Skip to content

Update rust-dependencies (major) - #2197

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/major-rust-dependencies
Open

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/major-rust-dependencies

Conversation

@renovate

@renovate renovate Bot commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Pending
rmcp dependencies major 0.17 → 3.0 3.5.0 (+1)
zip dependencies major 2.1 → 8.0

Release Notes

modelcontextprotocol/rust-sdk (rmcp)

v3.4.0

Compare Source

Added
  • (model) add ServerConfig and ClientConfig (#​1266)
Fixed
  • (rmcp) use ServerConfig in cancellation test (#​1273)
  • (rmcp) route peer cancellation by lifecycle (#​1262)
  • run first pre-init request in service loop (#​1263)
  • (auth) let url origin decide prm discovery (#​1264)
  • (model) deprecate ServerInfo and ClientInfo aliases (#​1156)
  • (auth) ignore non-metadata JSON when probing for protected resource metadata (#​1204)
  • do not treat malformed JSON 200 as Accepted for requests (#​1208)
  • (streamable-http-server) map handler-generated HeaderMismatch to HTTP 400 (#​1259)
  • (http) enforce Origin validation semantics (#​1192)

v3.3.0

Compare Source

Added
  • add ServerHandler::negotiate_initialize (#​1247)
  • (macros) reject empty tool_router (#​1233)
  • (auth) add enterprise refresh-token and ID-JAG exchanges (#​1234)
Fixed
  • (sse) saturate exponential reconnect backoff to avoid overflow panic (#​1231)
  • resolve clippy warnings across workspace (#​1195)
  • (auth) unify refresh checks and error handling (#​1236)
Other
  • (deps) update process-wrap requirement from 9.0 to 10.0 (#​1229)

v3.2.0

Compare Source

Added
  • (auth) coordinate OAuth refreshes through credential stores (#​1232)
  • add request-state key rotation (#​1128)
Fixed
  • keep initialize on legacy protocol versions (#​1228)
  • (transport) fall back after sessionless HTTP discover rejections (#​1211)
  • allow concurrent streamable http requests (#​1186)

v3.1.4

Compare Source

Fixed
  • (rmcp) preserve elicitation requestedSchema $schema dialect (#​1176)
  • harden signing key handling (#​1166)
  • report pre-init metadata errors (#​1160)

v3.1.3

Compare Source

Fixed
  • (auth) ignore query parameters when matching resources (#​1177)
  • (auth) retain state until issuer validation (#​1167)
  • (model) preserve elicitation property order metadata (#​1150)
  • time out auto discovery probe (#​1149)
  • (client) classify discover outcome at source, not at the error type (#​1133)
Other
  • Fix typo in to_authorized_http_client doc comment (#​1158)

v3.1.2

Compare Source

Fixed
  • (auth) map 401/403 challenges on the SSE GET stream (#​1152)
  • (sse) loop instead of recursing when skipping SSE events (#​1146)
  • (auth) preserve issuer trailing slash during discovery (#​1145)

v3.1.1

Compare Source

Fixed
  • emit cache hints from handler macros (#​1120)
  • expose MRTR state to tool handlers (#​1104)
  • disambiguate input-required results (#​1103)
Other

v3.1.0

Compare Source

Added
  • classify authorization-required errors (#​1056)
  • add strict stateless protocol metadata validation (#​1091)
  • SEP-2260 stream-based enforcement of client receive-side request association (#​1055)
Fixed
  • (model) decode metadata-bearing input-required results affecting mrtr (#​1097)
  • require metadata for modern HTTP requests (#​1089)
  • honor supported_protocol_versions when negotiating initialize (#​1093)
Other
  • document the ping utility with examples (#​1106)
  • complete Tier 1 feature docs and finalize roadmap (#​1101)
  • (conformance) meeting requirements for tier 1 (#​1087)

v3.0.1

Compare Source

Fixed
  • (auth) use discovered resource for token refresh (#​1084)
  • return header mismatch for missing protocol header (#​1083)
  • negotiate stateless initialize versions (#​1080)
  • stamp server info on graceful subscription results (#​1078)

v3.0.0

Compare Source

RMCP 3.0 adds support for MCP 2026-07-28. Review the protocol key changes and the RMCP 3.0 migration guide before upgrading from 2.x.

Breaking changes

  • Sessionless Streamable HTTP: MCP 2026-07-28 removes protocol-level sessions: no Mcp-Session-Id, standalone GET stream, DELETE-based session termination, or Last-Event-ID resumption. RMCP creates a fresh handler per request, so persistent state must live outside the handler. stateful_mode is renamed to legacy_session_mode and now only controls older protocol versions; custom SSE clients must also accept an optional session ID.
  • Stateless lifecycle and discovery: the 2026-07-28 protocol removes initialize/notifications/initialized; each request carries the protocol version and client capabilities in _meta, and servers expose server/discover. RMCP clients opt into this lifecycle with serve_with_lifecycle and ClientLifecycleMode::Discover or Auto; the existing serve() path remains available for legacy initialization.
  • Subscriptions and removed methods: subscriptions/listen replaces the standalone GET stream and resources/subscribe/resources/unsubscribe. ping, logging/setLevel, and notifications/roots/list_changed are unavailable under 2026-07-28; RMCP retains their APIs for legacy protocol sessions.
  • Multi Round-Trip Requests and result types: ServerHandler::call_tool, get_prompt, and read_resource now return MRTR-aware response enums. Manual handler implementations and exhaustive ServerResult matches must handle InputRequiredResult, and result models carry an optional result_type for legacy wire compatibility.
  • Tasks: the experimental core tasks API is replaced by the io.modelcontextprotocol/tasks extension, including new task handlers, methods, and TaskManager APIs.
  • Rust model types: metadata is split into MetaObject, RequestMetaObject, and NotificationMetaObject; Annotations::last_modified is now Option<String>; and tool structured content accepts any serde_json::Value.
  • OAuth: authorization startup is consolidated around AuthorizationRequest; metadata discovery is renamed to resolve_metadata and returns provenance; and custom OAuth HTTP errors are now boxed source errors.
  • Compatibility: APIs deprecated before 3.0 have been removed, and the minimum supported Rust version is now 1.88.

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/rust-sdk@rmcp-v2.2.0...rmcp-v3.0.0

v2.2.0

Compare Source

Added
  • reject auth servers lacking S256 PKCE support (#​955)
Fixed
  • pass client conformance suite (#​960)
  • don't respond to cancelled requests (#​957)
  • fail orphaned streamable HTTP responses on reinit (#​914)
  • address 2025-11-25 conformance audit findings (#​951)

v2.1.0

Compare Source

Added
  • add SEP-414 trace context meta accessors (#​910)
  • add SEP-2575 meta helpers (#​942)
Fixed
  • (transport) make AsyncRwTransport::receive cancel-safe (#​941) (#​947)
  • (auth) preserve refresh_token when refresh response omits it (#​949)
  • block redirect header leaks (#​936)
  • don't respond to unparsable messages (#​940)
  • negotiate protocol version in handler (#​930)

v2.0.0

Compare Source

Migration guide: https://redirect.github.com/modelcontextprotocol/rust-sdk/discussions/926

Added
  • [breaking] (rmcp) add Audio variant to PromptMessageContent (#​865)
  • [breaking] align model types with MCP 2025-11-25 spec (#​927)
  • deprecate roots/sampling/logging types (#​923)
Fixed
  • prevent OAuth resource spoofing (#​937)
  • block oauth metadata ssrf (#​935)
  • prevent streamable HTTP session leak (#​934)
  • fill missing fully qualified syntax in prompt_handler macros (#​866)
Other
  • consolidate repeated rmcp tests (#​931)
  • align README examples with v2 model API (#​928)

v1.8.0

Compare Source

[!WARNING]

⚠️ Breaking Changes

Despite being a minor version bump, this release contains a source-breaking API change (it should have been 2.0.0). If you depend on rmcp = "1.7", Cargo will resolve to 1.8.0 automatically and your build may fail. Pin to =1.7.x if you are not ready to migrate.

Peer::peer_info() return type changed (#​862):

- pub fn peer_info(&self) -> Option<&R::PeerInfo>
+ pub fn peer_info(&self) -> Option<Arc<R::PeerInfo>>

This was needed so peer info can be re-set on a duplicate initialize (it now lives behind an RwLock), which is why a borrow can no longer be returned.

Migration: field access still works through Arc's Deref. If you need the old &InitializeResult (e.g. you bound the type explicitly), use .as_deref():

// Before (1.7.x): info is &InitializeResult
let info: Option<&InitializeResult> = client.peer_info();

// After (1.8.0): info is Arc<InitializeResult>
let info: Option<Arc<InitializeResult>> = client.peer_info();

// To recover the old reference type:
let info: Option<&InitializeResult> = client.peer_info().as_deref();
Added
  • standardize resource-not-found error code (SEP-2164) (#​899)
  • validate OAuth authorization response issuer (#​896)
  • specify OIDC application_type during dynamic client registration (SEP-837) (#​883)
  • deprecate roots, sampling, and logging (SEP-2577) (#​884)
Fixed
  • (auth) preserve configured reqwest client (#​917)
  • (auth) align OAuth metadata discovery ordering (#​887)
  • align progress timeout token (#​909)
  • (elicitation) preserve enumNames through ElicitationSchema serde round-trip (#​905)
  • return tool errors for invalid arguments (#​894)
  • (auth) apply offline_access to reauth paths (#​897)
  • update peer info on duplicate initialize (#​862) — ⚠️ breaking: changes the Peer::peer_info() signature, see Breaking Changes above
  • strip and validate tool outputSchema and inputSchema (#​860)
  • remove unnecessary fields from tools' inputSchema (#​856)
  • reject init header/body version mismatch (#​853)
  • align protocol version negotiation (#​855)
  • accept 200 with empty body in response to notifications in addition to 202 (#​849)
Other
  • Allow custom HTTP clients for OAuth (#​908)
  • Add progress-aware request timeout reset (#​858)
  • (server) document Err vs Ok(CallToolResult::error) visibility contract on ServerHandler::call_tool (#​854)
  • refine mcpmate listing copy (#​885)
  • added jilebi-mcp to the list of built with rmcp (#​861)

v1.7.0

Compare Source

Added
  • add task-based stdio examples (#​839)
Fixed
  • (rmcp) flatten Resource variant of PromptMessageContent (#​843)
  • reply -32700 on stdio parse errors instead of closing (#​833)
Other
  • (rmcp) remove dependency on chrono default features (#​829)
  • Fix/issue 817 idle timeout log level (#​824)

v1.6.0

Compare Source

Added
  • (http) log Host/Origin rejections (#​826)
  • (http) add Origin header validation (#​823)
  • (router) support runtime disabling of tools (#​809)
  • optional session store (resumabillity support) (#​775)
Fixed
  • add init_timeout for streamable-http sessions (#​811)
  • (http) fall back to :authority for HTTP/2 (#​827)
  • (docs) use correct Parameters syntax in tool examples (#​814)
Other
  • add systemprompt-template to Built with rmcp (#​820)

v1.5.0

Compare Source

Added
  • (transport) add constructors for non_exhaustive error types (#​806)
  • add 2025-11-25 protocol version support (#​802)
Fixed
  • treat resource metadata JSON parse failure as soft error (#​810)
  • include http_request_id in request-wise priming event IDs (#​799)
  • (http) drain SSE stream for connection reuse (#​790)
Other
  • (deps) update which requirement from 7 to 8 (#​807)

v1.4.0

Compare Source

Added
  • add Default and constructors to ServerSseMessage (#​794)
  • add meta to elicitation results (#​792)
  • (macros) auto-generate get_info and default router (#​785)
  • (transport) add which_command for cross-platform executable resolution (#​774)
  • (auth) add StoredCredentials::new() constructor (#​778)
Fixed
  • (server) remove initialized notification gate to support Streamable HTTP (#​788)
  • default session keep_alive to 5 minutes (#​780)
  • (http) add host check (#​764)
  • exclude local feature from docs.rs build (#​782)
Other
  • update Rust toolchain to 1.92 (#​797)
  • unify IntoCallToolResult Result impls (#​787)

v1.3.0

Compare Source

Added
  • (transport) add Unix domain socket client for streamable HTTP (#​749)
  • (auth) implement SEP-2207 OIDC-flavored refresh token guidance (#​676)
  • add configuration for transparent session re-init (#​760)
  • add local feature for !Send tool handler support (#​740)
Fixed
  • prevent CallToolResult and GetTaskPayloadResult from shadowing CustomResult in untagged enums (#​771)
  • drain in-flight responses on stdin EOF (#​759)
  • remove default type param from StreamableHttpService (#​758)
  • use cfg-gated Send+Sync supertraits to avoid semver break (#​757)
  • (rmcp) surface JSON-RPC error bodies on HTTP 4xx responses (#​748)
  • default CallToolResult content to empty vec on missing field (#​752)
  • (auth) redact secrets in Debug output for StoredCredentials and StoredAuthorizationState (#​744)
Other
  • fix all clippy warnings across workspace (#​746)

v1.2.0

Compare Source

Added
  • add missing constructors for non-exhaustive model types (#​739)
  • include granted scopes in OAuth refresh token request (#​731)
Fixed
  • handle ping requests sent before initialize handshake (#​745)
  • allow deserializing notifications without params field (#​729)
Other
  • (deps) update jsonwebtoken requirement from 9 to 10 (#​737)

v1.1.1

Compare Source

Fixed
  • accept logging/setLevel and ping before initialized notification (#​730)

v1.1.0

Compare Source

Added
  • implement OAuth 2.0 Client Credentials flow (#​707)
Other
  • add McpMux to Built with rmcp section (#​717)

v1.0.0

Compare Source

Fixed
  • (auth) pass WWW-Authenticate scopes to DCR registration request (#​705)
  • api ergonomics follow-up (#​720)
  • (streamable-http) map stale session 401 to status-aware error (#​709)
zip-rs/zip2 (zip)

v8.6.0

Compare Source

🚀 Features
  • add compression not supported as enum error (#​774)
🐛 Bug Fixes
  • allow for [u8] as filename (#​775)
🚜 Refactor
  • mark ZipFlags as non-exhaustive and add test for HasZipMetadata (#​777)
  • use and simplify is_dir (#​776)

v8.5.1

Compare Source

🚜 Refactor
  • change magic finder to stack buffer (#​763)
  • simplify extra field parsing (#​764)

v8.5.0

Compare Source

🐛 Bug Fixes
  • remove zip64 comment and add zip64 extensible data sector (#​747)
🚜 Refactor
  • remove useless magic in struct (#​730)
  • change extra_field from Arc<Vec> to Arc<[u8]> (#​741)
⚙️ Miscellaneous Tasks

v8.4.0

Compare Source

🚀 Features
  • add a check for building benches (#​748)
🚜 Refactor
  • split part of read.rs for code readability (#​744)
  • remove unused allow (#​745)
⚡ Performance
  • skip BufReader for Stored files in make_reader (#​739)
⚙️ Miscellaneous Tasks
  • move pull request template to correct folder (#​749)

v8.3.1

Compare Source

🚜 Refactor
  • use AexEncryption::new (#​736)
  • update tests to add big endian miri check (#​735)
⚙️ Miscellaneous Tasks
  • cleanup repository files (#​743)

v8.3.0

Compare Source

🚀 Features
  • add must_use (#​727)
  • improve and fix extended timestamp extra field parsing (#​713)
  • add crc32 ignore option (#​710)
  • path related code in single file (#​712)
🐛 Bug Fixes
🚜 Refactor
  • refactor some imports (#​734)
  • move code to distinct file (datetime, FixedSizeBlock) (#​733)
  • move stream code to src/read/stream.rs (#​731)
  • remove zip64 extra field update (#​732)
  • improve part of the code with clippy help (#​725)
  • simplify code for unicode extra field and improve error message (#​724)
  • reorganize code (#​714)
Deps
  • avoid pulling in zeroize_derive (#​720)

v8.2.0

Compare Source

🚀 Features
  • allow custom salt (#​680)
  • Support compressing bzip2 when feature bzip2-rs is enabled, since bzip2/bzip2-sys now supports it (#​685)
  • enforce clippy in CI (#​674)
🐛 Bug Fixes
  • zip64 central header (issue 617) (#​629)
  • allow aes password as bytes (#​686)
  • handle extra field padding (#​682)
🚜 Refactor
  • Simplify 2 type conversions in src/write.rs (#​687)
⚡ Performance
  • AI tweaks for string type conversions in src/types.rs (#​670)

v8.1.0

Compare Source

🚀 Features
  • (writer) Allow getting underlying writer of ZipWriter (#​464)
  • add system to FileOption, so byte-for-byte identical archives can be created across platforms (#​660)
🐛 Bug Fixes
  • Bugs in extra-data length calculation in src/write.rs (#​662)

v8.0.0

Compare Source

🚀 Features
  • document zip flags as enum (#​639)
  • Migrate to Rust 2024 (#​650)
  • [breaking] Remove deprecated methods of DateTime (#​597)

v7.4.0

Compare Source

🚀 Features
  • Increase MSRV to 1.88 and update dependencies (#​626)

v7.3.0

Compare Source

🚀 Features
  • cleanup the benchmarks and Cargo.toml (#​606)
  • Add support for per-file comments (#​543)
🐛 Bug Fixes
  • Document feature unreserved and make the mapping of extra fields public (#​616)
  • Return an error if abort_file() fails when exceeding non-large-file limit (#​598)
⚙️ Miscellaneous Tasks
  • Bump version to 7.3.0 (semver checks fail if it's still 7.3.0-pre1)

v7.2.0

Compare Source

🚀 Features
  • add read_zipfile_from_stream_with_compressed_size (#​70)
  • Allow choosing bzip2 rust backend (#​329)
🐛 Bug Fixes
  • Need to include zip64 extra field in central directory (fix #​353) (#​360)
  • Fails to extract file which might or might not be malformed (#​376) (#​426)
  • (aes) Allow AES encryption while streaming (#​463)
  • Default "platform" field in zip files should be set to the local platform, rather than always "Unix" (#​470) (#​471)
🚜 Refactor
  • Define cfg_if! and cfg_if_expr! internal macros (#​438)
⚡ Performance
  • Change an assert to debug_assert when encrypting/decrypting AES, and eliminate a fallible operation (#​521)
  • eliminate a String clone per new file added to archive, and other related refactors (#​522)

v7.1.0

Compare Source

🚀 Features
  • display the underlying error in Display impl for ZipError (#​483)
  • Enable creation of ZipArchive without reparsing (

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/major-rust-dependencies branch 2 times, most recently from f9efe9f to c3b242e Compare September 22, 2026 18:54
@renovate
renovate Bot force-pushed the renovate/major-rust-dependencies branch from c3b242e to b96439f Compare September 25, 2026 00:21
@renovate

renovate Bot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: packages/player/src-tauri/Cargo.toml
Artifact update for rmcp resolved to version 3.4.1, which is a pending version that has not yet passed the Minimum Release Age threshold.
Renovate was attempting to update to 3.4.0
This is (likely) not a bug in Renovate, but due to the way your project pins dependencies, _and_ how Renovate calls your package manager to update them.
Until Renovate supports specifying an exact update to your package manager (https://github.com/renovatebot/renovate/issues/41624), it is recommended to directly pin your dependencies (with `rangeStrategy=pin` for apps, or `rangeStrategy=widen` for libraries)
See also: https://docs.renovatebot.com/dependency-pinning/

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants