Repository navigation
fix(deps): update dependency fastmcp to v4 - #721
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Contributor
Author
|
renovate
Bot
force-pushed
the
renovate/fastmcp-4.x
branch
3 times, most recently
from
September 22, 2026 12:38
0bcd2ea to
817595c
Compare
renovate
Bot
force-pushed
the
renovate/fastmcp-4.x
branch
2 times, most recently
from
September 30, 2026 02:03
eb187a3 to
be1168b
Compare
renovate
Bot
force-pushed
the
renovate/fastmcp-4.x
branch
2 times, most recently
from
October 7, 2026 23:19
2edfa7f to
d3c789d
Compare
renovate
Bot
force-pushed
the
renovate/fastmcp-4.x
branch
from
October 9, 2026 19:25
d3c789d to
cbc20d2
Compare
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



This PR contains the following updates:
>=3.2.0,<4→>=3.2.0,<5Release Notes
PrefectHQ/fastmcp (fastmcp)
v4.0.10: : Inside JobCompare Source
Task-enabled tools now work behind search transforms and CodeMode: they're registered with the task backend even when hidden, and a tool, resource, or prompt that calls one through
ctx.fastmcp.call_tool()(including the searchcall_toolproxy and CodeMode'sexecute) now gets its result instead of an empty task receipt.What's Changed
Fixes 🐞
Docs 📚
Other Changes 🦾
New Contributors
Full Changelog: PrefectHQ/fastmcp@v4.0.9...v4.0.10
v4.0.9: : Cache and ReleaseCompare Source
ResourceTemplatenow keeps its compiled URI pattern for its own lifetime whilethe shared cache is bounded again, preventing dynamic proxies from growing
process memory without restoring the 4,096-template performance cliff.
What's Changed
Fixes 🐞
Other Changes 🦾
Full Changelog: PrefectHQ/fastmcp@v4.0.8...v4.0.9
v4.0.8: : Take ThreeCompare Source
Completion goes back to its 4.0.5 behavior. The visibility check added in 4.0.6 and reworked in 4.0.7 simulated list requests through middleware, and in 4.0.7 that could let a response cache serve hidden prompts to other clients. New tests pin both problems, and withholding suggestions for hidden references will return with a proper design. Resource template patterns are now cached without a size limit, so servers with thousands of templates read fast again, and OAuthProxy revokes the upstream refresh token instead of sending its own token upstream.
What's Changed
Security 🔒
Fixes 🐞
Docs 📚
New Contributors
Full Changelog: PrefectHQ/fastmcp@v4.0.7...v4.0.8
v4.0.7: : Double TakeCompare Source
Fixes two regressions from 4.0.6. The completion visibility check runs only the list-specific middleware hooks, so rate limits, logging, and metrics see a single request per completion again. Resource template patterns are cached, which makes template reads faster than in 4.0.5.
What's Changed
Fixes 🐞
Docs 📚
Full Changelog: PrefectHQ/fastmcp@v4.0.6...v4.0.7
v4.0.6: : Comma ChameleonCompare Source
Resource templates now match what clients actually send: literals raw or percent-encoded, and list query parameters exploded or comma-joined. A
Clientwhose exit is cancelled releases its session instead of leaking it, completion no longer answers for prompts and templates the caller can't see, and JSON schemas with float or oversized length limits load instead of failing. The auth fixes cache OIDC discovery and keep Google tokens out of request URLs.What's Changed
Enhancements ✨
Security 🔒
Fixes 🐞
get_schemaby @zzstoatzz in #4970Docs 📚
Dependencies 📦
Other Changes 🦾
New Contributors
Full Changelog: PrefectHQ/fastmcp@v4.0.5...v4.0.6
v4.0.5: : No Country for Loose IntsCompare Source
Tool parameters declared strict with
Field(strict=True),StrictInt, or a strict model config are honored again, on both direct calls and task submission. Since the SDK v2 migration the server's lax default overrode them and silently coerced values.What's Changed
Security 🔒
Fixes 🐞
Other Changes 🦾
Full Changelog: PrefectHQ/fastmcp@v4.0.4...v4.0.5
v4.0.4: : Here Be No DragonsCompare Source
OpenAPI request bodies get most of the attention in this patch: multipart string arrays are sent as repeated fields, whole-body arguments no longer clobber same-named HTTP parameters, dictionary bodies and raw content types survive intact, and JSON scalar bodies are encoded. On the auth side, OAuthProxy rejects ID-JAG tokens unless identity assertion is configured and refuses non-positive upstream token expiries. Clients now follow empty pagination cursors and servers reject malformed ones.
What's Changed
Enhancements ✨
Security 🔒
Fixes 🐞
Other Changes 🦾
New Contributors
Full Changelog: PrefectHQ/fastmcp@v4.0.3...v4.0.4
v4.0.3: : Once Is EnoughCompare Source
Multi-server clients with legacy-only backends now avoid unnecessary startup retries, and tools returning unconstrained sequences no longer send images twice. This patch also fixes task timing values rejected by strict clients and cleans up unfinished Monty callbacks when execution ends.
What's Changed
Enhancements ✨
Fixes 🐞
Docs 📚
New Contributors
Full Changelog: PrefectHQ/fastmcp@v4.0.2...v4.0.3
v4.0.2: : Root AccessCompare Source
ClientGroupis now importable from the package root,from fastmcp import ClientGroup, with the same lazy export and install hint asClient, so integrations no longer couple to FastMCP's internal module layout.What's Changed
Enhancements ✨
Fixes 🐞
Docs 📚
Other Changes 🦾
Full Changelog: PrefectHQ/fastmcp@v4.0.1...v4.0.2
v4.0.1: : Come Back Any TimeCompare Source
ClientGroupnow reference-counts its context the wayClientdoes, so entering a connected group from a nested block or a concurrent task reuses the existing connections instead of raising. Adapters written againstClient's reentrancy can hold aClientGroupthe same way.What's Changed
Fixes 🐞
Docs 📚
Other Changes 🦾
Full Changelog: PrefectHQ/fastmcp@v4.0.0...v4.0.1
v4.0.0: : Four RealCompare Source
FastMCP 4 is stable. Five betas, five weeks, 23 contributors, and more than 80 pull requests later — the new protocol engine held up under real gateways, agent frameworks, and production servers, and most FastMCP 3 applications upgrade without code changes.
This is the FastMCP release for the new MCP. On July 28, MCP released the
2026-07-28protocol revision and the rewritten Python SDK v2 shipped the same day. FastMCP 4 is built on both: modern requests are sessionless and self-contained, so any replica behind an ordinary load balancer can answer them, and one FastMCP 4 deployment negotiates the best protocol version per connection — new clients get the new protocol, old clients keep working, andClient(url)does the same negotiation from the other side.The new protocol's capabilities come through FastMCP's usual high-level surfaces:
@mcp.tool(task=True)) run outside the request path via theio.modelcontextprotocol/tasksextension, shipped in the optionalfastmcp-taskspackage on the same Docket engine as FastMCP 3.add_extension(): a negotiated capability, additive request methods, tool-call interception, and a lifespan. Tasks are built this way, outside core.Mcp-Method/Mcp-Namerouting headers so gateways can route without parsing JSON-RPC.The framework grew alongside the protocol: dependency injection can bind a dependency to arguments of the call it serves (
Depends(get_account, user_id=CallArgument("owner"))) while keeping it out of the tool schema, andClientGroupmanages one client per server with collision-checked namespacing — each member negotiating its own protocol version.The beta period motivated a bunch of correctness work. Most of it was auth: hardened OAuth consent flows, issuer validation, and JWT verification, plus proxies that strip cookies and connection-owned headers at trust boundaries. The rest was durability and compatibility — encrypted task snapshots, serialized event-store writes, response caching handling empty results, errors, and versioned components, and dozens of smaller fixes from CodeMode to Python 3.14 compat.
Breaking changes: server-initiated sampling and roots are removed (no live connection exists to call back into mid-request),
ctx.elicit()is old-protocol-only, FastMCP 3's deprecated APIs are gone, MCP model fields are snake_case (with a warning compatibility bridge for the old names), and background tasks moved tofastmcp-tasks. Passing a bare string likeClient("server.py")to run local code is deprecated in favor ofPath, for removal in FastMCP 5.The upgrade guide covers every change and includes a copyable prompt for auditing an application with a coding agent.
Happy (context) engineering!
What's Changed
New Features 🎉
Breaking Changes⚠️
Enhancements ✨
valid_scopesparameter to OIDC proxy valid scopes by @Educg550 in #4660Security 🔒
Fixes 🐞
Configuration
📅 Schedule: (in timezone Europe/Berlin)
* 0-5 * * *)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.