Skip to content

chore(deps): bump rmcp from 2.2.0 to 3.1.0 - #260

Merged
KooshaPari merged 1 commit into
mainfrom
dependabot/cargo/rmcp-3.1.0
Aug 7, 2026
Merged

chore(deps): bump rmcp from 2.2.0 to 3.1.0#260
KooshaPari merged 1 commit into
mainfrom
dependabot/cargo/rmcp-3.1.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps rmcp from 2.2.0 to 3.1.0.

Release notes

Sourced from rmcp's releases.

rmcp-macros-v3.1.0

Added

  • add strict stateless protocol metadata validation (#1091)

Other

  • document the ping utility with examples (#1106)
  • complete Tier 1 feature docs and finalize roadmap (#1101)
  • (conformance) meeting requirements for tier 1 (#1087)

rmcp-v3.1.0

Added

  • classify authorization-required errors (#1056)
  • add strict stateless protocol metadata validation (#1091)
  • SEP-2260 stream-based enforcement of client receive-side request association (#1055)

Fixed

  • (model) decode metadata-bearing input-required results affecting mrtr (#1097)
  • require metadata for modern HTTP requests (#1089)
  • honor supported_protocol_versions when negotiating initialize (#1093)

Other

  • document the ping utility with examples (#1106)
  • complete Tier 1 feature docs and finalize roadmap (#1101)
  • (conformance) meeting requirements for tier 1 (#1087)

rmcp-macros-v3.0.1

Other

  • release stable 3.0.0

rmcp-v3.0.1

Fixed

  • (auth) use discovered resource for token refresh (#1084)
  • return header mismatch for missing protocol header (#1083)
  • negotiate stateless initialize versions (#1080)
  • stamp server info on graceful subscription results (#1078)

rmcp-macros-v3.0.0

Other

  • release stable 3.0.0

rmcp-v3.0.0

RMCP 3.0 adds support for MCP 2026-07-28. Review the protocol key changes and the RMCP 3.0 migration guide before upgrading from 2.x.

... (truncated)

Commits
  • 1f9358e chore: release v3.1.0 (#1090)
  • 1cf6deb docs: document the ping utility with examples (#1106)
  • 00bcf13 fix(model): decode metadata-bearing input-required results affecting mrtr (#1...
  • 65f05e9 feat: classify authorization-required errors (#1056)
  • 3240b6e docs: complete Tier 1 feature docs and finalize roadmap (#1101)
  • def31f0 chore(deps): bump github/codeql-action from 4 to 4.37.3 (#1100)
  • 570c478 chore(deps): bump taiki-e/install-action from 2 to 2.85.2 (#1099)
  • 983a137 feat: add strict stateless protocol metadata validation (#1091)
  • 58b136f fix: require metadata for modern HTTP requests (#1089)
  • d272389 fix: honor supported_protocol_versions when negotiating initialize (#1093)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note

Bump rmcp dependency from 2.2.0 to 3.1.0 in the elicitate crate

Updates the rmcp version in Cargo.toml from 2.2.0 to 3.1.0. No feature flags or other dependency settings change.

Macroscope summarized 1a581c5.

Bumps [rmcp](https://github.com/modelcontextprotocol/rust-sdk) from 2.2.0 to 3.1.0.
- [Release notes](https://github.com/modelcontextprotocol/rust-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/rust-sdk/blob/main/release-plz.toml)
- [Commits](modelcontextprotocol/rust-sdk@rmcp-v2.2.0...rmcp-v3.1.0)

---
updated-dependencies:
- dependency-name: rmcp
  dependency-version: 3.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests updating dependencies label Aug 3, 2026
@dependabot
dependabot Bot requested a review from KooshaPari as a code owner August 3, 2026 16:07
@dependabot @github

dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: security. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests updating dependencies label Aug 3, 2026
@codeant-ai

codeant-ai Bot commented Aug 3, 2026

Copy link
Copy Markdown

Skipping PR review because a bot author is detected.

If you want to trigger CodeAnt AI, comment @codeant-ai review to trigger a manual review.

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

No high/critical vulnerabilities introduced by this PR. ✅

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

License audit failed — one or more dependencies use a non-allowlisted license. See the job log for details and update LICENSE_ALLOWLIST.toml if the license is acceptable.

@sonarqubecloud

sonarqubecloud Bot commented Aug 3, 2026

Copy link
Copy Markdown

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1a581c5fbd

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

schemars = "0.8"
crossbeam-channel = "0.5"
rmcp = { version = "2.2", features = ["server", "transport-io", "macros"], optional = true }
rmcp = { version = "3.1", features = ["server", "transport-io", "macros"], optional = true }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Restore the advertised Rust version compatibility

With the default mcp feature enabled, elicitate now resolves rmcp 3.1.0 on every default build. That release declares rust-version = "1.88" in its upstream manifest (https://raw.githubusercontent.com/modelcontextprotocol/rust-sdk/rmcp-v3.1.0/Cargo.toml), while this crate still inherits the workspace rust-version = "1.75"; for CI or user installs pinned to a lower supported toolchain (for example Rust 1.85–1.87, which could handle the previous edition-2024 dependency), Cargo rejects the locked graph before tests run. Please either raise the crate/workspace MSRV or keep rmcp on a compatible line.

Useful? React with 👍 / 👎.

@socket-security

Copy link
Copy Markdown

Dependency limit exceeded — report not shown.

This pull request scan exceeded the 10,000-dependency limit applied to this scan, so the results are incomplete and may be inaccurate. To avoid reporting false positives, Socket has not posted a report.

Upgrade your plan to raise the dependency limit and get complete reports, or view the partial scan in the dashboard.

Socket is always free for open source. If this is a non-commercial open source project, contact us to request a free Team account.

@KooshaPari
KooshaPari merged commit 7eaf618 into main Aug 7, 2026
49 of 60 checks passed
@KooshaPari
KooshaPari deleted the dependabot/cargo/rmcp-3.1.0 branch August 7, 2026 05:08
KooshaPari pushed a commit that referenced this pull request Aug 8, 2026
Rewrites crates/elicitate/src/mcp/router.rs to work against rmcp 1.4.
Main has been on rmcp 1.4 since #260, but the router code was still
written against the rmcp 0.2 API, which broke the --features mcp build.
This commit makes --features mcp compile cleanly and the elicitate-mcp
binary successfully complete an MCP initialize handshake.

What changed
------------
* rmcp::Error → rmcp::ErrorData (alias deprecated since 0.13)
* Parameters import: handler::server::tool::Parameters
    → handler::server::wrapper::Parameters
* ServerInfo / Implementation non-exhaustive struct fields:
    - Use ServerInfo::new(ServerCapabilities::default())
              .with_server_info(Implementation::new("elicitate", version))
    - Cannot construct ServerInfo { server_info: Implementation { … } } directly
* Content::json returns Result<Self, ErrorData> — propagate the error
* CallToolResult: use success(vec) / error(vec) constructors
  instead of struct literal with is_error field
* #[tool(...)] macro: provide explicit input_schema and
  output_schema attributes since the macro's auto-inference tries
  to call schema_for_input which doesn't exist in rmcp 1.4

Dep bump
--------
* schemars 0.8 → 1.0 in elicitate/Cargo.toml
    Required: rmcp 1.4 pulls schemars 1.0 internally. Without the bump,
    the JsonSchema derive macro expanded against the 0.8 source while
    rmcp::schemars resolved to 1.0, producing confusing 'argument #5
    missing' errors.

Tests
-----
* Added: params_roundtrip_via_spec — ElicitateParams → PromptSpec
* Existing: 121/121 still green with --features mcp
  (70 lib + 26 bin + 14 plugin + 6 lib-int + 4 mcp_stdio + 1 router)
* New total: 122/122

Verification
------------
$ echo '{"jsonrpc":"2.0","id":1,"method":"initialize",...}' \
    | ./target/debug/elicitate-mcp
{"jsonrpc":"2.0","id":1,"result":{"protocolVersion":"2024-11-05",
 "capabilities":{},"serverInfo":{"name":"elicitate","version":"0.4.0"}}}

End-to-end MCP handshake works.

Unblocked follow-up
-------------------
This unblocks porting the rmcp-coupled features from
wip/2026-07-22-phenotype-tooling-absorbed-go-mod:
* v0.13.0 elicitate_reply MCP tool
* v0.14.0 multi-inbox (MCP) routing
* v0.16.0 elicitate_enqueue MCP tool
* v0.17.0 elicitate_cancel MCP tool

Each will need a similar rmcp 1.4 adapter as it's ported.

Version bumped 0.3.0 → 0.4.0.
KooshaPari pushed a commit that referenced this pull request Aug 9, 2026
Rewrites crates/elicitate/src/mcp/router.rs to work against rmcp 1.4.
Main has been on rmcp 1.4 since #260, but the router code was still
written against the rmcp 0.2 API, which broke the --features mcp build.
This commit makes --features mcp compile cleanly and the elicitate-mcp
binary successfully complete an MCP initialize handshake.

What changed
------------
* rmcp::Error → rmcp::ErrorData (alias deprecated since 0.13)
* Parameters import: handler::server::tool::Parameters
    → handler::server::wrapper::Parameters
* ServerInfo / Implementation non-exhaustive struct fields:
    - Use ServerInfo::new(ServerCapabilities::default())
              .with_server_info(Implementation::new("elicitate", version))
    - Cannot construct ServerInfo { server_info: Implementation { … } } directly
* Content::json returns Result<Self, ErrorData> — propagate the error
* CallToolResult: use success(vec) / error(vec) constructors
  instead of struct literal with is_error field
* #[tool(...)] macro: provide explicit input_schema and
  output_schema attributes since the macro's auto-inference tries
  to call schema_for_input which doesn't exist in rmcp 1.4

Dep bump
--------
* schemars 0.8 → 1.0 in elicitate/Cargo.toml
    Required: rmcp 1.4 pulls schemars 1.0 internally. Without the bump,
    the JsonSchema derive macro expanded against the 0.8 source while
    rmcp::schemars resolved to 1.0, producing confusing 'argument #5
    missing' errors.

Tests
-----
* Added: params_roundtrip_via_spec — ElicitateParams → PromptSpec
* Existing: 121/121 still green with --features mcp
  (70 lib + 26 bin + 14 plugin + 6 lib-int + 4 mcp_stdio + 1 router)
* New total: 122/122

Verification
------------
$ echo '{"jsonrpc":"2.0","id":1,"method":"initialize",...}' \
    | ./target/debug/elicitate-mcp
{"jsonrpc":"2.0","id":1,"result":{"protocolVersion":"2024-11-05",
 "capabilities":{},"serverInfo":{"name":"elicitate","version":"0.4.0"}}}

End-to-end MCP handshake works.

Unblocked follow-up
-------------------
This unblocks porting the rmcp-coupled features from
wip/2026-07-22-phenotype-tooling-absorbed-go-mod:
* v0.13.0 elicitate_reply MCP tool
* v0.14.0 multi-inbox (MCP) routing
* v0.16.0 elicitate_enqueue MCP tool
* v0.17.0 elicitate_cancel MCP tool

Each will need a similar rmcp 1.4 adapter as it's ported.

Version bumped 0.3.0 → 0.4.0.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests updating dependencies other phase3:wp06

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant