Skip to content

deps: bump the dependencies group with 2 updates - #137

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/dependencies-ff9b6d759c
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/dependencies-ff9b6d759c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the dependencies group with 2 updates: mcp and tree-sitter-language-pack.

Updates mcp from 2.1.1 to 2.2.0

Release notes

Sourced from mcp's releases.

v2.2.0

pip install -U mcp. Docs: https://py.sdk.modelcontextprotocol.io/

A few defaults changed in this release. If you run a server or client on 2.x, skim these first:

Behaviour changes

HTTP client redirects are only followed within the endpoint's origin (#3397)

  • Client("https://..."), streamable_http_client and sse_client follow a redirect only if it stays on the same scheme, host and port (or upgrades http to https on the same host).
  • A redirect anywhere else is not followed: the call fails with MCPError and the session stays usable (an SSE connect fails with httpx2.HTTPStatusError). If that other URL is the server you meant, use it as the endpoint URL.
  • The follow_redirects setting on an httpx2.AsyncClient you pass in is no longer used for MCP requests, so you don't need it for the trailing-slash redirect any more.
  • The OAuth providers apply the same rule to their own requests.

Idle Streamable HTTP sessions now expire (legacy <=2025-11-25 spec( (#3395)

  • A stateful session with nothing in flight for 30 minutes is closed. The client's next request gets a 404 and it has to initialize again.
  • Clients that keep the GET stream open (the SDK's Client does) are not affected. Neither are stateless servers or 2026-07-28 connections.
  • A server also holds at most 10 000 sessions at once; beyond that, new sessions get a 503.
  • To turn either off: mcp.run(transport="streamable-http", session_idle_timeout=None, max_sessions=None) (also on streamable_http_app() and run_streamable_http_async()).

The OAuth client checks the authorization server's issuer on the legacy path too (#3398)

  • For servers without protected resource metadata, authorization server metadata whose issuer isn't the server's own origin is now rejected with OAuthFlowError: Authorization server metadata issuer mismatch. The protected-resource-metadata path has done this since 2.0.
  • A 403 that isn't an insufficient_scope challenge is returned to the caller instead of retried.
  • If protected resource metadata can't be fetched because of a 5xx/429, the flow now stops instead of falling back to the legacy endpoints.

Two new MCPDeprecationWarnings (#3435, #3447)

  • ClientCredentialsOAuthProvider / PrivateKeyJWTOAuthProvider without issuer=. Pass your authorization server's issuer URL; 3.0 will require it.
  • AuthSettings with resource_server_url set but validate_token_resource unset. Set it to True or False; 3.0 defaults it to True.
  • Both keep working as before in 2.x; this mostly matters if your tests turn warnings into errors.

New

  • AuthSettings.validate_token_resource: only accept tokens your TokenVerifier reports as issued for this server (#3447).
  • issuer= on ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider (#3398).
  • session_idle_timeout= and max_sessions= on the Streamable HTTP server entry points (#3395).

Fixes

  • A client DELETE frees its session immediately, and a refused opening request no longer leaves a session behind (#2455, #3228, #3300).
  • $refs in a tool's outputSchema resolve within that schema only; an unresolvable one surfaces as RuntimeError: Invalid schema for tool ... (#3394).

Known gaps

The tasks extension (SEP-2663), DPoP (SEP-1932) and the jwt-bearer grant are not implemented yet; https://github.com/modelcontextprotocol/python-sdk/blob/main/ROADMAP.md tracks them.

What's Changed

... (truncated)

Commits
  • 9972c21 Replace RootModel wrappers with type aliases and TypeAdapter validation (#3470)
  • fd66270 docs: refresh translations, and translate pages in parallel (#3458)
  • 08a3bc8 docs: ask for AI disclosure on comments too (#3459)
  • 7bb486a docs: stop presenting the in-memory client as the way to connect (#3443)
  • 0c91368 Add AuthSettings.validate_token_resource to check a bearer token's resource (...
  • 9771e6b Keep following a relative redirect when the endpoint URL carries userinfo (#3...
  • a925e55 Bump the locked versions of eight dev and test dependencies (#3449)
  • e8b9486 Bump pymdown-extensions from 11.0 to 11.0.1 (#3285)
  • c6762e8 Follow redirects only within the MCP endpoint's origin (#3397)
  • 5fd3abc Skip automatic docs previews for fork PRs and drop the setup-uv retry steps (...
  • Additional commits viewable in compare view

Updates tree-sitter-language-pack from 1.16.2 to 1.19.1

Release notes

Sourced from tree-sitter-language-pack's releases.

Release v1.19.1

What's Changed

Full Changelog: xberg-io/tree-sitter-language-pack@v1.16.0...v1.19.1

Release v1.19.0

Changed

  • Upgraded the tree-sitter runtime to 0.27, moving tree-sitter-language to 0.1.8 in the same step. The two pins are not independent: 0.27 requires tree-sitter-language ^0.1.8, and 0.1.8 relocates the 0.26 WASM shims under wasm/unsupported/ so they no longer compile against the older runtime. The grammar ABI is unchanged -- both 0.26 and 0.27 are TREE_SITTER_LANGUAGE_VERSION 15 with a minimum compatible version of 13 -- so every bundled grammar loads exactly as before and no regeneration is implied.
  • Consumers that also depend on tree-sitter directly must move to 0.27 in the same step. The tree-sitter crate declares links = "tree-sitter", and Cargo permits only one package per links value in a dependency graph, so pairing this release with a 0.26 pin fails to resolve rather than failing to compile. Nothing this crate exports changed: the requirement is a dependency floor, not a break in its own API.
  • Grammar scanners now compile with NDEBUG on wasm32. 0.27's WASM libc is a documented subset that excludes assert, so a scanner keeping its assertions emitted an unresolved __assert_fail. That became an env module import rather than a link error, and the package then failed to load at runtime with Cannot find module 'env'. Native builds keep their assertions.
  • Dropped this crate's own WASM libc shims (memchr, strcmp, iswalnum and friends) now that 0.27 defines them. Keeping both made the two definitions collide at link time, which broke the WASM package under the split-codegen-unit settings the release build uses.
  • Replaced the 0.26 WASM integration, which used a separate non-thread-safe allocator and an incomplete libc. 0.27 supplies its own WASM libc and forwards C allocation to the Rust application's global allocator.

Fixed

  • Swift binaries again link a single tree-sitter C runtime. SwiftPM builds tree-sitter 0.25.10 for SwiftTreeSitter as loose object files, while this package's Rust staticlib carries the 0.27 runtime in one archive member. Archive members load only to resolve an undefined symbol, and 0.27's new ts_language_is_parseable was the first symbol SwiftPM's copy could not supply -- pulling the member in and colliding on 253 other runtime symbols at link time. The C bridge now provides a weak definition, so the member stays unreferenced and yields to any future SwiftPM runtime that exports the symbol itself (#189).
  • wasm32 builds now find their headers under either wasi-sysroot include layout. wasi-libc renamed include/wasm32-wasi to include/wasm32-wasip1, and probing only the former meant a sysroot that existed but used the newer name contributed no include flag at all, failing every grammar with 'stdlib.h' file not found. Toolchains whose clang supplies its own sysroot were unaffected, which is why this surfaced only in local builds.
  • Node::child_count now returns tree-sitter's u32 widened to the usize this crate has always

... (truncated)

Changelog

Sourced from tree-sitter-language-pack's changelog.

[1.19.1] - 2026-09-13

Changed

  • Alef stays pinned at 0.85.15. 0.86.1 rewrites the Swift binding to real value types -- DataNode, ProcessResult and StructureItem become Codable structs with typed properties instead of typealiases to opaque Rust handles -- but does not update the Swift e2e suite it generates alongside them, which still calls result.language() and result.structure() on what are now properties. The two halves of its own output do not compile together, and e2e/ is generated with a CI freshness gate, so the mismatch cannot be patched downstream. Reported upstream; the upgrade lands once the e2e emitter follows the binding emitter.
  • Removed the eight superseded release/swift/<version> branches. publish.yaml moves the release tag onto the same checksummed commit it pushes the branch to, so each branch named a commit already reachable through v<version>; a consumer pinned to one can switch to exact: "<version>" with no other change. release/swift/1.19.0 is retained.

Fixed

  • Patched an indent-stack underflow in the vendored agda external scanner. VEC_POP is a bare len-- and VEC_BACK reads data[len - 1], so the dedent loop could drain the stack, wrap len to UINT32_MAX and dereference the buffer plus 16 GiB. 1023 or more repeated ' characters -- or NUL bytes -- crash the parser with SIGBUS. The same scanner also seeded its column-0 sentinel only when deserialize was called with a NULL buffer, while tree-sitter resets a scanner with a non-NULL inline buffer of length 0, leaving the following scan to read data[-1]. A survey of all 186 vendored scanners found both defects only in agda.
  • Dynamically loaded grammars are ABI-checked at load time. load_from_dir called Language::from_raw on a downloaded parser with only a null check, so an incompatible grammar was accepted and failed later at ts_parser_set_language -- or, just outside the compatible range, parsed wrongly. The ABI version is now compared against the linked runtime's MIN_COMPATIBLE_LANGUAGE_VERSION..=LANGUAGE_VERSION and rejected with both versions named. The bounds are read from the runtime, so a runtime upgrade moves them rather than leaving a stale literal behind.
  • scripts/sync_zig_zon_hashes.py now maintains alef.toml's [crates.e2e.registry.packages.zig.platform_hashes] alongside test_apps/zig/build.zig.zon. Nothing had ever populated that table, so it carried five STALE_HASH_REGENERATE placeholders; Alef responds to a placeholder by omitting the .hash line entirely, which is the only reason the manifest had to be declared user_owned in the first place. The five real digests are in place and the gate now fails on drift in either file.
  • The nightly sanitizer sweep finishes inside its job. Six consecutive nightlies were killed at the 120-minute limit, every one inside the parse sweep after all twelve preceding steps had passed, so the job reported neither its findings nor how far it got. The sweep now runs against a 90-minute budget checked between languages, states how many languages it swept, names any it did not reach, and bounds each parse with a timeout -- one pathological input had been running over ten minutes. The day's language order rotates by day-of-year so a truncated sweep stops dropping the same alphabetical tail every night.
  • That sweep also reports a finding it cannot attribute to a sanitizer exit code. UBSan raises SIGABRT where abort_on_error defaults to 1 and prints ERROR: UndefinedBehaviorSanitizer, neither of which the previous detector matched, so the agda crash above was exactly the shape it let through; any parse killed by a signal now counts. Its sanitizer environment is scoped to the ts-pack invocation as well -- as a step-level env: it also reached the shell, python3,

... (truncated)

Commits
  • 0a8a6b4 chore(swift): update Package.swift with checksum for v1.19.1
  • 481753f fix(swift): include stddef.h for NULL in the RustBridgeC shim
  • f5f9f78 fix(swift): re-stamp the RustBridge files alef owns
  • e57a51f fix(swift): restore the alef stamps the swift-bridge build strips
  • 1605195 fix(alef): hold the generator at 0.85.15 for 1.19.1
  • f070230 chore(release): 1.19.1
  • 025652d test(intel): name the grammars the configuration-node suite needs
  • 6ca0dae fix(zig): gate alef.toml's platform hashes alongside the manifest
  • 1d2d135 chore(swift): prune the superseded release/swift branches
  • 8462b54 fix(registry): reject dynamically loaded grammars with an unusable ABI
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dependencies group with 2 updates: [mcp](https://github.com/modelcontextprotocol/python-sdk) and [tree-sitter-language-pack](https://github.com/xberg-io/tree-sitter-language-pack).


Updates `mcp` from 2.1.1 to 2.2.0
- [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md)
- [Commits](modelcontextprotocol/python-sdk@v2.1.1...v2.2.0)

Updates `tree-sitter-language-pack` from 1.16.2 to 1.19.1
- [Release notes](https://github.com/xberg-io/tree-sitter-language-pack/releases)
- [Changelog](https://github.com/xberg-io/tree-sitter-language-pack/blob/main/CHANGELOG.md)
- [Commits](xberg-io/tree-sitter-language-pack@v1.16.2...v1.19.1)

---
updated-dependencies:
- dependency-name: mcp
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: tree-sitter-language-pack
  dependency-version: 1.19.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 17, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 24, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 24, 2026
@dependabot
dependabot Bot deleted the dependabot/uv/dependencies-ff9b6d759c branch September 24, 2026 15:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants