Repository navigation
chore(deps): require fastmcp 4.1.0 and mcp 2.3.0 - #39
Conversation
## Why Template v1.7.0 (#82) raised the FastMCP floor to 4.1.0 and mcp to 2.3.0. This copies both floors here so the product matches the template. Nothing in `src/` or `tests/` needed to change. ## Changes - `pyproject.toml` (core), `fastmcp.json`: `fastmcp>=4.0.11` becomes `>=4.1.0` and `mcp>=2.2.0` becomes `>=2.3.0`. - `uv.lock`: refreshed with `uv lock --upgrade-package fastmcp --upgrade-package mcp` only. No other package was upgraded. - `README.md`: the template's idle-session line, added as a bullet under "Known limits" in the Streamable HTTP section, because this README documents serving Streamable HTTP in the default stateful mode. No source or test changes. No version bump. ## Audit (src, tests, docs, README) - Tool Search ([#5467](PrefectHQ/fastmcp#5467)): `RegexSearchTransform()` is opt-in (`--enable-tool-search`, `src/snowflake_mcp/server.py:377`); the tests only list `search_tools`/`call_tool` and pass no pattern. A client sending a lookaround or backreference now gets an empty result instead of an error. The lookarounds and backreferences in `errors.py` belong to the redaction patterns. Python's `re` compiles them, not Tool Search, so they are unaffected. - Code Mode: No Code Mode in this repo; no `CodeMode(` or `max_duration_secs`. - HTTP idle expiry ([#5229](PrefectHQ/fastmcp#5229)): `session_idle_timeout` is not set anywhere, so stateful HTTP deployments now expire sessions after 30 idle minutes (HTTP 404, and the client starts a new session). The HTTP tests build stateless apps, and the `stateless_http=False` assertions only check the arguments passed to `run()`, so the tests are unaffected. The README line documents this. - No `x-mcp-header` annotations ([#3620](modelcontextprotocol/python-sdk#3620)), no `ctx.meta` / `ctx.params` reads ([#3628](modelcontextprotocol/python-sdk#3628)), no `MultiAuth`, no skills, and no OpenAPI `.`/`..` path parameters. ## FastMCP 4.1.0 ([release](https://github.com/PrefectHQ/fastmcp/releases/tag/v4.1.0)) and mcp 2.3.0 ([release](https://github.com/modelcontextprotocol/python-sdk/releases/tag/v2.3.0)) The items that apply here are the Tool Search engine change, the 30-minute idle expiry and the Monty 1.1 rename above. The other breaking items in 4.1.0 (MultiAuth client IDs, skill file paths, OpenAPI path parameters, Python 3.15) touch nothing used here. In mcp 2.3.0, `httpx2>=2.10.0` ([#3600](modelcontextprotocol/python-sdk#3600)) was already satisfied. [#3630](modelcontextprotocol/python-sdk#3630) (`Mcp-Param-*` lookup by name) and [#3635](modelcontextprotocol/python-sdk#3635) (OAuth login vs request timeouts, client side) need nothing here. ## Lock changes | Package | Before | After | |---|---|---| | fastmcp | 4.0.11 | 4.1.0 | | fastmcp-slim | 4.0.11 | 4.1.0 | | mcp | 2.2.0 | 2.3.0 | | mcp-types | 2.2.0 | 2.3.0 | | beartype | 0.22.9 | 0.22.9 (Python < 3.15) and 0.23.0 (Python >= 3.15) | **Why beartype is locked twice:** this is deliberate, not drift, and it matches template v1.7.0. `fastmcp-slim` 4.1.0 adds `beartype>=0.23.0rc2; python_version >= "3.15"` ([#5558](PrefectHQ/fastmcp#5558)), so uv forks the resolution at 3.15. Below 3.15, only `py-key-value-aio`'s `beartype>=0.20.0` applies, and uv keeps the 0.22.9 already locked because beartype wasn't upgraded. Python 3.10 to 3.13, the versions CI runs, still install 0.22.9. ## Tests No test changes. On Python 3.10, 3.11, 3.12 and 3.13, with `CI=true` and `--extra dev`, 667 passed, 1 deselected (the deselected one is the opt-in e2e test), at 100% coverage. The 3.12 run gave the same result with `SNOWFLAKE_MCP_AUTH_TOKEN` and `SNOWFLAKE_MCP_ALLOW_UNAUTHENTICATED_BIND` exported in the shell. ## Gates - `ruff check .` and `ruff format --check .`: clean - `mypy src/`: clean - `uv lock --check`: clean - `scripts/check_tool_contract.py`: passed - `scripts/check_snowflake_drift.py`: passed - `scripts/check_version.py` (on a fresh `uv build`): passed - `scripts/check_conformance.sh`: the baseline check passed (12 passed; all 20 failures are expected and in the baseline)
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info
📜 Recent review details
📝 Walkthrough
Merge Risk: ⚪ Minimal · up to This update raises the minimum FastMCP and mcp versions and documents the new 30-minute idle expiry for stateful HTTP sessions. No actionable merge-blocking risk was found. Pre-merge checks |
|
Why
Template v1.7.0 (#82) raised the FastMCP floor to 4.1.0 and mcp to 2.3.0. This copies both floors here so the product matches the template. Nothing in
src/ortests/needed to change.Changes
pyproject.toml(core),fastmcp.json:fastmcp>=4.0.11becomes>=4.1.0andmcp>=2.2.0becomes>=2.3.0.uv.lock: refreshed withuv lock --upgrade-package fastmcp --upgrade-package mcponly. No other package was upgraded.README.md: the template's idle-session line, added as a bullet under "Known limits" in the Streamable HTTP section, because this README documents serving Streamable HTTP in the default stateful mode.No source or test changes. No version bump.
Audit (src, tests, docs, README)
RegexSearchTransform()is opt-in (--enable-tool-search,src/snowflake_mcp/server.py:377); the tests only listsearch_tools/call_tooland pass no pattern. A client sending a lookaround or backreference now gets an empty result instead of an error. The lookarounds and backreferences inerrors.pybelong to the redaction patterns. Python'srecompiles them, not Tool Search, so they are unaffected.CodeMode(ormax_duration_secs.session_idle_timeoutis not set anywhere, so stateful HTTP deployments now expire sessions after 30 idle minutes (HTTP 404, and the client starts a new session). The HTTP tests build stateless apps, and thestateless_http=Falseassertions only check the arguments passed torun(), so the tests are unaffected. The README line documents this.x-mcp-headerannotations (#3620), noctx.meta/ctx.paramsreads (#3628), noMultiAuth, no skills, and no OpenAPI./..path parameters.FastMCP 4.1.0 (release) and mcp 2.3.0 (release)
The items that apply here are the Tool Search engine change, the 30-minute idle expiry and the Monty 1.1 rename above. The other breaking items in 4.1.0 (MultiAuth client IDs, skill file paths, OpenAPI path parameters, Python 3.15) touch nothing used here. In mcp 2.3.0,
httpx2>=2.10.0(#3600) was already satisfied. #3630 (Mcp-Param-*lookup by name) and #3635 (OAuth login vs request timeouts, client side) need nothing here.Lock changes
Why beartype is locked twice: this is deliberate, not drift, and it matches template v1.7.0.
fastmcp-slim4.1.0 addsbeartype>=0.23.0rc2; python_version >= "3.15"(#5558), so uv forks the resolution at 3.15. Below 3.15, onlypy-key-value-aio'sbeartype>=0.20.0applies, and uv keeps the 0.22.9 already locked because beartype wasn't upgraded. Python 3.10 to 3.13, the versions CI runs, still install 0.22.9.Tests
No test changes. On Python 3.10, 3.11, 3.12 and 3.13, with
CI=trueand--extra dev, 667 passed, 1 deselected (the deselected one is the opt-in e2e test), at 100% coverage. The 3.12 run gave the same result withSNOWFLAKE_MCP_AUTH_TOKENandSNOWFLAKE_MCP_ALLOW_UNAUTHENTICATED_BINDexported in the shell.Gates
ruff check .andruff format --check .: cleanmypy src/: cleanuv lock --check: cleanscripts/check_tool_contract.py: passedscripts/check_snowflake_drift.py: passedscripts/check_version.py(on a freshuv build): passedscripts/check_conformance.sh: the baseline check passed (12 passed; all 20 failures are expected and in the baseline)pyproject.tomlandfastmcp.json.FASTMCP_HTTP_SESSION_IDLE_TIMEOUT; no environment variable changes are shown.