Skip to content

chore(deps): bump the python-runtime group with 4 updates - #68

Merged
arthurpanhku merged 1 commit into
mainfrom
dependabot/pip/python-runtime-247bab83d3
Oct 9, 2026
Merged

arthurpanhku merged 1 commit into
mainfrom
dependabot/pip/python-runtime-247bab83d3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on a2a-sdk, fastapi, mcp and python-dotenv to permit the latest version.
Updates a2a-sdk from 1.2.0 to 1.2.1

Release notes

Sourced from a2a-sdk's releases.

v1.2.1

1.2.1 (2026-09-30)

Bug Fixes

  • server: use keyset cursors for ListTasks page tokens (#1282) (b7cba7c), closes #1280
Changelog

Sourced from a2a-sdk's changelog.

1.2.1 (2026-09-30)

Bug Fixes

  • server: use keyset cursors for ListTasks page tokens (#1282) (b7cba7c), closes #1280
Commits

Updates fastapi to 0.142.2

Release notes

Sourced from fastapi's releases.

0.142.2

Fixes

  • 🐛 Allow startup when automatic OpenTelemetry configuration fails. PR #16418 by @​tiangolo.
Commits

Updates mcp from 2.2.0 to 2.3.0

Release notes

Sourced from mcp's releases.

v2.3.0

pip install -U mcp. Docs: https://py.sdk.modelcontextprotocol.io/

Mostly fixes, plus three new options. A few things behave differently, so skim these first:

Behaviour changes

httpx2>=2.10.0 is now required (#3600)

  • It was >=2.5.0. The new max_sse_event_size option needs it.
  • Nothing to do unless you pin httpx2 below 2.10.

A tool with an invalid x-mcp-header annotation fails at registration (#3620)

  • @mcp.tool(), add_tool and Tool.from_function raise InvalidSignature, naming the tool and the problem.
  • Until now the server started, and 2026-07-28 clients silently dropped the tool from their listing.
  • Refused: anything other than a plain str, int or bool parameter (so also str | None, float, lists and enums), a header name that isn't a valid token, and two names that differ only by case.
  • For an optional header parameter, give the schema directly: Annotated[str | None, WithJsonSchema({"type": "string", "x-mcp-header": "Region"})] = None.

Empty _meta and params are no longer sent (#3628)

  • On 2025-11-25 and earlier connections, 2.x sent "_meta": {} on every request. Some servers reject that. It is now left out, as in v1.
  • ping and list requests without a cursor go out with no params member.
  • On the receiving side ctx.meta is None rather than {}, and middleware sees ctx.params as None for a request without params.
  • 2026-07-28 connections are unchanged.

initialize leaves out experimental when none is configured (#3614)

  • It used to send "experimental": {}. server/discover already left it out.
  • Client code reading capabilities.experimental on a legacy connection should handle None.

Mcp-Param-* validation looks the tool up by name (#3630)

  • MCPServer no longer runs tools/list for every tools/call, so middleware no longer sees that extra request.
  • The registered schema is what gets checked. Middleware that filters or rewrites tools/list no longer affects it.

An interactive OAuth login no longer counts against request timeouts (#3635)

  • The timeout pauses while OAuthClientProvider waits on redirect_handler and callback_handler.
  • This fixes Client(mode="auto") settling on 2025-11-25 when the login took longer than 10 seconds.
  • A request timeout no longer ends a login nobody finishes. Put a limit inside callback_handler if you need one.

New

  • max_sse_event_size= on streamable_http_client and StreamableHttpParameters. The default stays 1 MiB per SSE event; raise it, or pass None, for larger tool results (#3600).
  • MCPServer(subscriptions=False) stops serving subscriptions/listen and advertises listChanged and subscribe as false (#3626).
  • Server(get_tool_input_schema=...) lets a low-level server supply a tool's schema for header validation without running its tools/list handler (#3630).
  • Client.call_tool re-lists the tools and retries once after a HeaderMismatch (-32020) rejection (#3627).

Fixes

  • ctx: Context[AppState] works on prompts and resource templates, not only on tools (#3624).
  • An explicit "structuredContent": null is checked against the output schema instead of being treated as missing (#3621).
  • A progress_callback that raises no longer fails the call on an in-process Client(server) (#3623).
  • Client OpenTelemetry spans record JSON-RPC error responses. With mode="auto", connecting to a server without server/discover now shows one ERROR span for the probe (#3629).
  • stdio_client resolves the executable off the event loop on Windows (#3510).

... (truncated)

Commits
  • 2118f14 docs: refresh translations for recent English changes (#3636)
  • ed9b2d6 Stop counting an interactive OAuth login against request timeouts (#3635)
  • d5cebd1 Keep inline-snapshot disabled when pytest runs in a terminal (#3634)
  • c15566c Link What's new to the Header parameters page (#3632)
  • 4d29994 Let a newer Deploy Docs run cancel the one in progress (#3633)
  • 0acea60 Bump urllib3 from 2.7.0 to 2.8.0 (#3607)
  • c54075c Look the tool schema up by name for Mcp-Param-* validation instead of running...
  • 9afccae Retry a tool call once after a HeaderMismatch rejection (#3627)
  • cafa33b Record JSON-RPC error responses on the client OpenTelemetry span (#3629)
  • 0b2fd3e Omit an empty _meta and empty params from outbound requests (#3628)
  • Additional commits viewable in compare view

Updates python-dotenv to 1.2.4

Release notes

Sourced from python-dotenv's releases.

v1.2.4

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698
Changelog

Sourced from python-dotenv's changelog.

[1.2.4] - 2026-10-01

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698

[1.2.3] - 2026-08-16

Fixed

  • Strip a leading UTF-8 BOM from .env file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [@​h1whelan] in #640
  • set_key now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [@​dchaudhari7177] in #680
  • dotenv run now prints a friendly error instead of a traceback when no command is given by [@​bbc2] in #606
  • Cache the parsed result for empty .env files so repeated dotenv_values/load_dotenv calls no longer re-read the file by [@​ReinerBRO] in #638

[1.2.2] - 2026-03-01

Added

  • Support for Python 3.14, including the free-threaded (3.14t) build. (#588)

Changed

  • The dotenv run command now forwards flags directly to the specified command by [@​bbc2] in #607
  • Improved documentation clarity regarding override behavior and the reference page.
  • Updated PyPy support to version 3.11.
  • Documentation for FIFO file support.
  • Dropped Support for Python 3.9.

Fixed

  • Improved set_key and unset_key behavior when interacting with symlinks by [@​bbc2] in [790c5c0]
  • Corrected the license specifier and added missing Python 3.14 classifiers in package metadata by [@​JYOuyang] in #590

Breaking Changes

  • dotenv.set_key and dotenv.unset_key used to follow symlinks in some situations. This is no longer the case. For that behavior to be restored in all cases, follow_symlinks=True should be used.

  • In the CLI, set and unset used to follow symlinks in some situations. This is no longer the case.

  • dotenv.set_key, dotenv.unset_key and the CLI commands set and unset used to reset the file mode of the modified .env file to 0o600 in some situations. This is no longer the case: The original mode of the file is now preserved. Is the file needed to be created or wasn't a regular file, mode 0o600 is used.

... (truncated)

Commits
  • a565c2c Bump version: 1.2.3 → 1.2.4
  • 4a7abd0 docs: add 1.2.4 release notes (#663, #698, #700)
  • f215c02 fix: dotenv get exits 0 for empty string values (#700)
  • 58f2d7c test: make test_run_with_command_flags portable and meaningful (#709)
  • e0310e5 fix: honor --no-override when expanding variables in dotenv run (#698)
  • a00cb2e docs: add CHANGELOG entry for #663 (fix #600)
  • f5485a6 fix: parse empty unquoted value with inline comment as empty string
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Updates the requirements on [a2a-sdk](https://github.com/a2aproject/a2a-python), [fastapi](https://github.com/fastapi/fastapi), [mcp](https://github.com/modelcontextprotocol/python-sdk) and [python-dotenv](https://github.com/theskumar/python-dotenv) to permit the latest version.

Updates `a2a-sdk` from 1.2.0 to 1.2.1
- [Release notes](https://github.com/a2aproject/a2a-python/releases)
- [Changelog](https://github.com/a2aproject/a2a-python/blob/main/CHANGELOG.md)
- [Commits](a2aproject/a2a-python@v1.2.0...v1.2.1)

Updates `fastapi` to 0.142.2
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.141.1...0.142.2)

Updates `mcp` from 2.2.0 to 2.3.0
- [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md)
- [Commits](modelcontextprotocol/python-sdk@v2.2.0...v2.3.0)

Updates `python-dotenv` to 1.2.4
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](theskumar/python-dotenv@v1.2.3...v1.2.4)

---
updated-dependencies:
- dependency-name: a2a-sdk
  dependency-version: 1.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-runtime
- dependency-name: fastapi
  dependency-version: 0.142.2
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: mcp
  dependency-version: 2.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-runtime
- dependency-name: python-dotenv
  dependency-version: 1.2.4
  dependency-type: direct:production
  dependency-group: python-runtime
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 7, 2026
@dependabot
dependabot Bot requested a review from arthurpanhku as a code owner October 7, 2026 18:16
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 7, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedpypi/​mcp@​2.2.0 ⏵ 2.3.099 +1100100100100
Updatedpypi/​a2a-sdk@​1.2.0 ⏵ 1.2.1100 +1100100100100

View full report

@arthurpanhku
arthurpanhku merged commit 263a142 into main Oct 9, 2026
7 of 8 checks passed
@dependabot
dependabot Bot deleted the dependabot/pip/python-runtime-247bab83d3 branch October 9, 2026 07:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant