Skip to content

chore(deps): Bump the dependencies group across 1 directory with 2 updates - #110

Merged
GoodbyePlanet merged 1 commit into
mainfrom
dependabot/uv/dependencies-39da4f9091
Sep 6, 2026
Merged

GoodbyePlanet merged 1 commit into
mainfrom
dependabot/uv/dependencies-39da4f9091

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the dependencies group with 2 updates in the / directory: mcp and tree-sitter-language-pack.

Updates mcp from 2.0.0 to 2.1.1

Release notes

Sourced from mcp's releases.

v2.1.1

What's Changed

Full Changelog: modelcontextprotocol/python-sdk@v2.1.0...v2.1.1

v2.1.0

Highlights

  • Client accepts StdioServerParameters directly: Client(StdioServerParameters(command="uv", args=["run", "server.py"])) (#3321).
  • Prompt messages accept Image and Audio, prompt functions may return bare content blocks, and Message / UserMessage / AssistantMessage are exported from mcp.server.mcpserver (#3320).
  • The 4 MiB request body limit now also covers the SSE transport and the OAuth endpoints; SseServerTransport and MCPServer.sse_app() take max_request_body_size, and the SSE message endpoint answers 405 to non-POST requests (#3336).

Behaviour changes to be aware of

  • Handler exceptions (#3314): an unexpected exception from a tool, resource or prompt handler is logged once at ERROR with its traceback, and the client now sees only Error executing tool <name> (or the resource/prompt equivalent) rather than the exception text. Raise ToolError / ResourceError when the message is meant for the model; those still reach the client and are logged at INFO without a traceback.
  • Content-block return annotations (#3320): a tool annotated to return TextContent, EmbeddedResource, Image, Audio, or lists/unions of them no longer advertises outputSchema or returns structuredContent; its content is unchanged. Pass structured_output=True to keep the previous shape.

Fixes

  • TypedDict tool results: NotRequired keys are omitted instead of serialized as null, and registration no longer fails on Python 3.10 (#3224, #3227); recursive return types get an object-rooted outputSchema that pre-2026 clients accept (#3337).
  • 2026-07-28 over HTTP: a POSTed notification such as notifications/cancelled is acknowledged with 202 instead of rejected with 400 (#3324).
  • Pre-2026 sessions ignore cache-hint fields from later revisions instead of failing list_tools() (#3223), and accept boolean sub-schemas in tool schema properties (#3353).
  • mcp install reads and preserves a Claude Desktop config containing non-ASCII text on any Windows code page (#3296).

What's Changed

... (truncated)

Commits
  • 0921d94 Point imports of mcp.server.fastmcp at the migration guide (#3388)
  • 4d6f87e Build releases with the pinned hatchling and a publish action that accepts Me...
  • c5d7d0b docs: refresh translations for recent English changes (#3379)
  • d8b6383 Give recursive tool return types an object-rooted output schema (#3376)
  • 56af447 Log MCPServer handler exceptions by kind and keep crash details off the wire ...
  • f1c40b0 Accept boolean sub-schemas in 2025-11-25 tool schema properties (#3354)
  • 57394b0 Apply the request body limit to the SSE and OAuth endpoints (#3336)
  • 0cee624 Hand TypedDict tool results to pydantic natively (#3331)
  • 0d92192 Shorten stdio test comments (#3329)
  • b2025ab Acknowledge notification POSTs with 202 on the 2026-07-28 HTTP entry (#3326)
  • Additional commits viewable in compare view

Updates tree-sitter-language-pack from 1.14.3 to 1.15.8

Changelog

Sourced from tree-sitter-language-pack's changelog.

[1.15.8] - 2026-08-23

Fixed

  • The plain-Java artifact reaches Maven Central again. It was the only registry still stuck at 1.14.3: every 1.15.x publish skipped Publish Maven package, because the E2E gate — Java it sits behind failed first on 8 assertions of the shape expected: <null> but was: <[]>.

    The cause was a disagreement inside each generated Java record. A component backed by a Rust Vec carrying #[serde(default, skip_serializing_if = "Vec::is_empty")] was emitted as @Nullable, and the canonical constructor stored whatever it was handed — null included — while the Jackson builder defaulted the same component to List.of(). A record built through the builder, or round-tripped through JSON, therefore never compared equal to the same record built through the constructor. Regenerating against alef 0.67.2 drops @Nullable on those components and adds a compact constructor normalizing null to an empty collection, so both construction paths agree. Affected records: DataNode, DocstringInfo, ImportInfo, ProcessResult, StructureItem.

  • The hand-written Java unit tests asserted the old, wrong contract. They required such a component to arrive as null; the Rust fields behind them are plain Vec, never Option<Vec>, so empty is the truthful representation. They now assert assertEquals(List.of(), ...), which fails on null as well as on a non-empty list — the assertions were tightened, not relaxed to accept either shape. mvn test in packages/java reports 150 tests, 0 failures, 0 errors.

Added

  • Prerelease mode for the registry-mode test apps. task test-apps:prerelease:run (and :verify, :status, :clean) stages a throwaway copy of each test_apps/ app under .prerelease/ and redirects its dependency resolution at the in-repo package source, so the suite is runnable between a version bump and the publish — the window in which the pinned version exists on no registry and alef test-apps run cannot resolve anything. Covers rust, go, python, ruby, dart, elixir and swift; status names the remaining targets and why each needs a built artifact rather than a source path.

  • scripts/check_test_app_pins.py — a gate that fails when a test app is pinned to a release other than the one being built. It re-derives all 18 pins across every test_apps/ app plus the alef.toml registry pins from Cargo.toml, deliberately independent of alef, so a change in what alef sync-versions is willing to write surfaces as a failure instead of as silent drift. A pattern that matches nothing is an error, not a pass — that was the Dart failure mode. --fix repins everything; --release X checks against the version being published and also catches a Cargo.toml that disagrees with the tag.

    Wired in three places: task version:sync repins after alef sync-versions, the Check version sync CI step gates every push, and the publish workflow's validate-versions job gates the release itself against the tag. Also exposed as task test-apps:check-pins / :fix-pins.

  • scripts/sync_zig_zon_hashes.py — regenerates and verifies the test_apps/zig/build.zig.zon package hashes from the tarballs their URLs name. A Zig package hash is a content digest, so it cannot be derived from a version string the way every other test-app pin can; the only

... (truncated)

Commits
  • 86fa5a8 chore(swift): update Package.swift with checksum for v1.15.8
  • 7f3d1e6 docs(changelog): roll [Unreleased] into 1.15.8
  • d9d1647 chore(release): bump version to 1.15.8
  • 0f55a1e fix(java): assert the non-null empty-collection contract
  • e85d7ee chore: regenerate bindings with alef 0.67.2
  • eededd2 chore(deps): repin alef to 0.67.2
  • 4da61e7 feat(ci): refresh zig test-app package hashes after publish
  • 4d0b2b3 chore(deps): refresh Cargo.lock to latest compatible versions
  • 19508d1 fix(ci): trigger CI Zig on the files its hash check reads
  • 308fcb1 fix(test-apps): regenerate zig package hashes stale since 1.14.3
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…dates

Bumps the dependencies group with 2 updates in the / directory: [mcp](https://github.com/modelcontextprotocol/python-sdk) and [tree-sitter-language-pack](https://github.com/xberg-io/tree-sitter-language-pack).


Updates `mcp` from 2.0.0 to 2.1.1
- [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md)
- [Commits](modelcontextprotocol/python-sdk@v2.0.0...v2.1.1)

Updates `tree-sitter-language-pack` from 1.14.3 to 1.15.8
- [Changelog](https://github.com/xberg-io/tree-sitter-language-pack/blob/main/CHANGELOG.md)
- [Commits](xberg-io/tree-sitter-language-pack@v1.14.3...v1.15.8)

---
updated-dependencies:
- dependency-name: mcp
  dependency-version: 2.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: tree-sitter-language-pack
  dependency-version: 1.15.8
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 3, 2026
@GoodbyePlanet

Copy link
Copy Markdown
Owner

Verification: ✅ valid, safe to merge

Checked out and tested locally on macOS / Python 3.12.12.

Scope of the bump

  • mcp 2.0.0 → 2.1.1 (+ mcp-types) — uv.lock only, since pyproject.toml declares mcp>=2.0.0 with no upper bound
  • tree-sitter-language-pack 1.14.3 → 1.15.8 — needed the pyproject.toml ceiling widened <1.15.0 → <1.16.0, which is the single visible manifest line

Results

Check Result
uv run pytest 330 passed
uvx ruff format --check . 135 files already formatted
uvx ruff check . All checks passed
uv sync --frozen --all-groups lock consistent with pyproject
stdio transport, live Qdrant boots, 10 tools / 2 prompts, tool calls OK
streamable-http transport list_tools, call_tool, get_prompt all OK
POST /reindex valid NDJSON stream, HTTP 200
Dart + R parse on 1.15.8 correct symbols

The two breaking MCP 2.1.0 behaviours don't affect us

The 2.1.0 release notes flag two behaviour changes. Both were checked against actual usage:

  1. Handler exceptions no longer reach the client (only Error executing tool <name>). Not applicable — the tools don't raise for control flow. Both error paths (server/tools/search.py:235, server/tools/stats.py:42) catch and return the message as a string, so it still reaches the model.
  2. Content-block return annotations drop outputSchema/structuredContent. Not applicable — all 10 tools are annotated -> str, not TextContent/Image/etc. Confirmed all 10 still advertise an outputSchema.

Grammar pack blast radius is small

Only server/parser/dart.py and server/parser/r.py pull from tree-sitter-language-pack; every other language uses a dedicated tree-sitter-* package. Both parse their fixtures correctly on 1.15.8 (user_widget.dart → 11 symbols, utils.R → 4), and all 24 parser snapshot suites pass.

End-to-end against live Qdrant

Ran a real qdrant/qdrant:latest (v1.19.1) and booted the server through its full lifespan on both transports — collections and payload indexes created, client handshake fine, index_stats / list_indexed_services returning correct output, zero ERROR/Traceback lines in the server log.

Not covered: no real reindex of a service was triggered (that hits the GitHub API and paid embedding calls), so this doesn't exercise the ingest → embed → upsert path against real data.

Unrelated follow-up (pre-existing, not this PR)

pyproject.toml:7 has mcp>=2.0.0 with no upper bound, so mcp upgrades land as lock-only changes with no signal in the manifest — and a future 3.0 with genuinely breaking changes would arrive the same silent way. Adding mcp>=2.0.0,<3.0.0 would make these visible, the way the tree-sitter constraint already is. Worth a separate PR.

🤖 Generated with Claude Code

@GoodbyePlanet
GoodbyePlanet merged commit 0f9af33 into main Sep 6, 2026
2 checks passed
@GoodbyePlanet
GoodbyePlanet deleted the dependabot/uv/dependencies-39da4f9091 branch September 6, 2026 10:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant