Skip to content

chore(deps): bump fastmcp from 4.0.5 to 4.0.8 - #786

Open
dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/uv/staging/fastmcp-4.0.8
Open

dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/uv/staging/fastmcp-4.0.8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor

Bumps fastmcp from 4.0.5 to 4.0.8.

Release notes

Sourced from fastmcp's releases.

v4.0.8: Take Three

Completion goes back to its 4.0.5 behavior. The visibility check added in 4.0.6 and reworked in 4.0.7 simulated list requests through middleware, and in 4.0.7 that could let a response cache serve hidden prompts to other clients. New tests pin both problems, and withholding suggestions for hidden references will return with a proper design. Resource template patterns are now cached without a size limit, so servers with thousands of templates read fast again, and OAuthProxy revokes the upstream refresh token instead of sending its own token upstream.

What's Changed

Security 🔒

Fixes 🐞

Docs 📚

New Contributors

Full Changelog: PrefectHQ/fastmcp@v4.0.7...v4.0.8

v4.0.7: Double Take

Fixes two regressions from 4.0.6. The completion visibility check runs only the list-specific middleware hooks, so rate limits, logging, and metrics see a single request per completion again. Resource template patterns are cached, which makes template reads faster than in 4.0.5.

What's Changed

Fixes 🐞

Docs 📚

Full Changelog: PrefectHQ/fastmcp@v4.0.6...v4.0.7

v4.0.6: Comma Chameleon

Resource templates now match what clients actually send: literals raw or percent-encoded, and list query parameters exploded or comma-joined. A Client whose exit is cancelled releases its session instead of leaking it, completion no longer answers for prompts and templates the caller can't see, and JSON schemas with float or oversized length limits load instead of failing. The auth fixes cache OIDC discovery and keep Google tokens out of request URLs.

What's Changed

Enhancements ✨

Security 🔒

... (truncated)

Changelog

Sourced from fastmcp's changelog.


title: "Changelog" icon: "list-check" rss: true tag: NEW

v4.0.10: Inside Job

Task-enabled tools now work behind search transforms and CodeMode: they're registered with the task backend even when hidden, and a tool, resource, or prompt that calls one through ctx.fastmcp.call_tool() (including the search call_tool proxy and CodeMode's execute) now gets its result instead of an empty task receipt.

Fixes 🐞

  • fix(stdio): tolerate a transport whose construction failed in __del__ by @​kbkb628 in #5256
  • tasks: register task tools hidden by search and CodeMode by @​zzstoatzz in #5262
  • tasks: run tools called from another tool in the foreground by @​zzstoatzz in #5275

Docs 📚

New Contributors

Full Changelog: v4.0.9...v4.0.10

v4.0.9: Cache and Release

ResourceTemplate now keeps its compiled URI pattern for its own lifetime while the shared cache is bounded again, preventing dynamic proxies from growing process memory without restoring the 4,096-template performance cliff.

Fixes 🐞

  • resources: keep each template's compiled pattern on the template by @​zzstoatzz in #5253

Full Changelog: v4.0.8...v4.0.9

v4.0.8: Take Three

Completion goes back to its 4.0.5 behavior. The visibility check added in 4.0.6 and reworked in 4.0.7 simulated list requests through middleware, and in 4.0.7 that could let a response cache serve hidden prompts to other clients. New tests pin both problems, and withholding suggestions for hidden references will return with a proper design. Resource template patterns are now cached without a size limit, so servers with thousands of templates read fast again, and OAuthProxy revokes the upstream refresh token instead of sending its own token upstream.

Security 🔒

Fixes 🐞

... (truncated)

Commits
  • 8299082 docs: add v4.0.8 changelog entries (#5251)
  • 2af8a68 resources: keep every compiled template pattern cached (#5248)
  • 94c346f completions: revert the list-based visibility check (#5240, #5244) (#5250)
  • 9949d9a Fix OAuthProxy upstream refresh token revocation (#5243)
  • 83c9734 docs: add v4.0.7 changelog entries (#5246)
  • e913d93 resources: cache compiled URI template patterns (#5245)
  • 94c5a21 completions: check reference visibility through typed list hooks only (#5244)
  • 15fd008 docs: add v4.0.6 changelog entries (#5241)
  • 0959c27 completions: answer only references the caller can list (#5240)
  • a031ba9 ci: retry downstream version lookups and bind the wedge test's names (#5239)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [fastmcp](https://github.com/PrefectHQ/fastmcp) from 4.0.5 to 4.0.8.
- [Release notes](https://github.com/PrefectHQ/fastmcp/releases)
- [Changelog](https://github.com/PrefectHQ/fastmcp/blob/main/docs/changelog.mdx)
- [Commits](PrefectHQ/fastmcp@v4.0.5...v4.0.8)

---
updated-dependencies:
- dependency-name: fastmcp
  dependency-version: 4.0.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 27, 2026
@coderabbitai

coderabbitai Bot commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 01ecf165-0b5b-4cfb-a497-d7ec928ccfb7

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
pip/fastmcp 4.0.8 UnknownUnknown
pip/fastmcp-slim 4.0.8 UnknownUnknown

Scanned Files

  • uv.lock

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants