock --upgrade-package fastmcp --upgrade-package mcp` only. No other package was upgraded.
- `README.md`: the template's idle-session line, added as a bullet under the HTTP authentication list, because this README documents serving Streamable HTTP in the default stateful mode.

No source or test changes. No version bump.

## Audit (src, tests, docs, README)

- Tool Search ([#5467](PrefectHQ/fastmcp#5467)): Regex (default) or BM25 Tool Search is opt-in (`src/sigma_mcp/server.py:415`). Test patterns are plain words (`workbooks_`, `workbooks_list`) and `\b<name>\b` in `tests/test_client_surface.py:204`; the rust-regex engine supports `\b`, and that test passes on 4.1.0. The lookarounds and backreferences in `errors.py` belong to the redaction patterns. Python's `re` compiles them, not Tool Search, so they are unaffected.
- Code Mode: `CodeMode()` is called with no arguments (`src/sigma_mcp/server.py`), and `max_duration_secs` appears nowhere, so the Monty 1.1 rename to `max_feed_duration_secs` (default 30.0) needs no change; Code Mode inherits the new default.
- HTTP idle expiry ([#5229](PrefectHQ/fastmcp#5229)): `session_idle_timeout` is not set anywhere, so stateful HTTP deployments now expire sessions after 30 idle minutes (HTTP 404, and the client starts a new session). The HTTP tests build stateless apps, and the `stateless_http=False` assertions only check the arguments passed to `run()`, so the tests are unaffected. The README line documents this.
- No `x-mcp-header` annotations ([#3620](modelcontextprotocol/python-sdk#3620)), no `ctx.meta` / `ctx.params` reads ([#3628](modelcontextprotocol/python-sdk#3628)), no `MultiAuth`, no skills, and no OpenAPI `.`/`..` path parameters.

## FastMCP 4.1.0 ([release](https://github.com/PrefectHQ/fastmcp/releases/tag/v4.1.0)) and mcp 2.3.0 ([release](https://github.com/modelcontextprotocol/python-sdk/releases/tag/v2.3.0))

The items that apply here are the Tool Search engine change, the 30-minute idle expiry and the Monty 1.1 rename above. The other breaking items in 4.1.0 (MultiAuth client IDs, skill file paths, OpenAPI path parameters, Python 3.15) touch nothing used here. In mcp 2.3.0, `httpx2>=2.10.0` ([#3600](modelcontextprotocol/python-sdk#3600)) was already satisfied. [#3630](modelcontextprotocol/python-sdk#3630) (`Mcp-Param-*` lookup by name) and [#3635](modelcontextprotocol/python-sdk#3635) (OAuth login vs request timeouts, client side) need nothing here.

## Lock changes

| Package | Before | After |
|---|---|---|
| fastmcp | 4.0.11 | 4.1.0 |
| fastmcp-slim | 4.0.11 | 4.1.0 |
| mcp | 2.2.0 | 2.3.0 |
| mcp-types | 2.2.0 | 2.3.0 |
| pydantic-monty | 0.0.21 | 1.1.0 |
| pydantic-monty-client | 0.0.21 | 1.1.0 |
| pydantic-monty-runtime | 0.0.21 | 1.1.0 |
| beartype | 0.22.9 | 0.22.9 (Python < 3.15) and 0.23.0 (Python >= 3.15) |

**Why beartype is locked twice:** this is deliberate, not drift, and it matches template v1.7.0. `fastmcp-slim` 4.1.0 adds `beartype>=0.23.0rc2; python_version >= "3.15"` ([#5558](PrefectHQ/fastmcp#5558)), so uv forks the resolution at 3.15. Below 3.15, only `py-key-value-aio`'s `beartype>=0.20.0` applies, and uv keeps the 0.22.9 already locked because beartype wasn't upgraded. Python 3.10 to 3.13, the versions CI runs, still install 0.22.9.

## Tests

No test changes. On Python 3.10, 3.11, 3.12 and 3.13, with `CI=true` and `--extra dev --extra code-mode`, 830 passed, 9 skipped, 1 deselected (the deselected one is the opt-in e2e test), at 100% coverage. The 3.12 run gave the same result with `SIGMA_MCP_AUTH_TOKEN` and `SIGMA_MCP_ALLOW_UNAUTHENTICATED_BIND` exported in the shell.

## Gates

- `ruff check .` and `ruff format --check .`: clean
- `mypy --strict src/`: clean
- `uv lock --check`: clean
- `scripts/check_tool_contract.py`: passed
- `scripts/check_openapi_drift.py`: could not run; Sigma's OpenAPI hosts returned HTTP 400 for every spec URL, and `main` fails the same way, so this is upstream, not this change
- `scripts/check_version.py` (on a fresh `uv build`): passed
- `scripts/check_conformance.sh`: the baseline check passed (12 passed; all 20 failures are expected and in the baseline)
@coderabbitai

coderabbitai Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: QUIET
  • Plan: Advanced
  • Run ID: b6152eef-94a0-4fb3-acfe-a14f5ecda3f3


📥 Commits

Reviewing files that changed from the base of the PR and between 5219b2b and 237bfba.



⛔ Files ignored due to path filters (1)
  • uv.lock is excluded by !**/*.lock


📒 Files selected for processing (3)
  • README.md
  • fastmcp.json
  • pyproject.toml


Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.



📜 Recent review details
⏰ Context from checks skipped due to timeout. (10)
  • GitHub Check: CodeQL
  • GitHub Check: Tests (py3.13)
  • GitHub Check: Tests (py3.10)
  • GitHub Check: Tests (py3.11)
  • GitHub Check: Build and package check
  • GitHub Check: Docker build
  • GitHub Check: Tests (py3.12)
  • GitHub Check: Lint and types
  • GitHub Check: OpenAPI drift
  • GitHub Check: Tool contract and env gating


🧰 Additional context used
📚 Code guidelines (1)
AGENTS.md — configured

📓 Path-based instructions (3)
Dependency floors.

⚙️ CodeRabbit configuration file

Files:

  • pyproject.toml
  • fastmcp.json

README is the user contract for env vars, tool lists, and install steps: flag text that contradicts the code in this PR (renamed or removed tools, env vars, defaults).

⚙️ CodeRabbit configuration file

Files:

  • README.md

Source excerpt: **Git Safety & Releases**: Never commit API secrets or tenant credentials.

📄 CodeRabbit inference engine (AGENTS.md)

Files:

  • pyproject.toml
  • README.md



🔇 Additional comments (3)
fastmcp.json (1)

9-10: LGTM!


README.md (1)

181-181: LGTM!


pyproject.toml (1)

24-25: 📐 Maintainability & Code Quality

The full PR diff includes uv.lock, and its locked versions and dependency metadata match the updated floors. The concern is refuted.





📝 Walkthrough
📝 Walkthrough

Walkthrough

The project raises its minimum mcp and FastMCP dependency versions. The README documents default stateful HTTP session expiration after 30 minutes of inactivity and the available timeout configuration options.

Changes

FastMCP requirements and session timeout documentation

Layer / File(s) Summary
Dependency requirements and session timeout documentation
fastmcp.json, pyproject.toml, README.md
The minimum mcp and FastMCP versions increase. The README states that default stateful HTTP sessions expire after 30 minutes of inactivity, causing the next request to return HTTP 404. It also documents FastMCP configuration options to change or disable expiration.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~5 minutes

Change: Other

Suggested labels: dependencies



Merge Risk: ⚪ Minimal · up to 237bf

The dependency and documentation changes are ready to merge after normal checks.

Pre-merge checks | Passed 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly and concisely identifies the main change: raising the minimum required versions of FastMCP to 4.1.0 and MCP to 2.3.0.

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@christianclaudio
christianclaudio merged commit 03480ed into main Oct 10, 2026
13 checks passed
@christianclaudio
christianclaudio deleted the cursor/fastmcp-4.1.0-floor branch October 10, 2026 13:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant