Skip to content

Bump mcp from 1.0.0 to 1.3.0 - #668

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bundler/mcp-1.3.0
Open

Bump mcp from 1.0.0 to 1.3.0#668
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bundler/mcp-1.3.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

Bumps mcp from 1.0.0 to 1.3.0.

Release notes

Sourced from mcp's releases.

v1.3.0

User-facing documentation now lives on the documentation site at https://ruby.sdk.modelcontextprotocol.io, and README.md keeps the quick start. Two entries under "Changed" reject traffic that earlier releases accepted and ship in a minor release under the exceptions described in https://github.com/modelcontextprotocol/ruby-sdk/blob/HEAD/VERSIONING.md.

Added

  • Add a resources_list_handler for context-dependent resource lists (#509)
  • Pass a handler-returned _meta through the subscribe result (#510)

Changed

  • Bound OAuth response bodies in the client (#520)
  • Reject duplicate in-flight JSON-RPC request ids (#521)
  • Move the documentation from README.md to the documentation site (#523)

v1.2.0

This release completes the SEP-2575 stateless lifecycle of the 2026-07-28 specification, together with the SEP-2322, SEP-2549, and SEP-2243 features that revision builds on. Several entries under "Changed" are incompatible with 1.1.0 and ship in a minor release under the spec-conformance and security exceptions described in https://github.com/modelcontextprotocol/ruby-sdk/blob/HEAD/VERSIONING.md.

Added

  • Handle the SEP-2575 modern request envelope in the server core (#475)
  • Serve both lifecycle eras over stdio with an era lock per SEP-2575 (#478)
  • Serve the sessionless modern path over Streamable HTTP per SEP-2575 (#479)
  • Finalize server/discover and add client modern lifecycle support per SEP-2575 (#480)
  • Let handlers return multi round-trip input_required results per SEP-2322 (#481)
  • Add MCP::Elicitation::EnumSchema builders per SEP-1330 (#482)
  • Stamp the required resultType on modern results per SEP-2322 (#487)
  • Enforce the modern lifecycle admission rules per SEP-2575 (#489)
  • Stream modern request notifications and honor the envelope logLevel per SEP-2575 (#490)
  • Expose the user-defined server_context in instrumentation data (#493)
  • Serve the subscriptions/listen notification stream per SEP-2575 (#495)
  • Add opt-in requestState sealing via MCP::Server::RequestStateSecurity (#496)
  • Mirror x-mcp-header tool parameters into Mcp-Param-* headers per SEP-2243 (#498)
  • Stamp the required cache hints on modern cacheable results per SEP-2549 (#499)
  • Drive multi round-trip input_required results on the client per SEP-2322 (#500)
  • Fulfill input_required results on the legacy wire per SEP-2322 (#501)

Changed

  • Align modern envelope validation with the finalized specification (#491)
  • Require the Mcp-Method header on the modern path (#492)
  • Bound server-to-client requests with a timeout (#502)
  • Refuse server-to-client requests in the modern lifecycle per SEP-2575 (#503)
  • Bound the total wait across SSE reconnection attempts (#504)
  • Bound automatic pagination in the MCP client (#505)
  • Reject modern-removed methods before the connection era locks (#511)
  • Stop negotiating modern protocol versions through the initialize handshake (#516)

Deprecated

  • Warn on modern client connects that declare the Roots or Sampling capabilities deprecated per SEP-2577 (#406, #516)

... (truncated)

Changelog

Sourced from mcp's changelog.

[1.3.0] - 2026-08-22

User-facing documentation now lives on the documentation site at https://ruby.sdk.modelcontextprotocol.io, and README.md keeps the quick start. Two entries under "Changed" reject traffic that earlier releases accepted and ship in a minor release under the exceptions described in https://github.com/modelcontextprotocol/ruby-sdk/blob/main/VERSIONING.md.

Added

  • Add a resources_list_handler for context-dependent resource lists (#509)
  • Pass a handler-returned _meta through the subscribe result (#510)

Changed

  • Bound OAuth response bodies in the client (#520)
  • Reject duplicate in-flight JSON-RPC request ids (#521)
  • Move the documentation from README.md to the documentation site (#523)

[1.2.0] - 2026-08-15

This release completes the SEP-2575 stateless lifecycle of the 2026-07-28 specification, together with the SEP-2322, SEP-2549, and SEP-2243 features that revision builds on. Several entries under "Changed" are incompatible with 1.1.0 and ship in a minor release under the spec-conformance and security exceptions described in https://github.com/modelcontextprotocol/ruby-sdk/blob/main/VERSIONING.md.

Added

  • Handle the SEP-2575 modern request envelope in the server core (#475)
  • Serve both lifecycle eras over stdio with an era lock per SEP-2575 (#478)
  • Serve the sessionless modern path over Streamable HTTP per SEP-2575 (#479)
  • Finalize server/discover and add client modern lifecycle support per SEP-2575 (#480)
  • Let handlers return multi round-trip input_required results per SEP-2322 (#481)
  • Add MCP::Elicitation::EnumSchema builders per SEP-1330 (#482)
  • Stamp the required resultType on modern results per SEP-2322 (#487)
  • Enforce the modern lifecycle admission rules per SEP-2575 (#489)
  • Stream modern request notifications and honor the envelope logLevel per SEP-2575 (#490)
  • Expose the user-defined server_context in instrumentation data (#493)
  • Serve the subscriptions/listen notification stream per SEP-2575 (#495)
  • Add opt-in requestState sealing via MCP::Server::RequestStateSecurity (#496)
  • Mirror x-mcp-header tool parameters into Mcp-Param-* headers per SEP-2243 (#498)
  • Stamp the required cache hints on modern cacheable results per SEP-2549 (#499)
  • Drive multi round-trip input_required results on the client per SEP-2322 (#500)
  • Fulfill input_required results on the legacy wire per SEP-2322 (#501)

Changed

  • Align modern envelope validation with the finalized specification (#491)
  • Require the Mcp-Method header on the modern path (#492)
  • Bound server-to-client requests with a timeout (#502)
  • Refuse server-to-client requests in the modern lifecycle per SEP-2575 (#503)
  • Bound the total wait across SSE reconnection attempts (#504)

... (truncated)

Commits
  • fcb1ac9 Merge pull request #524 from koic/release_1_3_0
  • 79d89e0 Merge pull request #523 from koic/restructure_readme_into_docs_site
  • 833e21a Release 1.3.0
  • 88831b4 Move the Documentation From README.md to the Documentation Site
  • 5124cb4 Merge pull request #522 from koic/update_mrtr_resumption_doc
  • 0ff1406 Merge pull request #510 from koic/pass_meta_through_subscription_results
  • 77f571b [Doc] Describe the client's automatic MRTR resumption
  • 3447328 Merge pull request #509 from koic/add_resources_list_handler
  • 4eb6615 Merge pull request #521 from koic/reject_duplicate_in_flight_request_ids
  • 87ad91d Merge pull request #520 from koic/bound_oauth_response_bodies
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [mcp](https://github.com/modelcontextprotocol/ruby-sdk) from 1.0.0 to 1.3.0.
- [Release notes](https://github.com/modelcontextprotocol/ruby-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/ruby-sdk/blob/main/CHANGELOG.md)
- [Commits](modelcontextprotocol/ruby-sdk@v1.0.0...v1.3.0)

---
updated-dependencies:
- dependency-name: mcp
  dependency-version: 1.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies ruby Pull requests that update ruby code labels Aug 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants