/
/
Bumps [fastmcp](https://github.com/PrefectHQ/fastmcp) from 3.4.4 to 3.4.7. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/PrefectHQ/fastmcp/releases">fastmcp's releases</a>.</em></p> <blockquote> <h2>v3.4.7: Know Your Audience</h2> <p>FastMCP 3.4.7 restores CIMD <code>private_key_jwt</code> authentication for OAuthProxy deployments at a bare origin. Client assertions are now validated against the exact token endpoint advertised in authorization server metadata, eliminating the doubled-slash audience mismatch.</p> <!-- raw HTML omitted --> <h2>What's Changed</h2> <h3>Security 🔒</h3> <ul> <li>Backport CIMD assertion audience fix to v3 by <a href="https://github.com/jlowin"><code>@jlowin</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4799">PrefectHQ/fastmcp#4799</a></li> </ul> <h3>Docs 📚</h3> <ul> <li>Docs: add v3.4.7 changelog entries by <a href="https://github.com/jlowin"><code>@jlowin</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4810">PrefectHQ/fastmcp#4810</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/PrefectHQ/fastmcp/compare/v3.4.6...v3.4.7">https://github.com/PrefectHQ/fastmcp/compare/v3.4.6...v3.4.7</a></p> <h2>v3.4.6: Trust, but Proxy</h2> <p>FastMCP 3.4.6 backports trusted-proxy support for SSRF-protected OAuth metadata and JWKS fetches. Deployments can now route these requests through a mandated corporate proxy while preserving custom CA certificates; FastMCP refuses the fetch when no proxy is configured instead of risking an unprotected direct request.</p> <!-- raw HTML omitted --> <h2>What's Changed</h2> <h3>Fixes 🐞</h3> <ul> <li>Backport <a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4412">#4412</a> to 3.x: support trusted SSRF proxies by <a href="https://github.com/jlowin"><code>@jlowin</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4755">PrefectHQ/fastmcp#4755</a></li> </ul> <h3>Docs 📚</h3> <ul> <li>Docs: add v3.4.6 changelog entries by <a href="https://github.com/jlowin"><code>@jlowin</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4761">PrefectHQ/fastmcp#4761</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/PrefectHQ/fastmcp/compare/v3.4.5...v3.4.6">https://github.com/PrefectHQ/fastmcp/compare/v3.4.5...v3.4.6</a></p> <h2>v3.4.5: Key Change</h2> <p>FastMCP 3.4.5 collects five fixes for the 3.x line. The one that prompted it: a single Ed25519 key in a JWKS — which Rauthy, Ory Hydra, and some Keycloak configurations publish by default — made <code>JWTVerifier</code> reject every token, including ones correctly signed by supported keys in the same set.</p> <!-- raw HTML omitted --> <h2>What's Changed</h2> <h3>Fixes 🐞</h3> <ul> <li>Backport <a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4517">#4517</a> to release/3.x: skip unsupported JWKS keys (<a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4515">#4515</a>) by <a href="https://github.com/kakiii"><code>@kakiii</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4631">PrefectHQ/fastmcp#4631</a></li> <li>Backport <a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4469">#4469</a> to release/3.x: fix Azure scope fallback by <a href="https://github.com/jlowin"><code>@jlowin</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4662">PrefectHQ/fastmcp#4662</a></li> <li>Backport <a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4523">#4523</a> to release/3.x: serialize deep object query parameters by <a href="https://github.com/jlowin"><code>@jlowin</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4664">PrefectHQ/fastmcp#4664</a></li> <li>Backport <a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4564">#4564</a> to release/3.x: make transformed tool required order deterministic by <a href="https://github.com/jlowin"><code>@jlowin</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4665">PrefectHQ/fastmcp#4665</a></li> <li>Backport <a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4492">#4492</a> to release/3.x: don't mutate the caller's schema in compress_schema by <a href="https://github.com/jlowin"><code>@jlowin</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4663">PrefectHQ/fastmcp#4663</a></li> </ul> <h3>Docs 📚</h3> <ul> <li>Docs: add v3.4.5 changelog entries by <a href="https://github.com/jlowin"><code>@jlowin</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4673">PrefectHQ/fastmcp#4673</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/kakiii"><code>@kakiii</code></a> made their first contribution in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4631">PrefectHQ/fastmcp#4631</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/PrefectHQ/fastmcp/compare/v3.4.4...v3.4.5">https://github.com/PrefectHQ/fastmcp/compare/v3.4.4...v3.4.5</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/PrefectHQ/fastmcp/blob/main/docs/changelog.mdx">fastmcp's changelog</a>.</em></p> <blockquote> <hr /> <h2>title: "Changelog" icon: "list-check" rss: true tag: NEW</h2> <!-- raw HTML omitted --> <p><strong><a href="https://github.com/PrefectHQ/fastmcp/releases/tag/v4.0.0b3">v4.0.0b3: Fast Fourward</a></strong></p> <p>FastMCP 4 beta 3 moves the v4 line toward general availability with Prefect Horizon authentication, <code>CallArgument</code> and <code>Depends</code> bindings for tools and background tasks, and a round of OAuth, proxy, OpenAPI, and Python 3.14 compatibility hardening.</p> <h3>Enhancements ✨</h3> <ul> <li>Add Prefect Horizon authentication client and local state by <a href="https://github.com/parkedwards"><code>@parkedwards</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4785">#4785</a></li> <li>Clarify auto-closed PR message by <a href="https://github.com/jlowin"><code>@jlowin</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4820">#4820</a></li> <li>Support CallArgument and Depends bindings from uncalled-for 0.4.0 by <a href="https://github.com/chrisguidry"><code>@chrisguidry</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4802">#4802</a></li> <li>Fix static analysis under newer ty releases by <a href="https://github.com/zzstoatzz"><code>@zzstoatzz</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4831">#4831</a></li> <li>Cover CallArgument resolution in background tasks by <a href="https://github.com/zzstoatzz"><code>@zzstoatzz</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4833">#4833</a></li> <li>Scalekit issuer updates backward compatibility by <a href="https://github.com/AkshayParihar33"><code>@AkshayParihar33</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4798">#4798</a></li> </ul> <h3>Security 🔒</h3> <ul> <li>Add audience pinning to GoogleTokenVerifier by <a href="https://github.com/zzstoatzz"><code>@zzstoatzz</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4827">#4827</a></li> <li>Bump cryptography to 50.0.0 by <a href="https://github.com/zzstoatzz"><code>@zzstoatzz</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4836">#4836</a></li> </ul> <h3>Fixes 🐞</h3> <ul> <li>Fix partial parameter hints on Python 3.14 by <a href="https://github.com/zzstoatzz"><code>@zzstoatzz</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4796">#4796</a></li> <li>fix(openapi): extract parameter-level example and examples by <a href="https://github.com/doneman536"><code>@doneman536</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4793">#4793</a></li> <li>Keep earlier consent CSRF tokens valid within a transaction by <a href="https://github.com/trevhud"><code>@trevhud</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4818">#4818</a></li> <li>Fix StatefulProxyClient reconnection after session failure by <a href="https://github.com/jlowin"><code>@jlowin</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4829">#4829</a></li> </ul> <h3>Docs 📚</h3> <ul> <li>Docs language dropdown by <a href="https://github.com/znicholasbrown"><code>@znicholasbrown</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4801">#4801</a></li> <li>Docs: mirror v3.4.7 release notes by <a href="https://github.com/jlowin"><code>@jlowin</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4811">#4811</a></li> <li>docs: prepare FastMCP 4 beta 3 by <a href="https://github.com/jlowin"><code>@jlowin</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4840">#4840</a></li> <li>docs: add FastMCP 4 beta 3 release entries by <a href="https://github.com/jlowin"><code>@jlowin</code></a> in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4841">#4841</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/parkedwards"><code>@parkedwards</code></a> made their first contribution in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4785">#4785</a></li> <li><a href="https://github.com/trevhud"><code>@trevhud</code></a> made their first contribution in <a href="https://redirect.github.com/PrefectHQ/fastmcp/pull/4818">#4818</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/PrefectHQ/fastmcp/compare/v4.0.0b2...v4.0.0b3">v4.0.0b2...v4.0.0b3</a></p> <!-- raw HTML omitted --> <!-- raw HTML omitted --> <p><strong><a href="https://github.com/PrefectHQ/fastmcp/releases/tag/v3.4.7">v3.4.7: Know Your Audience</a></strong></p> <p>FastMCP 3.4.7 fixes CIMD <code>private_key_jwt</code> authentication on bare-origin OAuth proxy deployments by validating client assertions against the exact token endpoint advertised in OAuth metadata.</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/PrefectHQ/fastmcp/commit/758397efa66e2cedac95ada540001bc44a95a646"><code>758397e</code></a> Docs: add v3.4.7 changelog entries (<a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4810">#4810</a>)</li> <li><a href="https://github.com/PrefectHQ/fastmcp/commit/538611b50be30e6ed90a27d083e0847e25a62c51"><code>538611b</code></a> Backport CIMD assertion audience fix to v3 (<a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4799">#4799</a>)</li> <li><a href="https://github.com/PrefectHQ/fastmcp/commit/c587bdd854c85052e908a7c8ef8088d108c87174"><code>c587bdd</code></a> Docs: add v3.4.6 changelog entries (<a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4761">#4761</a>)</li> <li><a href="https://github.com/PrefectHQ/fastmcp/commit/fcdf422e54fe84d384b37a10115d3e7b4aeb0f3f"><code>fcdf422</code></a> Backport <a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4412">#4412</a> to 3.x: support trusted SSRF proxies (<a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4755">#4755</a>)</li> <li><a href="https://github.com/PrefectHQ/fastmcp/commit/8de0c94cbbe71849c98cef2bbe08cdf498dba09c"><code>8de0c94</code></a> Docs: add v3.4.5 changelog entries (<a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4673">#4673</a>)</li> <li><a href="https://github.com/PrefectHQ/fastmcp/commit/5daa91bafe75a9549e9acf0fd68cfdb3fe2d0ccb"><code>5daa91b</code></a> Backport <a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4492">#4492</a> to release/3.x: don't mutate the caller's schema in compress_s...</li> <li><a href="https://github.com/PrefectHQ/fastmcp/commit/49c5ed55815700473d045bf6143e57e4847ce654"><code>49c5ed5</code></a> Make transformed tool required order deterministic (<a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4564">#4564</a>) (<a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4665">#4665</a>)</li> <li><a href="https://github.com/PrefectHQ/fastmcp/commit/87ba18c89825541fa45de2c3cbde2ca9f33530ee"><code>87ba18c</code></a> Serialize deep object query parameters (<a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4523">#4523</a>) (<a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4664">#4664</a>)</li> <li><a href="https://github.com/PrefectHQ/fastmcp/commit/aa8ab1ee66c0fc6b5386ddb6973e934d2071d546"><code>aa8ab1e</code></a> Fix Azure scope fallback (<a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4469">#4469</a>) (<a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4662">#4662</a>)</li> <li><a href="https://github.com/PrefectHQ/fastmcp/commit/93696a59f433157ad01b1d5945f032c233903435"><code>93696a5</code></a> Skip unsupported JWKS keys instead of failing the whole key set (<a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/4515">#4515</a>) (<a href="https://redirect.github.com/PrefectHQ/fastmcp/issues/451">#451</a>...</li> <li>See full diff in <a href="https://github.com/PrefectHQ/fastmcp/compare/v3.4.4...v3.4.7">compare view</a></li> </ul> </details> <br /> --------- Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>