Skip to content

chore(deps): require fastmcp 4.1.0 and mcp 2.3.0 - #39

Merged
christianclaudio merged 1 commit into
mainfrom
cursor/fastmcp-4.1.0-floor
Oct 10, 2026
Merged

christianclaudio merged 1 commit into
mainfrom
cursor/fastmcp-4.1.0-floor

Conversation

@christianclaudio

@christianclaudio christianclaudio commented Oct 10, 2026 •

Copy link
Copy Markdown
Owner

Why

Template v1.7.0 (#82) raised the FastMCP floor to 4.1.0 and mcp to 2.3.0. This copies both floors here so the product matches the template. Nothing in src/ or tests/ needed to change.

Changes

  • pyproject.toml (core), fastmcp.json: fastmcp>=4.0.11 becomes >=4.1.0 and mcp>=2.2.0 becomes >=2.3.0.
  • uv.lock: refreshed with uv lock --upgrade-package fastmcp --upgrade-package mcp only. No other package was upgraded.
  • README.md: the template's idle-session line, added as a bullet under "Known limits" in the Streamable HTTP section, because this README documents serving Streamable HTTP in the default stateful mode.

No source or test changes. No version bump.

Audit (src, tests, docs, README)

  • Tool Search (#5467): RegexSearchTransform() is opt-in (--enable-tool-search, src/snowflake_mcp/server.py:377); the tests only list search_tools/call_tool and pass no pattern. A client sending a lookaround or backreference now gets an empty result instead of an error. The lookarounds and backreferences in errors.py belong to the redaction patterns. Python's re compiles them, not Tool Search, so they are unaffected.
  • Code Mode: No Code Mode in this repo; no CodeMode( or max_duration_secs.
  • HTTP idle expiry (#5229): session_idle_timeout is not set anywhere, so stateful HTTP deployments now expire sessions after 30 idle minutes (HTTP 404, and the client starts a new session). The HTTP tests build stateless apps, and the stateless_http=False assertions only check the arguments passed to run(), so the tests are unaffected. The README line documents this.
  • No x-mcp-header annotations (#3620), no ctx.meta / ctx.params reads (#3628), no MultiAuth, no skills, and no OpenAPI ./.. path parameters.

FastMCP 4.1.0 (release) and mcp 2.3.0 (release)

The items that apply here are the Tool Search engine change, the 30-minute idle expiry and the Monty 1.1 rename above. The other breaking items in 4.1.0 (MultiAuth client IDs, skill file paths, OpenAPI path parameters, Python 3.15) touch nothing used here. In mcp 2.3.0, httpx2>=2.10.0 (#3600) was already satisfied. #3630 (Mcp-Param-* lookup by name) and #3635 (OAuth login vs request timeouts, client side) need nothing here.

Lock changes

Package Before After
fastmcp 4.0.11 4.1.0
fastmcp-slim 4.0.11 4.1.0
mcp 2.2.0 2.3.0
mcp-types 2.2.0 2.3.0
beartype 0.22.9 0.22.9 (Python < 3.15) and 0.23.0 (Python >= 3.15)

Why beartype is locked twice: this is deliberate, not drift, and it matches template v1.7.0. fastmcp-slim 4.1.0 adds beartype>=0.23.0rc2; python_version >= "3.15" (#5558), so uv forks the resolution at 3.15. Below 3.15, only py-key-value-aio's beartype>=0.20.0 applies, and uv keeps the 0.22.9 already locked because beartype wasn't upgraded. Python 3.10 to 3.13, the versions CI runs, still install 0.22.9.

Tests

No test changes. On Python 3.10, 3.11, 3.12 and 3.13, with CI=true and --extra dev, 667 passed, 1 deselected (the deselected one is the opt-in e2e test), at 100% coverage. The 3.12 run gave the same result with SNOWFLAKE_MCP_AUTH_TOKEN and SNOWFLAKE_MCP_ALLOW_UNAUTHENTICATED_BIND exported in the shell.

Gates

  • ruff check . and ruff format --check .: clean
  • mypy src/: clean
  • uv lock --check: clean
  • scripts/check_tool_contract.py: passed
  • scripts/check_snowflake_drift.py: passed
  • scripts/check_version.py (on a fresh uv build): passed
  • scripts/check_conformance.sh: the baseline check passed (12 passed; all 20 failures are expected and in the baseline)
  • Raised the minimum FastMCP and MCP versions to 4.1.0 and 2.3.0 in pyproject.toml and fastmcp.json.
  • Updated the README to document default Streamable HTTP session expiry after 30 minutes of inactivity and how to configure or disable the timeout.
  • Tool surface: none.
  • Config: documents FASTMCP_HTTP_SESSION_IDLE_TIMEOUT; no environment variable changes are shown.

## Why

Template v1.7.0 (#82) raised the FastMCP floor to 4.1.0 and mcp to 2.3.0. This copies both floors here so the product matches the template. Nothing in `src/` or `tests/` needed to change.

## Changes

- `pyproject.toml` (core), `fastmcp.json`: `fastmcp>=4.0.11` becomes `>=4.1.0` and `mcp>=2.2.0` becomes `>=2.3.0`.
- `uv.lock`: refreshed with `uv lock --upgrade-package fastmcp --upgrade-package mcp` only. No other package was upgraded.
- `README.md`: the template's idle-session line, added as a bullet under "Known limits" in the Streamable HTTP section, because this README documents serving Streamable HTTP in the default stateful mode.

No source or test changes. No version bump.

## Audit (src, tests, docs, README)

- Tool Search ([#5467](PrefectHQ/fastmcp#5467)): `RegexSearchTransform()` is opt-in (`--enable-tool-search`, `src/snowflake_mcp/server.py:377`); the tests only list `search_tools`/`call_tool` and pass no pattern. A client sending a lookaround or backreference now gets an empty result instead of an error. The lookarounds and backreferences in `errors.py` belong to the redaction patterns. Python's `re` compiles them, not Tool Search, so they are unaffected.
- Code Mode: No Code Mode in this repo; no `CodeMode(` or `max_duration_secs`.
- HTTP idle expiry ([#5229](PrefectHQ/fastmcp#5229)): `session_idle_timeout` is not set anywhere, so stateful HTTP deployments now expire sessions after 30 idle minutes (HTTP 404, and the client starts a new session). The HTTP tests build stateless apps, and the `stateless_http=False` assertions only check the arguments passed to `run()`, so the tests are unaffected. The README line documents this.
- No `x-mcp-header` annotations ([#3620](modelcontextprotocol/python-sdk#3620)), no `ctx.meta` / `ctx.params` reads ([#3628](modelcontextprotocol/python-sdk#3628)), no `MultiAuth`, no skills, and no OpenAPI `.`/`..` path parameters.

## FastMCP 4.1.0 ([release](https://github.com/PrefectHQ/fastmcp/releases/tag/v4.1.0)) and mcp 2.3.0 ([release](https://github.com/modelcontextprotocol/python-sdk/releases/tag/v2.3.0))

The items that apply here are the Tool Search engine change, the 30-minute idle expiry and the Monty 1.1 rename above. The other breaking items in 4.1.0 (MultiAuth client IDs, skill file paths, OpenAPI path parameters, Python 3.15) touch nothing used here. In mcp 2.3.0, `httpx2>=2.10.0` ([#3600](modelcontextprotocol/python-sdk#3600)) was already satisfied. [#3630](modelcontextprotocol/python-sdk#3630) (`Mcp-Param-*` lookup by name) and [#3635](modelcontextprotocol/python-sdk#3635) (OAuth login vs request timeouts, client side) need nothing here.

## Lock changes

| Package | Before | After |
|---|---|---|
| fastmcp | 4.0.11 | 4.1.0 |
| fastmcp-slim | 4.0.11 | 4.1.0 |
| mcp | 2.2.0 | 2.3.0 |
| mcp-types | 2.2.0 | 2.3.0 |
| beartype | 0.22.9 | 0.22.9 (Python < 3.15) and 0.23.0 (Python >= 3.15) |

**Why beartype is locked twice:** this is deliberate, not drift, and it matches template v1.7.0. `fastmcp-slim` 4.1.0 adds `beartype>=0.23.0rc2; python_version >= "3.15"` ([#5558](PrefectHQ/fastmcp#5558)), so uv forks the resolution at 3.15. Below 3.15, only `py-key-value-aio`'s `beartype>=0.20.0` applies, and uv keeps the 0.22.9 already locked because beartype wasn't upgraded. Python 3.10 to 3.13, the versions CI runs, still install 0.22.9.

## Tests

No test changes. On Python 3.10, 3.11, 3.12 and 3.13, with `CI=true` and `--extra dev`, 667 passed, 1 deselected (the deselected one is the opt-in e2e test), at 100% coverage. The 3.12 run gave the same result with `SNOWFLAKE_MCP_AUTH_TOKEN` and `SNOWFLAKE_MCP_ALLOW_UNAUTHENTICATED_BIND` exported in the shell.

## Gates

- `ruff check .` and `ruff format --check .`: clean
- `mypy src/`: clean
- `uv lock --check`: clean
- `scripts/check_tool_contract.py`: passed
- `scripts/check_snowflake_drift.py`: passed
- `scripts/check_version.py` (on a fresh `uv build`): passed
- `scripts/check_conformance.sh`: the baseline check passed (12 passed; all 20 failures are expected and in the baseline)
@coderabbitai

coderabbitai Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: QUIET
  • Plan: Advanced
  • Run ID: 6d5dd7c4-3027-45ec-9b49-56482c4989e1

📥 Commits

Reviewing files that changed from the base of the PR and between d4d5b17 and 2d5e89a.


⛔ Files ignored due to path filters (1)
  • uv.lock is excluded by !**/*.lock

📒 Files selected for processing (3)
  • README.md
  • fastmcp.json
  • pyproject.toml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📜 Recent review details
⏰ Context from checks skipped due to timeout. (8)
  • GitHub Check: Tests (py3.10)
  • GitHub Check: Build & Package Validation
  • GitHub Check: Tests (py3.13)
  • GitHub Check: Tool Contract Verification (140 Tools)
  • GitHub Check: Tests (py3.12)
  • GitHub Check: Protocol Conformance (MCP Spec 2026-07-28)
  • GitHub Check: Tests (py3.11)
  • GitHub Check: Lint and Type Check

🧰 Additional context used
📚 Code guidelines (1)
AGENTS.md — configured

📓 Path-based instructions (3)
Dependency floors.

⚙️ CodeRabbit configuration file

Files:

  • pyproject.toml
  • fastmcp.json

README is the user contract for env vars, tool lists, and install steps: flag text that contradicts the code in this PR (renamed or removed tools, env vars, defaults).

⚙️ CodeRabbit configuration file

Files:

  • README.md

Source excerpt: **Changesets & Releases**: Open a pull request.

📄 CodeRabbit inference engine (AGENTS.md)

Files:

  • pyproject.toml
  • README.md

🔇 Additional comments (3)
fastmcp.json (1)

9-10: LGTM!


pyproject.toml (1)

41-42: LGTM!


README.md (1)

314-314: LGTM!



📝 Walkthrough

Walkthrough

The README documents the default stateful HTTP session idle timeout and its configuration. Project metadata raises the minimum versions of mcp and fastmcp.

Changes

HTTP Session Documentation

Layer / File(s) Summary
Document HTTP session timeout
README.md
The README describes the 30-minute idle timeout, the resulting HTTP 404, and configuration through http_app() or an environment variable. Setting the timeout to none disables expiration.

Dependency Minimums

Layer / File(s) Summary
Raise dependency minimums
fastmcp.json, pyproject.toml
Both files raise the minimum mcp version to 2.3.0 and the minimum fastmcp version to 4.1.0.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Other

Suggested labels: dependencies


Merge Risk: ⚪ Minimal · up to 2d5e8

This update raises the minimum FastMCP and mcp versions and documents the new 30-minute idle expiry for stateful HTTP sessions. No actionable merge-blocking risk was found.

Pre-merge checks | Passed 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly and concisely describes the main change: raising the required FastMCP and MCP dependency versions.
Docstring Coverage Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@christianclaudio
christianclaudio merged commit f8dbcb8 into main Oct 10, 2026
10 checks passed
@christianclaudio
christianclaudio deleted the cursor/fastmcp-4.1.0-floor branch October 10, 2026 13:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant