Update dependency fastmcp to v3.4.7 - #14622
Open
renovate-bot wants to merge 1 commit into
Open
renovate-bot wants to merge 1 commit into
renovate-bot wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==3.4.3→==3.4.7Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
PrefectHQ/fastmcp (fastmcp)
v3.4.7: : Know Your AudienceCompare Source
FastMCP 3.4.7 restores CIMD
private_key_jwtauthentication for OAuthProxy deployments at a bare origin. Client assertions are now validated against the exact token endpoint advertised in authorization server metadata, eliminating the doubled-slash audience mismatch.What's Changed
Security 🔒
Docs 📚
Full Changelog: PrefectHQ/fastmcp@v3.4.6...v3.4.7
v3.4.6: : Trust, but ProxyCompare Source
FastMCP 3.4.6 backports trusted-proxy support for SSRF-protected OAuth metadata and JWKS fetches. Deployments can now route these requests through a mandated corporate proxy while preserving custom CA certificates; FastMCP refuses the fetch when no proxy is configured instead of risking an unprotected direct request.
What's Changed
Fixes 🐞
Docs 📚
Full Changelog: PrefectHQ/fastmcp@v3.4.5...v3.4.6
v3.4.5: : Key ChangeCompare Source
FastMCP 3.4.5 collects five fixes for the 3.x line. The one that prompted it: a single
Ed25519key in a JWKS — which Rauthy, Ory Hydra, and some Keycloak configurations publish by default — madeJWTVerifierreject every token, including ones correctly signed by supported keys in the same set.What's Changed
Fixes 🐞
Docs 📚
New Contributors
Full Changelog: PrefectHQ/fastmcp@v3.4.4...v3.4.5
v3.4.4: : Host in TranslationCompare Source
FastMCP 3.4.4 restores HTTP deployment compatibility after the 3.4.3 Host/Origin guard changed default behavior for existing ASGI, serverless, and reverse-proxy deployments. The guard implementation remains available for deployments that opt in with explicit trusted hosts and origins, while 3.x returns to accepting traffic that worked before the patch. This release also adds Hugging Face OAuth provider support, with docs and examples for public and private apps, PKCE, Dynamic Client Registration, and CIMD.
What's Changed
Enhancements ✨
Fixes 🐞
Docs 📚
New Contributors
Full Changelog: PrefectHQ/fastmcp@v3.4.3...v3.4.4
Configuration
📅 Schedule: (UTC)
* * 1 */3 *)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Never, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.