Repository navigation
chore(deps): require fastmcp 4.1.0 and mcp 2.3.0 - #45
Conversation
## Why Template v1.7.0 (#82) raised the FastMCP floor to 4.1.0 and mcp to 2.3.0. This copies both floors here so the product matches the template. Nothing in `src/` or `tests/` needed to change. ## Changes - `pyproject.toml` (core and both `code-mode` / `dev` extras), `fastmcp.json`: `fastmcp>=4.0.11` becomes `>=4.1.0` and `mcp>=2.2.0` becomes `>=2.3.0`. - `uv.lock`: refreshed with `uv lock --upgrade-package fastmcp --upgrade-package mcp` only. No other package was upgraded. - `README.md`: the template's idle-session line, added as a bullet under the HTTP authentication list, because this README documents serving Streamable HTTP in the default stateful mode. No source or test changes. No version bump. ## Audit (src, tests, docs, README) - Tool Search ([#5467](PrefectHQ/fastmcp#5467)): Regex (default) or BM25 Tool Search is opt-in (`src/sigma_mcp/server.py:415`). Test patterns are plain words (`workbooks_`, `workbooks_list`) and `\b<name>\b` in `tests/test_client_surface.py:204`; the rust-regex engine supports `\b`, and that test passes on 4.1.0. The lookarounds and backreferences in `errors.py` belong to the redaction patterns. Python's `re` compiles them, not Tool Search, so they are unaffected. - Code Mode: `CodeMode()` is called with no arguments (`src/sigma_mcp/server.py`), and `max_duration_secs` appears nowhere, so the Monty 1.1 rename to `max_feed_duration_secs` (default 30.0) needs no change; Code Mode inherits the new default. - HTTP idle expiry ([#5229](PrefectHQ/fastmcp#5229)): `session_idle_timeout` is not set anywhere, so stateful HTTP deployments now expire sessions after 30 idle minutes (HTTP 404, and the client starts a new session). The HTTP tests build stateless apps, and the `stateless_http=False` assertions only check the arguments passed to `run()`, so the tests are unaffected. The README line documents this. - No `x-mcp-header` annotations ([#3620](modelcontextprotocol/python-sdk#3620)), no `ctx.meta` / `ctx.params` reads ([#3628](modelcontextprotocol/python-sdk#3628)), no `MultiAuth`, no skills, and no OpenAPI `.`/`..` path parameters. ## FastMCP 4.1.0 ([release](https://github.com/PrefectHQ/fastmcp/releases/tag/v4.1.0)) and mcp 2.3.0 ([release](https://github.com/modelcontextprotocol/python-sdk/releases/tag/v2.3.0)) The items that apply here are the Tool Search engine change, the 30-minute idle expiry and the Monty 1.1 rename above. The other breaking items in 4.1.0 (MultiAuth client IDs, skill file paths, OpenAPI path parameters, Python 3.15) touch nothing used here. In mcp 2.3.0, `httpx2>=2.10.0` ([#3600](modelcontextprotocol/python-sdk#3600)) was already satisfied. [#3630](modelcontextprotocol/python-sdk#3630) (`Mcp-Param-*` lookup by name) and [#3635](modelcontextprotocol/python-sdk#3635) (OAuth login vs request timeouts, client side) need nothing here. ## Lock changes | Package | Before | After | |---|---|---| | fastmcp | 4.0.11 | 4.1.0 | | fastmcp-slim | 4.0.11 | 4.1.0 | | mcp | 2.2.0 | 2.3.0 | | mcp-types | 2.2.0 | 2.3.0 | | pydantic-monty | 0.0.21 | 1.1.0 | | pydantic-monty-client | 0.0.21 | 1.1.0 | | pydantic-monty-runtime | 0.0.21 | 1.1.0 | | beartype | 0.22.9 | 0.22.9 (Python < 3.15) and 0.23.0 (Python >= 3.15) | **Why beartype is locked twice:** this is deliberate, not drift, and it matches template v1.7.0. `fastmcp-slim` 4.1.0 adds `beartype>=0.23.0rc2; python_version >= "3.15"` ([#5558](PrefectHQ/fastmcp#5558)), so uv forks the resolution at 3.15. Below 3.15, only `py-key-value-aio`'s `beartype>=0.20.0` applies, and uv keeps the 0.22.9 already locked because beartype wasn't upgraded. Python 3.10 to 3.13, the versions CI runs, still install 0.22.9. ## Tests No test changes. On Python 3.10, 3.11, 3.12 and 3.13, with `CI=true` and `--extra dev --extra code-mode`, 830 passed, 9 skipped, 1 deselected (the deselected one is the opt-in e2e test), at 100% coverage. The 3.12 run gave the same result with `SIGMA_MCP_AUTH_TOKEN` and `SIGMA_MCP_ALLOW_UNAUTHENTICATED_BIND` exported in the shell. ## Gates - `ruff check .` and `ruff format --check .`: clean - `mypy --strict src/`: clean - `uv lock --check`: clean - `scripts/check_tool_contract.py`: passed - `scripts/check_openapi_drift.py`: could not run; Sigma's OpenAPI hosts returned HTTP 400 for every spec URL, and `main` fails the same way, so this is upstream, not this change - `scripts/check_version.py` (on a fresh `uv build`): passed - `scripts/check_conformance.sh`: the baseline check passed (12 passed; all 20 failures are expected and in the baseline)
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info
📜 Recent review details
📝 Walkthrough
Merge Risk: ⚪ Minimal · up to The dependency and documentation changes are ready to merge after normal checks. Pre-merge checks |
|
Why
Template v1.7.0 (#82) raised the FastMCP floor to 4.1.0 and mcp to 2.3.0. This copies both floors here so the product matches the template. Nothing in
src/ortests/needed to change.Changes
pyproject.toml(core and bothcode-mode/devextras),fastmcp.json:fastmcp>=4.0.11becomes>=4.1.0andmcp>=2.2.0becomes>=2.3.0.uv.lock: refreshed withuv lock --upgrade-package fastmcp --upgrade-package mcponly. No other package was upgraded.README.md: the template's idle-session line, added as a bullet under the HTTP authentication list, because this README documents serving Streamable HTTP in the default stateful mode.No source or test changes. No version bump.
Audit (src, tests, docs, README)
src/sigma_mcp/server.py:415). Test patterns are plain words (workbooks_,workbooks_list) and\b<name>\bintests/test_client_surface.py:204; the rust-regex engine supports\b, and that test passes on 4.1.0. The lookarounds and backreferences inerrors.pybelong to the redaction patterns. Python'srecompiles them, not Tool Search, so they are unaffected.CodeMode()is called with no arguments (src/sigma_mcp/server.py), andmax_duration_secsappears nowhere, so the Monty 1.1 rename tomax_feed_duration_secs(default 30.0) needs no change; Code Mode inherits the new default.session_idle_timeoutis not set anywhere, so stateful HTTP deployments now expire sessions after 30 idle minutes (HTTP 404, and the client starts a new session). The HTTP tests build stateless apps, and thestateless_http=Falseassertions only check the arguments passed torun(), so the tests are unaffected. The README line documents this.x-mcp-headerannotations (#3620), noctx.meta/ctx.paramsreads (#3628), noMultiAuth, no skills, and no OpenAPI./..path parameters.FastMCP 4.1.0 (release) and mcp 2.3.0 (release)
The items that apply here are the Tool Search engine change, the 30-minute idle expiry and the Monty 1.1 rename above. The other breaking items in 4.1.0 (MultiAuth client IDs, skill file paths, OpenAPI path parameters, Python 3.15) touch nothing used here. In mcp 2.3.0,
httpx2>=2.10.0(#3600) was already satisfied. #3630 (Mcp-Param-*lookup by name) and #3635 (OAuth login vs request timeouts, client side) need nothing here.Lock changes
Why beartype is locked twice: this is deliberate, not drift, and it matches template v1.7.0.
fastmcp-slim4.1.0 addsbeartype>=0.23.0rc2; python_version >= "3.15"(#5558), so uv forks the resolution at 3.15. Below 3.15, onlypy-key-value-aio'sbeartype>=0.20.0applies, and uv keeps the 0.22.9 already locked because beartype wasn't upgraded. Python 3.10 to 3.13, the versions CI runs, still install 0.22.9.Tests
No test changes. On Python 3.10, 3.11, 3.12 and 3.13, with
CI=trueand--extra dev --extra code-mode, 830 passed, 9 skipped, 1 deselected (the deselected one is the opt-in e2e test), at 100% coverage. The 3.12 run gave the same result withSIGMA_MCP_AUTH_TOKENandSIGMA_MCP_ALLOW_UNAUTHENTICATED_BINDexported in the shell.Gates
ruff check .andruff format --check .: cleanmypy --strict src/: cleanuv lock --check: cleanscripts/check_tool_contract.py: passedscripts/check_openapi_drift.py: the local HTTP 400 came from the review machine's network (DNS), not Sigma's servers.curlgets 200 from the spec URLs, and CI's drift job is green on this PR and onmain.scripts/check_version.py(on a freshuv build): passedscripts/check_conformance.sh: the baseline check passed (12 passed; all 20 failures are expected and in the baseline)fastmcpversion to 4.1.0 andmcpversion to 2.3.0 in project and FastMCP configuration; refresheduv.lock.Tool surface: none
Config: none