Skip to content
Open
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ dependencies = [
"requests>=2.28.0",
"pydantic>=2.5.1,<2.12.0",
"mcp>=1.8.0",
"fastmcp==2.13.0",
"fastmcp>=2.14.5,<3.0.0",
Comment on lines 27 to +29

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | 🏗️ Heavy lift

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Confirm pydantic version currently resolved in uv.lock and check for fastmcp's declared pydantic lower bound
rg -n "pydantic" uv.lock | head -40

Repository: pathintegral-institute/mcpm.sh

Length of output: 9738


🏁 Script executed:

#!/bin/bash
# Read the current pyproject.toml to see the actual dependency constraints
cat pyproject.toml

Repository: pathintegral-institute/mcpm.sh

Length of output: 1611


🏁 Script executed:

#!/bin/bash
# Search for mcp in uv.lock to see what version is resolved
rg -n "^name = \"mcp\"" uv.lock -A 5

Repository: pathintegral-institute/mcpm.sh

Length of output: 245


🌐 Web query:

fastmcp 2.14.5 pyproject.toml dependencies pydantic mcp

💡 Result:

FastMCP 2.14.5 is a Python framework for building MCP (Model Context Protocol) servers and clients. Its pyproject.toml dependencies, consistent across v2.14.x releases (e.g., v2.14.2 listed explicitly), include pydantic[email] >=2.11.7 [1][2] and mcp <2.0,>=1.24.0 [1][2]. Full core dependencies from the series: authlib>=1.6.5, cyclopts>=4.0.0, exceptiongroup>=1.2.2, httpx>=0.28.1, jsonschema-path>=0.3.4, mcp<2.0,>=1.24.0, openapi-pydantic>=0.5.1, platformdirs>=4.0.0, py-key-value-aio[disk,keyring,memory]<0.4.0,>=0.3.0 (updated in later 2.14.x), pydantic[email]>=2.11.7, pydocket>=0.16.3 (updated from 0.15.5 in 2.14.1), pyperclip>=1.9.0, python-dotenv>=1.1.0, rich>=13.9.4, uvicorn>=0.35, websockets>=15.0.1 [1][3][4]. No exact pyproject.toml for precisely 2.14.5 found, but changes between minor versions are minor (e.g., pydocket bump) [5][6][4], and main branch matches [2]. Projects using fastmcp==2.14.5 pin pydantic>=2.12.5,<3.0 and mcp[cli]>=1.26.0,<2.0 [7][8].

Citations:


Pydantic <2.12.0 creates an unsustainably narrow resolution window with fastmcp>=2.14.5

fastmcp 2.14.5 declares pydantic[email]>=2.11.7 as a requirement. Combined with mcpm's explicit cap pydantic>=2.5.1,<2.12.0, the valid pydantic range narrows to 2.11.7–2.11.x only (currently resolved to 2.11.7). Any future fastmcp 2.x release that bumps its pydantic floor to >=2.12.0 will make the dependency graph unsatisfiable.

The <2.12.0 cap was added to protect against the pydantic 2.12 breaking change that affected older fastmcp (<2.12.4). Since this PR already requires fastmcp>=2.14.5 (which is compatible with pydantic 2.12+), the cap is now unnecessarily constraining. Consider loosening it to match fastmcp's actual requirements:

🔧 Suggested fix
-    "pydantic>=2.5.1,<2.12.0",
+    "pydantic>=2.11.7",
     "mcp>=1.8.0",
     "fastmcp>=2.14.5,<3.0.0",

Or, if mcpm code relies on pre-2.11 pydantic APIs, drop just the cap:

-    "pydantic>=2.5.1,<2.12.0",
+    "pydantic>=2.5.1",

Verify resolution with uv lock --upgrade-package pydantic.

Minor note: mcpm's mcp>=1.8.0 has no upper bound, but fastmcp transitively enforces mcp<2.0,>=1.24.0 (currently resolved to 1.25.0). The loose lower bound in mcpm is misleading; consider tightening it to match fastmcp's actual minimum.

📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
"pydantic>=2.5.1,<2.12.0",
"mcp>=1.8.0",
"fastmcp==2.13.0",
"fastmcp>=2.14.5,<3.0.0",
"pydantic>=2.11.7",
"mcp>=1.8.0",
"fastmcp>=2.14.5,<3.0.0",
Suggested change
"pydantic>=2.5.1,<2.12.0",
"mcp>=1.8.0",
"fastmcp==2.13.0",
"fastmcp>=2.14.5,<3.0.0",
"pydantic>=2.5.1",
"mcp>=1.8.0",
"fastmcp>=2.14.5,<3.0.0",
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@pyproject.toml` around lines 27 - 29, The pydantic version cap
("pydantic>=2.5.1,<2.12.0") in pyproject.toml unnecessarily narrows resolution
with fastmcp>=2.14.5; update the pydantic constraint to remove the <2.12.0 upper
bound (e.g., "pydantic>=2.5.1" or "pydantic>=2.11.7") so it is compatible with
fastmcp's pydantic requirement, and optionally tighten the mcp constraint from
"mcp>=1.8.0" to match fastmcp's transitive requirement (e.g.,
"mcp>=1.24.0,<2.0") to avoid misleadingly loose bounds.

"ruamel-yaml>=0.18.10",
"watchfiles>=1.0.4",
"duckdb>=1.2.2",
Expand Down
Loading
Loading