Skip to content

Bump mcp from 1.4.0 to 1.5.0 - #116

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/mcp-1.5.0
Open

Bump mcp from 1.4.0 to 1.5.0#116
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bundler/mcp-1.5.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown
Contributor

Bumps mcp from 1.4.0 to 1.5.0.

Release notes

Sourced from mcp's releases.

v1.5.0

This release makes the client answer a server's ping with the empty result the specification requires. Earlier clients replied with Method not found over Streamable HTTP and stayed silent over stdio, so a server that checks liveness dropped their long-lived sessions. On the OAuth side, the embedding application can refuse an authorization request through authorization_request_validator, and stored tokens are refreshed only against the authorization server that issued them: when the server named for a session differs, the client reauthorizes instead of refreshing, and the validator sees the newly named server. Tokens stored by earlier releases carry no issuer and keep refreshing.

Added

  • Add authorization_request_validator to let the embedding application refuse an authorization request (#539)

Fixed

  • Answer server-to-client pings in the client (#541)
Changelog

Sourced from mcp's changelog.

[1.5.0] - 2026-09-05

This release makes the client answer a server's ping with the empty result the specification requires. Earlier clients replied with Method not found over Streamable HTTP and stayed silent over stdio, so a server that checks liveness dropped their long-lived sessions. On the OAuth side, the embedding application can refuse an authorization request through authorization_request_validator, and stored tokens are refreshed only against the authorization server that issued them: when the server named for a session differs, the client reauthorizes instead of refreshing, and the validator sees the newly named server. Tokens stored by earlier releases carry no issuer and keep refreshing.

Added

  • Add authorization_request_validator to let the embedding application refuse an authorization request (#539)

Fixed

  • Answer server-to-client pings in the client (#541)
Commits
  • 8a24e50 Merge pull request #543 from koic/release_1_5_0
  • 33525d6 Release 1.5.0
  • f706cc8 Merge pull request #542 from koic/fix_flaky_listen_keepalive_thread_assertion
  • 6d272df Merge pull request #541 from koic/respond_to_server_pings_in_the_client
  • eeab784 Merge pull request #539 from koic/add_authorization_request_validator
  • 09c3103 Fix the flaky thread count assertion in the listen keepalive test
  • 088f4b9 Answer server-to-client pings in the client
  • 6b1704f Merge pull request #540 from koic/mark_deprecated_features_on_the_server_over...
  • 6f0b854 [Doc] Mark the deprecated features on the server overview
  • 09d4bf4 Let the embedding application refuse an authorization request
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [mcp](https://github.com/modelcontextprotocol/ruby-sdk) from 1.4.0 to 1.5.0.
- [Release notes](https://github.com/modelcontextprotocol/ruby-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/ruby-sdk/blob/main/CHANGELOG.md)
- [Commits](modelcontextprotocol/ruby-sdk@v1.4.0...v1.5.0)

---
updated-dependencies:
- dependency-name: mcp
  dependency-version: 1.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Sep 9, 2026
@dependabot
dependabot Bot requested a review from leowilkin as a code owner September 9, 2026 00:25
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Sep 9, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedmcp@​1.4.0 ⏵ 1.5.0100 +1100100 +1100100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants