Skip to content

Bump mcp from 1.0.0 to 1.3.0 - #668

Merged
hsbt merged 1 commit into
masterfrom
dependabot/bundler/mcp-1.3.0
Aug 31, 2026
Merged

Bump mcp from 1.0.0 to 1.3.0#668
hsbt merged 1 commit into
masterfrom
dependabot/bundler/mcp-1.3.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

Bumps mcp from 1.0.0 to 1.3.0.

Release notes

Sourced from mcp's releases.

v1.3.0

User-facing documentation now lives on the documentation site at https://ruby.sdk.modelcontextprotocol.io, and README.md keeps the quick start. Two entries under "Changed" reject traffic that earlier releases accepted and ship in a minor release under the exceptions described in https://github.com/modelcontextprotocol/ruby-sdk/blob/HEAD/VERSIONING.md.

Added

  • Add a resources_list_handler for context-dependent resource lists (#509)
  • Pass a handler-returned _meta through the subscribe result (#510)

Changed

  • Bound OAuth response bodies in the client (#520)
  • Reject duplicate in-flight JSON-RPC request ids (#521)
  • Move the documentation from README.md to the documentation site (#523)

v1.2.0

This release completes the SEP-2575 stateless lifecycle of the 2026-07-28 specification, together with the SEP-2322, SEP-2549, and SEP-2243 features that revision builds on. Several entries under "Changed" are incompatible with 1.1.0 and ship in a minor release under the spec-conformance and security exceptions described in https://github.com/modelcontextprotocol/ruby-sdk/blob/HEAD/VERSIONING.md.

Added

  • Handle the SEP-2575 modern request envelope in the server core (#475)
  • Serve both lifecycle eras over stdio with an era lock per SEP-2575 (#478)
  • Serve the sessionless modern path over Streamable HTTP per SEP-2575 (#479)
  • Finalize server/discover and add client modern lifecycle support per SEP-2575 (#480)
  • Let handlers return multi round-trip input_required results per SEP-2322 (#481)
  • Add MCP::Elicitation::EnumSchema builders per SEP-1330 (#482)
  • Stamp the required resultType on modern results per SEP-2322 (#487)
  • Enforce the modern lifecycle admission rules per SEP-2575 (#489)
  • Stream modern request notifications and honor the envelope logLevel per SEP-2575 (#490)
  • Expose the user-defined server_context in instrumentation data (#493)
  • Serve the subscriptions/listen notification stream per SEP-2575 (#495)
  • Add opt-in requestState sealing via MCP::Server::RequestStateSecurity (#496)
  • Mirror x-mcp-header tool parameters into Mcp-Param-* headers per SEP-2243 (#498)
  • Stamp the required cache hints on modern cacheable results per SEP-2549 (#499)
  • Drive multi round-trip input_required results on the client per SEP-2322 (#500)
  • Fulfill input_required results on the legacy wire per SEP-2322 (#501)

Changed

  • Align modern envelope validation with the finalized specification (#491)
  • Require the Mcp-Method header on the modern path (#492)
  • Bound server-to-client requests with a timeout (#502)
  • Refuse server-to-client requests in the modern lifecycle per SEP-2575 (#503)
  • Bound the total wait across SSE reconnection attempts (#504)
  • Bound automatic pagination in the MCP client (#505)
  • Reject modern-removed methods before the connection era locks (#511)
  • Stop negotiating modern protocol versions through the initialize handshake (#516)

Deprecated

  • Warn on modern client connects that declare the Roots or Sampling capabilities deprecated per SEP-2577 (#406, #516)

... (truncated)

Changelog

Sourced from mcp's changelog.

[1.3.0] - 2026-08-22

User-facing documentation now lives on the documentation site at https://ruby.sdk.modelcontextprotocol.io, and README.md keeps the quick start. Two entries under "Changed" reject traffic that earlier releases accepted and ship in a minor release under the exceptions described in https://github.com/modelcontextprotocol/ruby-sdk/blob/main/VERSIONING.md.

Added

  • Add a resources_list_handler for context-dependent resource lists (#509)
  • Pass a handler-returned _meta through the subscribe result (#510)

Changed

  • Bound OAuth response bodies in the client (#520)
  • Reject duplicate in-flight JSON-RPC request ids (#521)
  • Move the documentation from README.md to the documentation site (#523)

[1.2.0] - 2026-08-15

This release completes the SEP-2575 stateless lifecycle of the 2026-07-28 specification, together with the SEP-2322, SEP-2549, and SEP-2243 features that revision builds on. Several entries under "Changed" are incompatible with 1.1.0 and ship in a minor release under the spec-conformance and security exceptions described in https://github.com/modelcontextprotocol/ruby-sdk/blob/main/VERSIONING.md.

Added

  • Handle the SEP-2575 modern request envelope in the server core (#475)
  • Serve both lifecycle eras over stdio with an era lock per SEP-2575 (#478)
  • Serve the sessionless modern path over Streamable HTTP per SEP-2575 (#479)
  • Finalize server/discover and add client modern lifecycle support per SEP-2575 (#480)
  • Let handlers return multi round-trip input_required results per SEP-2322 (#481)
  • Add MCP::Elicitation::EnumSchema builders per SEP-1330 (#482)
  • Stamp the required resultType on modern results per SEP-2322 (#487)
  • Enforce the modern lifecycle admission rules per SEP-2575 (#489)
  • Stream modern request notifications and honor the envelope logLevel per SEP-2575 (#490)
  • Expose the user-defined server_context in instrumentation data (#493)
  • Serve the subscriptions/listen notification stream per SEP-2575 (#495)
  • Add opt-in requestState sealing via MCP::Server::RequestStateSecurity (#496)
  • Mirror x-mcp-header tool parameters into Mcp-Param-* headers per SEP-2243 (#498)
  • Stamp the required cache hints on modern cacheable results per SEP-2549 (#499)
  • Drive multi round-trip input_required results on the client per SEP-2322 (#500)
  • Fulfill input_required results on the legacy wire per SEP-2322 (#501)

Changed

  • Align modern envelope validation with the finalized specification (#491)
  • Require the Mcp-Method header on the modern path (#492)
  • Bound server-to-client requests with a timeout (#502)
  • Refuse server-to-client requests in the modern lifecycle per SEP-2575 (#503)
  • Bound the total wait across SSE reconnection attempts (#504)

... (truncated)

Commits
  • fcb1ac9 Merge pull request #524 from koic/release_1_3_0
  • 79d89e0 Merge pull request #523 from koic/restructure_readme_into_docs_site
  • 833e21a Release 1.3.0
  • 88831b4 Move the Documentation From README.md to the Documentation Site
  • 5124cb4 Merge pull request #522 from koic/update_mrtr_resumption_doc
  • 0ff1406 Merge pull request #510 from koic/pass_meta_through_subscription_results
  • 77f571b [Doc] Describe the client's automatic MRTR resumption
  • 3447328 Merge pull request #509 from koic/add_resources_list_handler
  • 4eb6615 Merge pull request #521 from koic/reject_duplicate_in_flight_request_ids
  • 87ad91d Merge pull request #520 from koic/bound_oauth_response_bodies
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Bumps [mcp](https://github.com/modelcontextprotocol/ruby-sdk) from 1.0.0 to 1.3.0.
- [Release notes](https://github.com/modelcontextprotocol/ruby-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/ruby-sdk/blob/main/CHANGELOG.md)
- [Commits](modelcontextprotocol/ruby-sdk@v1.0.0...v1.3.0)

---
updated-dependencies:
- dependency-name: mcp
  dependency-version: 1.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies ruby Pull requests that update ruby code labels Aug 24, 2026
@hsbt
hsbt merged commit 26defd6 into master Aug 31, 2026
2 checks passed
@hsbt
hsbt deleted the dependabot/bundler/mcp-1.3.0 branch August 31, 2026 07:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies ruby Pull requests that update ruby code

1 participant