Skip to content

build(deps): bump mcp from 1.1.0 to 1.2.0 in /docs - #515

Merged
cirdes merged 1 commit into
mainfrom
dependabot/bundler/docs/mcp-1.2.0
Aug 24, 2026
Merged

build(deps): bump mcp from 1.1.0 to 1.2.0 in /docs#515
cirdes merged 1 commit into
mainfrom
dependabot/bundler/docs/mcp-1.2.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 23, 2026

Copy link
Copy Markdown
Contributor

Bumps mcp from 1.1.0 to 1.2.0.

Release notes

Sourced from mcp's releases.

v1.2.0

This release completes the SEP-2575 stateless lifecycle of the 2026-07-28 specification, together with the SEP-2322, SEP-2549, and SEP-2243 features that revision builds on. Several entries under "Changed" are incompatible with 1.1.0 and ship in a minor release under the spec-conformance and security exceptions described in https://github.com/modelcontextprotocol/ruby-sdk/blob/HEAD/VERSIONING.md.

Added

  • Handle the SEP-2575 modern request envelope in the server core (#475)
  • Serve both lifecycle eras over stdio with an era lock per SEP-2575 (#478)
  • Serve the sessionless modern path over Streamable HTTP per SEP-2575 (#479)
  • Finalize server/discover and add client modern lifecycle support per SEP-2575 (#480)
  • Let handlers return multi round-trip input_required results per SEP-2322 (#481)
  • Add MCP::Elicitation::EnumSchema builders per SEP-1330 (#482)
  • Stamp the required resultType on modern results per SEP-2322 (#487)
  • Enforce the modern lifecycle admission rules per SEP-2575 (#489)
  • Stream modern request notifications and honor the envelope logLevel per SEP-2575 (#490)
  • Expose the user-defined server_context in instrumentation data (#493)
  • Serve the subscriptions/listen notification stream per SEP-2575 (#495)
  • Add opt-in requestState sealing via MCP::Server::RequestStateSecurity (#496)
  • Mirror x-mcp-header tool parameters into Mcp-Param-* headers per SEP-2243 (#498)
  • Stamp the required cache hints on modern cacheable results per SEP-2549 (#499)
  • Drive multi round-trip input_required results on the client per SEP-2322 (#500)
  • Fulfill input_required results on the legacy wire per SEP-2322 (#501)

Changed

  • Align modern envelope validation with the finalized specification (#491)
  • Require the Mcp-Method header on the modern path (#492)
  • Bound server-to-client requests with a timeout (#502)
  • Refuse server-to-client requests in the modern lifecycle per SEP-2575 (#503)
  • Bound the total wait across SSE reconnection attempts (#504)
  • Bound automatic pagination in the MCP client (#505)
  • Reject modern-removed methods before the connection era locks (#511)
  • Stop negotiating modern protocol versions through the initialize handshake (#516)

Deprecated

  • Warn on modern client connects that declare the Roots or Sampling capabilities deprecated per SEP-2577 (#406, #516)

Fixed

  • Stop leaking exception messages to clients via JSON-RPC error data (#486)
  • Return Invalid Params for unknown prompts and missing prompt arguments (#517)
  • Restrict OAuth discovery to same-origin metadata URLs and refuse private-network destinations
Changelog

Sourced from mcp's changelog.

[1.2.0] - 2026-08-15

This release completes the SEP-2575 stateless lifecycle of the 2026-07-28 specification, together with the SEP-2322, SEP-2549, and SEP-2243 features that revision builds on. Several entries under "Changed" are incompatible with 1.1.0 and ship in a minor release under the spec-conformance and security exceptions described in https://github.com/modelcontextprotocol/ruby-sdk/blob/main/VERSIONING.md.

Added

  • Handle the SEP-2575 modern request envelope in the server core (#475)
  • Serve both lifecycle eras over stdio with an era lock per SEP-2575 (#478)
  • Serve the sessionless modern path over Streamable HTTP per SEP-2575 (#479)
  • Finalize server/discover and add client modern lifecycle support per SEP-2575 (#480)
  • Let handlers return multi round-trip input_required results per SEP-2322 (#481)
  • Add MCP::Elicitation::EnumSchema builders per SEP-1330 (#482)
  • Stamp the required resultType on modern results per SEP-2322 (#487)
  • Enforce the modern lifecycle admission rules per SEP-2575 (#489)
  • Stream modern request notifications and honor the envelope logLevel per SEP-2575 (#490)
  • Expose the user-defined server_context in instrumentation data (#493)
  • Serve the subscriptions/listen notification stream per SEP-2575 (#495)
  • Add opt-in requestState sealing via MCP::Server::RequestStateSecurity (#496)
  • Mirror x-mcp-header tool parameters into Mcp-Param-* headers per SEP-2243 (#498)
  • Stamp the required cache hints on modern cacheable results per SEP-2549 (#499)
  • Drive multi round-trip input_required results on the client per SEP-2322 (#500)
  • Fulfill input_required results on the legacy wire per SEP-2322 (#501)

Changed

  • Align modern envelope validation with the finalized specification (#491)
  • Require the Mcp-Method header on the modern path (#492)
  • Bound server-to-client requests with a timeout (#502)
  • Refuse server-to-client requests in the modern lifecycle per SEP-2575 (#503)
  • Bound the total wait across SSE reconnection attempts (#504)
  • Bound automatic pagination in the MCP client (#505)
  • Reject modern-removed methods before the connection era locks (#511)
  • Stop negotiating modern protocol versions through the initialize handshake (#516)

Deprecated

  • Warn on modern client connects that declare the Roots or Sampling capabilities deprecated per SEP-2577 (#406, #516)

Fixed

  • Stop leaking exception messages to clients via JSON-RPC error data (#486)
  • Return Invalid Params for unknown prompts and missing prompt arguments (#517)
  • Restrict OAuth discovery to same-origin metadata URLs and refuse private-network destinations
Commits
  • 8cac727 Merge pull request #518 from koic/release_1_2_0
  • af02717 Release 1.2.0
  • a62e56e Merge pull request #516 from koic/counter_offer_legacy_version_on_initialize
  • 84eac10 Merge commit from fork
  • c4921ed Merge pull request #517 from latent-9/prompts-get-invalid-params
  • ddec72f Merge pull request #514 from koic/http_standard_headers_driver
  • feba4d4 Return Invalid Params for unknown prompts and missing prompt arguments
  • ab17d50 Merge pull request #515 from koic/add_list_changed_notification_examples
  • 48b7aaa Stop negotiating modern protocol versions through the initialize handshake
  • 67779a2 Merge pull request #505 from koic/bound_client_automatic_pagination
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Summary by cubic

Bumps mcp in docs from 1.1.0 to 1.2.0 to align with the 2026 MCP spec and pick up security fixes. The new version enforces the stateless modern lifecycle (stricter headers, era locking, timeouts) versus the more permissive 1.1.0 behavior; this may affect doc examples that run clients/servers.

  • Only docs/Gemfile.lock changes; build the docs and run any MCP examples.
  • Ensure modern requests in examples include the Mcp-Method header and use the modern request envelope.
  • Do not rely on server-to-client requests on the modern path; update examples accordingly.
  • Expect stricter validation and new timeouts; address any Invalid Params errors in prompt examples.
  • Watch for deprecation warnings (Roots/Sampling) and adjust examples if present.

Written for commit 141e150. Summary will update on new commits.

Review in cubic

Bumps [mcp](https://github.com/modelcontextprotocol/ruby-sdk) from 1.1.0 to 1.2.0.
- [Release notes](https://github.com/modelcontextprotocol/ruby-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/ruby-sdk/blob/main/CHANGELOG.md)
- [Commits](modelcontextprotocol/ruby-sdk@v1.1.0...v1.2.0)

---
updated-dependencies:
- dependency-name: mcp
  dependency-version: 1.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Aug 23, 2026
@dependabot
dependabot Bot requested a review from cirdes as a code owner August 23, 2026 10:03
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Aug 23, 2026
@cirdes
cirdes merged commit 13a2fe9 into main Aug 24, 2026
7 checks passed
@cirdes
cirdes deleted the dependabot/bundler/docs/mcp-1.2.0 branch August 24, 2026 12:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant