Skip to content

chore(deps): bump the python-runtime group across 1 directory with 3 updates - #63

Merged
arthurpanhku merged 1 commit into
mainfrom
dependabot/pip/python-runtime-69e8655a67
Oct 5, 2026
Merged

arthurpanhku merged 1 commit into
mainfrom
dependabot/pip/python-runtime-69e8655a67

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on a2a-sdk, uvicorn and mcp to permit the latest version.
Updates a2a-sdk from 1.1.2 to 1.2.0

Release notes

Sourced from a2a-sdk's releases.

v1.2.0

1.2.0 (2026-09-29)

Features

  • rest: serve HTTP+JSON responses as application/a2a+json (#1274) (dc5a5da)
  • server: add caching headers to the agent card endpoint (#1272) (83d7f5d)
  • server: add multi-replica cluster mode (#1281) (942d621)
  • server: add opt-in validation of message media types against the agent card (#1269) (8037b24)

Bug Fixes

  • compare in-memory task timestamps numerically (#1233) (0d5473c)
  • server: ignore unrecognized request fields and fix parse-error data shape (#1273) (83f1cf8)
  • server: reject a message whose contextId disagrees with its task (#1270) (c25022f)
  • server: reject terminal-task operations with UnsupportedOperationError (#1268) (6cce91b)
  • server: send PushNotificationConfig.authentication as an Authorization header (#1271) (5751d31), closes #585

Documentation

v1.1.5

1.1.5 (2026-09-21)

Bug Fixes

  • deps: support protobuf 7 (#1260) (67ba0a4)
  • replace deprecated FieldDescriptor.label with is_repeated in proto_utils (#1158) (4554e2d)
  • server: avoid out-of-range datetime task ordering (#1220) (d55a3d3)

v1.1.4

1.1.4 (2026-09-07)

Features

  • itk: register itk-python-v10-agent as a uv workspace member and update dependency version markers (#1203) (6eee895)
  • itk: use shared scenarios (#1201) (b4a0b21)

Bug Fixes

... (truncated)

Changelog

Sourced from a2a-sdk's changelog.

1.2.0 (2026-09-29)

Features

  • rest: serve HTTP+JSON responses as application/a2a+json (#1274) (dc5a5da)
  • server: add caching headers to the agent card endpoint (#1272) (83d7f5d)
  • server: add multi-replica cluster mode (#1281) (942d621)
  • server: add opt-in validation of message media types against the agent card (#1269) (8037b24)

Bug Fixes

  • compare in-memory task timestamps numerically (#1233) (0d5473c)
  • server: ignore unrecognized request fields and fix parse-error data shape (#1273) (83f1cf8)
  • server: reject a message whose contextId disagrees with its task (#1270) (c25022f)
  • server: reject terminal-task operations with UnsupportedOperationError (#1268) (6cce91b)
  • server: send PushNotificationConfig.authentication as an Authorization header (#1271) (5751d31), closes #585

Documentation

1.1.5 (2026-09-21)

Bug Fixes

  • deps: support protobuf 7 (#1260) (67ba0a4)
  • replace deprecated FieldDescriptor.label with is_repeated in proto_utils (#1158) (4554e2d)
  • server: avoid out-of-range datetime task ordering (#1220) (d55a3d3)

1.1.4 (2026-09-07)

Features

  • itk: register itk-python-v10-agent as a uv workspace member and update dependency version markers (#1203) (6eee895)
  • itk: use shared scenarios (#1201) (b4a0b21)

Bug Fixes

  • make event queue sink removal idempotent (#1134) (58c72c6)
  • omit artifacts from list tasks responses (#1212) (35ef52e)
  • owner-scope cancel/subscribe and write terminal state on cancel (#1159, #1170) (#1172) (ddbf853)
  • prevent first-owner write loss in in-memory stores (#1194) (bcc489c)
  • server: let subscriber taps evict on full instead of wedging dispatch (#1137) (0c2126f)
  • server: surface producer errors after failed tasks (#1229) (bc32d7e)

... (truncated)

Commits
  • 5ca9859 chore(main): release 1.2.0 (#1266)
  • 942d621 feat(server): add multi-replica cluster mode (#1281)
  • dc5a5da feat(rest): serve HTTP+JSON responses as application/a2a+json (#1274)
  • 83f1cf8 fix(server): ignore unrecognized request fields and fix parse-error data shap...
  • 83d7f5d feat(server): add caching headers to the agent card endpoint (#1272)
  • 5751d31 fix(server): send PushNotificationConfig.authentication as an Authorization h...
  • c25022f fix(server): reject a message whose contextId disagrees with its task (#1270)
  • 8037b24 feat(server): add opt-in validation of message media types against the agent ...
  • 6cce91b fix(server): reject terminal-task operations with UnsupportedOperationError (...
  • 0d5473c fix: compare in-memory task timestamps numerically (#1233)
  • Additional commits viewable in compare view

Updates uvicorn to 0.54.0

Release notes

Sourced from uvicorn's releases.

Version 0.54.0

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0

Changelog

Sourced from uvicorn's changelog.

0.54.0 (September 24, 2026)

HTTP/2 support remains experimental. Install zttp>=0.0.34 and enable it with --http zttp --http2.

Added

  • Add HTTP/2 response trailers through the ASGI http.response.trailers extension. Clients must send TE: trailers to receive them (#3146)
  • Add HTTP/2 103 Early Hints through the ASGI http.response.early_hint extension (#3137)

0.53.0 (September 14, 2026)

This release adds experimental HTTP/2 support through zttp. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

Added

  • Add experimental HTTP/2 support through zttp (#2982, #3101)
  • Add support for zuvloop (#3104)

Fixed

  • Handle comma-separated, case-insensitive Connection: close tokens across HTTP implementations (#3103)
  • Trust IPv6 loopback in the default FORWARDED_ALLOW_IPS value (#3119)
  • Cancel the HTTP keep-alive timer when upgrading to WebSocket (#3107)

0.52.4 (August 18, 2026)

Fixed

  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#3078)

0.52.3 (August 13, 2026)

Changed

  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#3067)

0.52.2 (August 13, 2026)

Fixed

  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#3063)

0.52.1 (August 1, 2026)

Fixed

  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#3050)

... (truncated)

Commits

Updates mcp from 2.1.1 to 2.2.0

Release notes

Sourced from mcp's releases.

v2.2.0

pip install -U mcp. Docs: https://py.sdk.modelcontextprotocol.io/

A few defaults changed in this release. If you run a server or client on 2.x, skim these first:

Behaviour changes

HTTP client redirects are only followed within the endpoint's origin (#3397)

  • Client("https://..."), streamable_http_client and sse_client follow a redirect only if it stays on the same scheme, host and port (or upgrades http to https on the same host).
  • A redirect anywhere else is not followed: the call fails with MCPError and the session stays usable (an SSE connect fails with httpx2.HTTPStatusError). If that other URL is the server you meant, use it as the endpoint URL.
  • The follow_redirects setting on an httpx2.AsyncClient you pass in is no longer used for MCP requests, so you don't need it for the trailing-slash redirect any more.
  • The OAuth providers apply the same rule to their own requests.

Idle Streamable HTTP sessions now expire (legacy <=2025-11-25 spec( (#3395)

  • A stateful session with nothing in flight for 30 minutes is closed. The client's next request gets a 404 and it has to initialize again.
  • Clients that keep the GET stream open (the SDK's Client does) are not affected. Neither are stateless servers or 2026-07-28 connections.
  • A server also holds at most 10 000 sessions at once; beyond that, new sessions get a 503.
  • To turn either off: mcp.run(transport="streamable-http", session_idle_timeout=None, max_sessions=None) (also on streamable_http_app() and run_streamable_http_async()).

The OAuth client checks the authorization server's issuer on the legacy path too (#3398)

  • For servers without protected resource metadata, authorization server metadata whose issuer isn't the server's own origin is now rejected with OAuthFlowError: Authorization server metadata issuer mismatch. The protected-resource-metadata path has done this since 2.0.
  • A 403 that isn't an insufficient_scope challenge is returned to the caller instead of retried.
  • If protected resource metadata can't be fetched because of a 5xx/429, the flow now stops instead of falling back to the legacy endpoints.

Two new MCPDeprecationWarnings (#3435, #3447)

  • ClientCredentialsOAuthProvider / PrivateKeyJWTOAuthProvider without issuer=. Pass your authorization server's issuer URL; 3.0 will require it.
  • AuthSettings with resource_server_url set but validate_token_resource unset. Set it to True or False; 3.0 defaults it to True.
  • Both keep working as before in 2.x; this mostly matters if your tests turn warnings into errors.

New

  • AuthSettings.validate_token_resource: only accept tokens your TokenVerifier reports as issued for this server (#3447).
  • issuer= on ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider (#3398).
  • session_idle_timeout= and max_sessions= on the Streamable HTTP server entry points (#3395).

Fixes

  • A client DELETE frees its session immediately, and a refused opening request no longer leaves a session behind (#2455, #3228, #3300).
  • $refs in a tool's outputSchema resolve within that schema only; an unresolvable one surfaces as RuntimeError: Invalid schema for tool ... (#3394).

Known gaps

The tasks extension (SEP-2663), DPoP (SEP-1932) and the jwt-bearer grant are not implemented yet; https://github.com/modelcontextprotocol/python-sdk/blob/main/ROADMAP.md tracks them.

What's Changed

... (truncated)

Commits
  • 9972c21 Replace RootModel wrappers with type aliases and TypeAdapter validation (#3470)
  • fd66270 docs: refresh translations, and translate pages in parallel (#3458)
  • 08a3bc8 docs: ask for AI disclosure on comments too (#3459)
  • 7bb486a docs: stop presenting the in-memory client as the way to connect (#3443)
  • 0c91368 Add AuthSettings.validate_token_resource to check a bearer token's resource (...
  • 9771e6b Keep following a relative redirect when the endpoint URL carries userinfo (#3...
  • a925e55 Bump the locked versions of eight dev and test dependencies (#3449)
  • e8b9486 Bump pymdown-extensions from 11.0 to 11.0.1 (#3285)
  • c6762e8 Follow redirects only within the MCP endpoint's origin (#3397)
  • 5fd3abc Skip automatic docs previews for fork PRs and drop the setup-uv retry steps (...
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 23, 2026
@dependabot
dependabot Bot requested a review from arthurpanhku as a code owner September 23, 2026 18:19
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 23, 2026
@socket-security

socket-security Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedpypi/​mcp@​2.1.1 ⏵ 2.2.099 +1100100100100
Updatedpypi/​a2a-sdk@​1.1.2 ⏵ 1.2.0100100100100100

View full report

…updates

Updates the requirements on [a2a-sdk](https://github.com/a2aproject/a2a-python), [uvicorn](https://github.com/Kludex/uvicorn) and [mcp](https://github.com/modelcontextprotocol/python-sdk) to permit the latest version.

Updates `a2a-sdk` from 1.1.2 to 1.2.0
- [Release notes](https://github.com/a2aproject/a2a-python/releases)
- [Changelog](https://github.com/a2aproject/a2a-python/blob/main/CHANGELOG.md)
- [Commits](a2aproject/a2a-python@v1.1.2...v1.2.0)

Updates `uvicorn` to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.52.4...0.54.0)

Updates `mcp` from 2.1.1 to 2.2.0
- [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md)
- [Commits](modelcontextprotocol/python-sdk@v2.1.1...v2.2.0)

---
updated-dependencies:
- dependency-name: a2a-sdk
  dependency-version: 1.1.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-runtime
- dependency-name: mcp
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-runtime
- dependency-name: uvicorn
  dependency-version: 0.53.0
  dependency-type: direct:production
  dependency-group: python-runtime
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump the python-runtime group with 3 updates chore(deps): bump the python-runtime group across 1 directory with 3 updates Oct 2, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/python-runtime-69e8655a67 branch from 19df98e to bd84ddc Compare October 2, 2026 16:03
@arthurpanhku
arthurpanhku merged commit 77392da into main Oct 5, 2026
7 of 8 checks passed
@dependabot
dependabot Bot deleted the dependabot/pip/python-runtime-69e8655a67 branch October 5, 2026 03:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant