Skip to content

chore(deps-dev): bump mcp from 1.5.1 to 1.6.0 in the bundler-dependencies group - #288

Merged
dustinbyrne merged 2 commits into
mainfrom
dependabot/bundler/bundler-dependencies-5a7c162515
Sep 30, 2026
Merged

dustinbyrne merged 2 commits into
mainfrom
dependabot/bundler/bundler-dependencies-5a7c162515

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps the bundler-dependencies group with 1 update: mcp.

Updates mcp from 1.5.1 to 1.6.0

Release notes

Sourced from mcp's releases.

v1.6.0

This release lets an application configure, on the OAuth provider, the requests the flow makes to the authorization server: token_request_params: adds the parameters a server requires beyond the grant itself, and http_client_customizer: adds middleware to the connection the flow uses for discovery, registration, and token requests, behind a guard that refuses a request leaving the origin the flow asked for. The legacy 2025-03-26 discovery path is now taken only when the server publishes no Protected Resource Metadata: a fetch that failed to reach the server, or that answered 5xx or 429, raises Flow::MetadataUnreachableError instead, and the metadata served on that path must name the MCP server's origin as its issuer. The client_credentials and jwt-bearer grants run on that path, and a stored refresh token no longer crashes their providers. MCP::Icon.new now refuses an icon the specification's schema rejects, such as one without src or with sizes given as a String. Three entries under "Changed" reject what earlier releases accepted and ship in a minor release under the exceptions described in https://github.com/modelcontextprotocol/ruby-sdk/blob/HEAD/VERSIONING.md.

Added

  • Add token_request_params: to let a provider add parameters to the token requests it makes (#555)
  • Add http_client_customizer: to let a provider customize the HTTP client the OAuth flow uses (#560)

Changed

  • Validate the issuer of legacy authorization server metadata (#556)
  • Surface unreachable Protected Resource Metadata instead of falling back to legacy discovery (#561)
  • Validate the src and sizes of an icon against the specification (#563)

Fixed

  • Omit the body client_id from token requests that authenticate with HTTP Basic (#548)
  • Preserve the token endpoint's error and error_description in the raised error (#549)
  • Let the client_credentials and jwt-bearer grants run without Protected Resource Metadata (#557)
  • Let providers without a CIMD URL reader refresh their tokens (#559)
Changelog

Sourced from mcp's changelog.

[1.6.0] - 2026-09-21

This release lets an application configure, on the OAuth provider, the requests the flow makes to the authorization server: token_request_params: adds the parameters a server requires beyond the grant itself, and http_client_customizer: adds middleware to the connection the flow uses for discovery, registration, and token requests, behind a guard that refuses a request leaving the origin the flow asked for. The legacy 2025-03-26 discovery path is now taken only when the server publishes no Protected Resource Metadata: a fetch that failed to reach the server, or that answered 5xx or 429, raises Flow::MetadataUnreachableError instead, and the metadata served on that path must name the MCP server's origin as its issuer. The client_credentials and jwt-bearer grants run on that path, and a stored refresh token no longer crashes their providers. MCP::Icon.new now refuses an icon the specification's schema rejects, such as one without src or with sizes given as a String. Three entries under "Changed" reject what earlier releases accepted and ship in a minor release under the exceptions described in https://github.com/modelcontextprotocol/ruby-sdk/blob/main/VERSIONING.md.

Added

  • Add token_request_params: to let a provider add parameters to the token requests it makes (#555)
  • Add http_client_customizer: to let a provider customize the HTTP client the OAuth flow uses (#560)

Changed

  • Validate the issuer of legacy authorization server metadata (#556)
  • Surface unreachable Protected Resource Metadata instead of falling back to legacy discovery (#561)
  • Validate the src and sizes of an icon against the specification (#563)

Fixed

  • Omit the body client_id from token requests that authenticate with HTTP Basic (#548)
  • Preserve the token endpoint's error and error_description in the raised error (#549)
  • Let the client_credentials and jwt-bearer grants run without Protected Resource Metadata (#557)
  • Let providers without a CIMD URL reader refresh their tokens (#559)
Commits
  • 339f0a6 Merge pull request #565 from koic/release_1_6_0
  • ba25682 Release 1.6.0
  • 5ce47b6 Merge pull request #564 from koic/describe_connect_as_lifecycle_negotiation
  • 7b73bc7 [Doc] Describe connect across both protocol lifecycles
  • 538a364 Merge pull request #563 from koic/validate_icon_src_and_sizes
  • 66b2efa Merge pull request #561 from koic/propagate_network_errors_from_protected_res...
  • 8173a38 Validate the src and sizes of an icon against the specification
  • 5f429f3 Merge pull request #560 from koic/let_a_provider_customize_the_oauth_http_client
  • e1105c7 Merge pull request #559 from koic/let_providers_without_a_cimd_url_refresh
  • 5081cc5 Surface unreachable Protected Resource Metadata instead of falling back to le...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the bundler-dependencies group with 1 update: [mcp](https://github.com/modelcontextprotocol/ruby-sdk).


Updates `mcp` from 1.5.1 to 1.6.0
- [Release notes](https://github.com/modelcontextprotocol/ruby-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/ruby-sdk/blob/main/CHANGELOG.md)
- [Commits](modelcontextprotocol/ruby-sdk@v1.5.1...v1.6.0)

---
updated-dependencies:
- dependency-name: mcp
  dependency-version: 1.6.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bundler-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Sep 30, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 30, 2026 18:23
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Sep 30, 2026
@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

posthog-ruby-sync Compliance Report

Date: 2026-09-30T23:13:29.755625+00:00
Duration: 94228ms

⚠️ Some Tests Failed

45/47 tests passed, 2 failed


Capture Tests

⚠️ 29/30 tests passed, 1 failed

View Details
Test Status Duration
Format Validation.Event Has Required Fields ✅ 10ms
Format Validation.Event Has Uuid ✅ 6ms
Format Validation.Event Has Lib Properties ✅ 6ms
Format Validation.Distinct Id Is String ✅ 12ms
Format Validation.Token Is Present ✅ 9ms
Format Validation.Custom Properties Preserved ✅ 7ms
Format Validation.Event Has Timestamp ✅ 8ms
Format Validation.Non Utc Event Timestamp Is Converted To Utc ✅ 8ms
Retry Behavior.Retries On 503 ✅ 5322ms
Retry Behavior.Does Not Retry On 400 ✅ 2010ms
Retry Behavior.Does Not Retry On 401 ✅ 2012ms
Retry Behavior.Respects Retry After Header ✅ 8016ms
Retry Behavior.Implements Backoff ✅ 15356ms
Retry Behavior.Retries On 500 ✅ 5115ms
Retry Behavior.Retries On 502 ✅ 5147ms
Retry Behavior.Retries On 504 ✅ 5165ms
Retry Behavior.Max Retries Respected ✅ 15470ms
Deduplication.Generates Unique Uuids ✅ 22ms
Deduplication.Preserves Uuid On Retry ✅ 5114ms
Deduplication.Preserves Uuid And Timestamp On Retry ✅ 10348ms
Deduplication.Preserves Uuid And Timestamp On Batch Retry ✅ 5148ms
Deduplication.No Duplicate Events In Batch ✅ 18ms
Deduplication.Different Events Have Different Uuids ✅ 8ms
Compression.Sends Gzip When Enabled ✅ 6ms
Batch Format.Uses Proper Batch Structure ✅ 8ms
Batch Format.Flush With No Events Sends Nothing ✅ 3ms
Batch Format.Multiple Events Batched Together ❌ 17ms
Error Handling.Does Not Retry On 403 ✅ 2009ms
Error Handling.Does Not Retry On 413 ✅ 2008ms
Error Handling.Retries On 408 ✅ 5158ms

Failures

batch_format.multiple_events_batched_together

Expected 1 requests, got 5

Feature_Flags Tests

⚠️ 16/17 tests passed, 1 failed

View Details
Test Status Duration
Request Payload.Request With Person Properties Device Id ✅ 9ms
Request Payload.Flags Request Uses V2 Query Param ✅ 8ms
Request Payload.Flags Request Hits Flags Path Not Decide ✅ 9ms
Request Payload.Flags Request Omits Authorization Header ✅ 8ms
Request Payload.Token In Flags Body Matches Init ✅ 7ms
Request Payload.Groups Round Trip ✅ 7ms
Request Payload.Groups Default To Empty Object ✅ 6ms
Request Payload.Disable Geoip False Propagates As Geoip Disable False ✅ 7ms
Request Payload.Disable Geoip Omitted Defaults To False ❌ 7ms
Request Payload.Flag Keys To Evaluate Contains Only Requested Key ✅ 6ms
Request Lifecycle.No Flags Request On Init Alone ✅ 3ms
Request Lifecycle.No Flags Request On Normal Capture ✅ 5ms
Request Lifecycle.Two Flag Calls Produce Two Remote Requests ✅ 10ms
Request Lifecycle.Mock Response Value Is Returned To Caller ✅ 7ms
Retry Behavior.Retries Flags On 502 ✅ 146ms
Retry Behavior.Retries Flags On 504 ✅ 109ms
Side Effect Events.Get Feature Flag Captures Feature Flag Called Event ✅ 8ms

Failures

request_payload.disable_geoip_omitted_defaults_to_false

Field 'geoip_disable' not found in /flags request body at path 'geoip_disable'. Available keys: ['distinct_id', 'groups', 'person_properties', 'group_properties', 'flag_keys_to_evaluate', 'token']

@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

posthog-ruby-async Compliance Report

Date: 2026-09-30T23:13:33.691494+00:00
Duration: 98002ms

⚠️ Some Tests Failed

46/47 tests passed, 1 failed


Capture Tests

✅ 30/30 tests passed

View Details
Test Status Duration
Format Validation.Event Has Required Fields ✅ 9ms
Format Validation.Event Has Uuid ✅ 106ms
Format Validation.Event Has Lib Properties ✅ 109ms
Format Validation.Distinct Id Is String ✅ 106ms
Format Validation.Token Is Present ✅ 107ms
Format Validation.Custom Properties Preserved ✅ 107ms
Format Validation.Event Has Timestamp ✅ 107ms
Format Validation.Non Utc Event Timestamp Is Converted To Utc ✅ 10ms
Retry Behavior.Retries On 503 ✅ 5310ms
Retry Behavior.Does Not Retry On 400 ✅ 2108ms
Retry Behavior.Does Not Retry On 401 ✅ 2108ms
Retry Behavior.Respects Retry After Header ✅ 8016ms
Retry Behavior.Implements Backoff ✅ 15513ms
Retry Behavior.Retries On 500 ✅ 5211ms
Retry Behavior.Retries On 502 ✅ 5213ms
Retry Behavior.Retries On 504 ✅ 5212ms
Retry Behavior.Max Retries Respected ✅ 15522ms
Deduplication.Generates Unique Uuids ✅ 111ms
Deduplication.Preserves Uuid On Retry ✅ 5211ms
Deduplication.Preserves Uuid And Timestamp On Retry ✅ 10418ms
Deduplication.Preserves Uuid And Timestamp On Batch Retry ✅ 5214ms
Deduplication.No Duplicate Events In Batch ✅ 113ms
Deduplication.Different Events Have Different Uuids ✅ 108ms
Compression.Sends Gzip When Enabled ✅ 107ms
Batch Format.Uses Proper Batch Structure ✅ 106ms
Batch Format.Flush With No Events Sends Nothing ✅ 5ms
Batch Format.Multiple Events Batched Together ✅ 110ms
Error Handling.Does Not Retry On 403 ✅ 2108ms
Error Handling.Does Not Retry On 413 ✅ 2109ms
Error Handling.Retries On 408 ✅ 5209ms

Feature_Flags Tests

⚠️ 16/17 tests passed, 1 failed

View Details
Test Status Duration
Request Payload.Request With Person Properties Device Id ✅ 107ms
Request Payload.Flags Request Uses V2 Query Param ✅ 107ms
Request Payload.Flags Request Hits Flags Path Not Decide ✅ 108ms
Request Payload.Flags Request Omits Authorization Header ✅ 107ms
Request Payload.Token In Flags Body Matches Init ✅ 107ms
Request Payload.Groups Round Trip ✅ 107ms
Request Payload.Groups Default To Empty Object ✅ 106ms
Request Payload.Disable Geoip False Propagates As Geoip Disable False ✅ 107ms
Request Payload.Disable Geoip Omitted Defaults To False ❌ 107ms
Request Payload.Flag Keys To Evaluate Contains Only Requested Key ✅ 107ms
Request Lifecycle.No Flags Request On Init Alone ✅ 3ms
Request Lifecycle.No Flags Request On Normal Capture ✅ 106ms
Request Lifecycle.Two Flag Calls Produce Two Remote Requests ✅ 112ms
Request Lifecycle.Mock Response Value Is Returned To Caller ✅ 107ms
Retry Behavior.Retries Flags On 502 ✅ 211ms
Retry Behavior.Retries Flags On 504 ✅ 209ms
Side Effect Events.Get Feature Flag Captures Feature Flag Called Event ✅ 109ms

Failures

request_payload.disable_geoip_omitted_defaults_to_false

Field 'geoip_disable' not found in /flags request body at path 'geoip_disable'. Available keys: ['distinct_id', 'groups', 'person_properties', 'group_properties', 'flag_keys_to_evaluate', 'token']

dustinbyrne
dustinbyrne previously approved these changes Sep 30, 2026
@dustinbyrne
dustinbyrne self-requested a review September 30, 2026 23:11
@dustinbyrne
dustinbyrne enabled auto-merge (squash) September 30, 2026 23:12
@dustinbyrne
dustinbyrne merged commit eeefb1d into main Sep 30, 2026
23 checks passed
@dustinbyrne
dustinbyrne deleted the dependabot/bundler/bundler-dependencies-5a7c162515 branch September 30, 2026 23:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant