fix: cap mcp below 2.0 to stop silent no-op server fallback (0.4.1) #5

Merged
tim merged 4 commits from develop into main 2026-09-06 21:14:37 +00:00
Owner

Summary

  • mcp 2.x renamed FastMCP to MCPServer and moved the module. app/server.py's except ImportError fallback (meant for "SDK not installed" in dev/test) was silently catching that too and swapping in a no-op stub server, so unpinned installs (Dockerfile and CI both do a bare pip install .) were shipping a server where every tool/resource/prompt is inert.
  • Capped mcp[cli] to >=1.28.1,<2 to stop that, regenerated requirements-lock.txt against the capped constraint, and removed the unused uv.lock (stale since the initial commit; the project uses pip via Taskfile.yml, never uv).
  • Aligned ruff/mypy dev floors with the pre-commit revs (they had drifted) and added PLR0917 to the ruff ignore list (new rule surfaced by the ruff bump, same rationale as the existing PLR0913 ignore).
  • Version bumped to 0.4.1 with a matching CHANGELOG.md entry.

Test plan

  • pytest tests/ — 312 passed
  • ruff check / ruff format --check — clean
  • mypy app/ tests/ — clean
  • bandit -r app/ — no issues
  • Verified from mcp.server.fastmcp import FastMCP succeeds and app.server.mcp is the real TypedFastMCP wrapper (not the fallback stub) with the capped constraint

🤖 Generated with Claude Code

https://claude.ai/code/session_01T7TeYpy6hK7de1bAghSSjU

## Summary - `mcp` 2.x renamed `FastMCP` to `MCPServer` and moved the module. `app/server.py`'s `except ImportError` fallback (meant for "SDK not installed" in dev/test) was silently catching that too and swapping in a no-op stub server, so unpinned installs (Dockerfile and CI both do a bare `pip install .`) were shipping a server where every tool/resource/prompt is inert. - Capped `mcp[cli]` to `>=1.28.1,<2` to stop that, regenerated `requirements-lock.txt` against the capped constraint, and removed the unused `uv.lock` (stale since the initial commit; the project uses pip via `Taskfile.yml`, never uv). - Aligned `ruff`/`mypy` dev floors with the pre-commit revs (they had drifted) and added `PLR0917` to the ruff ignore list (new rule surfaced by the ruff bump, same rationale as the existing `PLR0913` ignore). - Version bumped to 0.4.1 with a matching `CHANGELOG.md` entry. ## Test plan - [x] `pytest tests/` — 312 passed - [x] `ruff check` / `ruff format --check` — clean - [x] `mypy app/ tests/` — clean - [x] `bandit -r app/` — no issues - [x] Verified `from mcp.server.fastmcp import FastMCP` succeeds and `app.server.mcp` is the real `TypedFastMCP` wrapper (not the fallback stub) with the capped constraint 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01T7TeYpy6hK7de1bAghSSjU
Forgejo doesn't support the permissions field (warns and ignores it --
capabilities are granted via Authorized Integrations instead). Both
jobs already authenticate explicitly with secrets.CODEBERG_TOKEN, so
the field was dead weight generating a warning on every run.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
chore: repoint CI/registry from Codeberg to self-hosted Forgejo
All checks were successful
Test & Build / Run Tests (push) Successful in 28s
Test & Build / Build & Push Docker Images (push) Successful in 3m51s
Test & Build / Create Forgejo Release (push) Has been skipped
a6eeec788f
Codeberg account is closed. Registry, release-creation API calls, and
docs now point at git.timstoop.nl/tim instead of codeberg.org/timstoop.
Secrets/vars renamed CODEBERG_* -> REGISTRY_* (FORGEJO_* prefix is
rejected by Forgejo as reserved).
fix: cap mcp below 2.0 to stop silent no-op server fallback, bump to 0.4.1
Some checks failed
Test & Build / Run Tests (push) Successful in 27s
Test & Build / Run Tests (pull_request) Successful in 26s
Test & Build / Build & Push Docker Images (pull_request) Has been skipped
Test & Build / Create Forgejo Release (pull_request) Has been skipped
Test & Build / Create Forgejo Release (push) Has been cancelled
Test & Build / Build & Push Docker Images (push) Has been cancelled
0d3fc765f0
mcp 2.x renamed FastMCP to MCPServer and moved the module. app/server.py's
except ImportError fallback (meant for "SDK not installed" in dev/test)
was silently catching that as well and swapping in a no-op stub server,
so unpinned installs (Dockerfile and CI both do a bare `pip install .`)
were shipping a server where every tool/resource/prompt is inert.

Also aligns ruff/mypy dev floors with pre-commit revs (they had drifted,
and the ruff bump surfaces PLR0917 on the existing multi-arg tool
functions, same rationale as the pre-existing PLR0913 ignore), and drops
the unused uv.lock (stale since the initial commit; the project uses pip
via Taskfile.yml, never uv).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01T7TeYpy6hK7de1bAghSSjU
Merge remote-tracking branch 'origin/main' into develop
All checks were successful
Test & Build / Run Tests (pull_request) Successful in 26s
Test & Build / Build & Push Docker Images (pull_request) Has been skipped
Test & Build / Create Forgejo Release (pull_request) Has been skipped
Test & Build / Run Tests (push) Successful in 26s
Test & Build / Build & Push Docker Images (push) Successful in 14s
Test & Build / Create Forgejo Release (push) Has been skipped
ce48c49ed3
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01T7TeYpy6hK7de1bAghSSjU
tim merged commit e6221964ba into main 2026-09-06 21:14:37 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
tim/hass-mcp!5
No description provided.