chore(deps): Update dependency fastmcp to 3.4.2#301
Open
robander wants to merge 1 commit into
Open
Conversation
gebhardtr
approved these changes
Jun 4, 2026
dustin-sale
requested changes
Jun 5, 2026
dustin-sale
left a comment
Contributor
There was a problem hiding this comment.
Can you kindly update the CHANGELOG.md files? This is a notable Security update. I dont think my PR for adding changelog guidence has been merged yet but you may refer to that.
Member
Author
|
@dustin-sale Updated to add changelog entries |
dustin-sale
approved these changes
Jun 5, 2026
gebhardtr
reviewed
Jun 10, 2026
gebhardtr
left a comment
Member
There was a problem hiding this comment.
Can we just bump the fastmcp version now instead?
4d1a15a to
bff0996
Compare
gebhardtr
approved these changes
Jun 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Package bump fastmcp to pick up latest version of the starlette dependency. This is a recreation of #292 after a rebase to fix conflicts.
This PR was originally submitted to update starlette, but revised to get the latest fastmcp which now updates starlette.
Fixes GHSA-86qp-5c8j-p5mr
This dependency is used by FastAPI, but there is not a version of FastAPI that pins starlette. It looks like they will not be forcing an update, based on a comment here: https://github.com/fastapi/fastapi/discussions/15593and#discussioncomment-17065958
Type of change
Please delete options that are not relevant.
How Has This Been Tested?
Please describe the tests that you ran to verify your changes. Provide instructions so we can reproduce. Please also list any relevant details for your test configuration
Test Configuration:
Checklist: