chore(deps): bump mcp from 1.26.0 to 1.28.1 in /envs/agent_world_model_env#985
chore(deps): bump mcp from 1.26.0 to 1.28.1 in /envs/agent_world_model_env#985dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [mcp](https://github.com/modelcontextprotocol/python-sdk) from 1.26.0 to 1.28.1. - [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases) - [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md) - [Commits](modelcontextprotocol/python-sdk@v1.26.0...v1.28.1) --- updated-dependencies: - dependency-name: mcp dependency-version: 1.28.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
The docs for this PR live here. All of your documentation changes will be reflected on that endpoint. The docs are available until 30 days after the last update. |
There was a problem hiding this comment.
Alignment Review Report
Dependabot transitive bump: mcp 1.26.0 → 1.28.1 in envs/agent_world_model_env/uv.lock (lock-only, +3/-3). This is a security-positive, born-clean single-package bump — no blocking issues.
Automated Checks
- Lint: PASS (for this diff).
.claude/hooks/lint.shexits non-zero, but every flagged file is pre-existing formatting drift in ~20.pyfiles across other envs (e.g.chat_env,coding_tools_env,opencode_env, andagent_world_model_env/server/web_ui.py). None are in this PR — the diff touches onlyuv.lock, whichruff/usortdon't lint. This PR introduces no lint issues. - Debug code: CLEAN (for this diff).
check-debug.shonly scanssrc/; all hits are pre-existing. This PR changes no.pyfiles.
Verification (positive signals)
- Transitive & lock-only correct —
mcphas no direct pin in this env'spyproject.toml(pulled viafastapi-mcp==0.4.0,fastmcp==3.2.0,mcp-agent==0.2.6,openenv), so a lock-only change with nopyproject.tomledit is expected. uv lock --checkpasses (159 packages resolved) — 1.28.1 satisfies every dependent's constraints.- Hashes verified against PyPI — sdist
d51e36a5…(638,501 B) and wheel2726bca5…(222,620 B) match the lock exactly;requires_python >=3.10, not yanked, 0 known vulnerabilities. - Security fix — base
mcp 1.26.0carries GHSA-hvrp-rf83-w775 (CVE-2026-52870, experimental-tasks cross-client access) and GHSA-jpw9-pfvf-9f58 (CVE-2026-52869, SSE/Streamable-HTTP session-id-only auth), bothfixed_in: 1.27.2→ 1.28.1 clears both. - Born clean — base lock is already fully on
pypi.org/simple(0 HF-mirror refs) atrevision = 3; head is identical. No index-source flip, no revision bump — the entire diff is the singlemcpblock. - Clean single-package bump — 155 → 155 packages, 0 added/removed, only
mcpchanged. - 1.28.0 deprecations don't affect OpenEnv — the newly-deprecated
mcpWebSocket transport and experimental-tasks APIs have 0 usages insrc/orenvs/agent_world_model_env, and there's nofilterwarnings = ["error"]to escalate DeprecationWarnings. The env's directmcpimports (ClientSession,streamable_http_clientinserver/scenario_manager.py) still resolve in 1.28.1.
Open RFCs Context
- RFC 003 — MCP Support (In Review): governs the MCP interface design (action mapping, transports), not the pinned SDK version. Topically adjacent, no conflict.
- RFC 010 (Draft) is an unrelated training-loss technique despite the "ECHO" name. No RFC covers dependency management / PyPI pins.
Tier 1: Fixes Required
None.
Tier 2: Alignment Discussion
Principle Conflicts: None identified.
RFC Conflicts: None identified.
Process note (repo config — not this PR's fault, non-blocking):
FLAG: Native env-scoped dependabot PR opened despite exclude-paths.
.github/dependabot.yml(lines 4-9) configures theuvupdater withdirectory: "/"andexclude-paths: ["envs/**"], yet this nativedependabot/uv/envs/agent_world_model_env/…PR still modifiedenvs/agent_world_model_env/uv.lock. Theuvecosystem doesn't appear to honorexclude-pathsfor env-scoped lockfiles (the aggregate roll-up is the intended path for env bumps). Worth a look at config vs. platform behavior.- Suggested reviewer: @burtenshaw (owns
.github/dependabot.yml, commit5f499da9/ #566).
Summary
- 0 mechanical issues to fix
- 1 alignment point for human review (dependabot
exclude-pathsprocess note, non-blocking) - 0 RFC conflicts
Net: a safe, security-positive, born-clean transitive bump. No code changes recommended — dependabot-generated lockfiles shouldn't be hand-edited (registry/config choices are team decisions).
Sent by Cursor Automation: Pre-review
| [[package]] | ||
| name = "mcp" | ||
| version = "1.26.0" | ||
| version = "1.28.1" |
There was a problem hiding this comment.
Transitive bump verified. mcp is pulled in via fastapi-mcp / fastmcp / mcp-agent / openenv (no direct pin in this env's pyproject.toml), so this lock-only change is correct. uv lock --check passes (159 pkgs resolved) and the package set is unchanged (155→155, only mcp).
Security-positive: base 1.26.0 carries CVE-2026-52870 (GHSA-hvrp-rf83-w775) + CVE-2026-52869 (GHSA-jpw9-pfvf-9f58), both fixed in ≥1.27.2 — so 1.28.1 clears both. 1.28.1 itself has 0 known advisories.
| { name = "uvicorn", marker = "sys_platform != 'emscripten'" }, | ||
| ] | ||
| sdist = { url = "https://files.pythonhosted.org/packages/fc/6d/62e76bbb8144d6ed86e202b5edd8a4cb631e7c8130f3f4893c3f90262b10/mcp-1.26.0.tar.gz", hash = "sha256:db6e2ef491eecc1a0d93711a76f28dec2e05999f93afd48795da1c1137142c66", size = 608005, upload-time = "2026-01-24T19:40:32.468Z" } | ||
| sdist = { url = "https://files.pythonhosted.org/packages/6e/77/9450b8f251a13affb6281997d0523c4615f8a8b35d0b21ff30db3a5aac9d/mcp-1.28.1.tar.gz", hash = "sha256:d51e36a5f5644faea4f85ea649bfffa6bc6c26770d42798ad6a3de3d2ba69683", size = 638501, upload-time = "2026-06-26T12:57:29.093Z" } |
There was a problem hiding this comment.
Hashes verified against PyPI. This sdist d51e36a5… (638,501 B) and the wheel below (2726bca5…, 222,620 B) match pypi.org/pypi/mcp/1.28.1 exactly; requires_python >=3.10, not yanked.
This lock is born clean (already pypi.org/simple + revision = 3 at base), so the diff is just this mcp block — no index-source flip or revision churn.
Heads-up: mcp 1.28.0 deprecates the WebSocket transport + experimental-tasks APIs, but neither is used in this env or src/, and no filterwarnings=error is set — no runtime impact.
|
Aggregated into #921. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |


Bumps mcp from 1.26.0 to 1.28.1.
Release notes
Sourced from mcp's releases.
... (truncated)
Commits
777b8d0[v1.x] Support TransportSecuritySettings in the WebSocket server transport (#...4720467[v1.x] Set Development Status classifier to Production/Stable (#2976)6df3d73[v1.x] Buffer per-request StreamableHTTP streams; store priming event before ...32d3290[v1.x] Pass a list to parametrize in test_docs_examples (pytest 9.1.0 compat)...0dca751[v1.x] Deflake the child process cleanup tests (#2839)52258a9[v1.x] Add a v2 status banner to the README (#2835)b8f4917[v1.x] Deprecate the WebSocket transport and the experimental tasks entry poi...2309e5efix: omit null optional fields from task result payloads (#2809)494eb11[v1.x] Support Python 3.14 (#2769)6213787[v1.x] Scope experimental tasks to the session that created them (#2720)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
Note
Low Risk
Dependency lock refresh with no repo code changes; minor risk if tests treat new MCP deprecation warnings as errors or if upstream auth/session binding affects MCP clients at runtime.
Overview
Updates the
mcpPython SDK lock entry inenvs/agent_world_model_env/uv.lockfrom 1.26.0 to 1.28.1 (sdist and wheel URLs/hashes only). No application source orpyproject.tomldependency pins change in this diff.The newer SDK includes auth-related fixes (e.g. binding transport sessions to the authenticated principal,
AccessTokenmetadata), StreamableHTTP buffering, Pydantic/OAuth edge-case fixes, and deprecation warnings for WebSocket transport and experimental tasks APIs when those code paths are used.agent_world_model_envconsumes MCP viamcp-agentand OpenEnv’sMCPToolClient/ MCP types, so behavior should stay the same unless those stacks hit deprecated surfaces or strict warning-as-error test settings.Reviewed by Cursor Bugbot for commit aa82d68. Bugbot is set up for automated code reviews on this repo. Configure here.