This repository was archived by the owner on Apr 29, 2026. It is now read-only.
fix(deps): update module github.com/modelcontextprotocol/go-sdk to v1 - autoclosed - #72
Closed
renovate[bot] wants to merge 1 commit into
Closed
Conversation
renovate
Bot
force-pushed
the
renovate/github.com-modelcontextprotocol-go-sdk-1.x
branch
2 times, most recently
from
October 6, 2025 08:00
c90c6ed to
3a7a5f0
Compare
renovate
Bot
force-pushed
the
renovate/github.com-modelcontextprotocol-go-sdk-1.x
branch
from
October 30, 2025 16:35
3a7a5f0 to
10d94e4
Compare
renovate
Bot
deleted the
renovate/github.com-modelcontextprotocol-go-sdk-1.x
branch
November 10, 2025 23:49
renovate
Bot
force-pushed
the
renovate/github.com-modelcontextprotocol-go-sdk-1.x
branch
2 times, most recently
from
November 11, 2025 04:54
10d94e4 to
a560813
Compare
renovate
Bot
force-pushed
the
renovate/github.com-modelcontextprotocol-go-sdk-1.x
branch
3 times, most recently
from
December 22, 2025 16:37
43df6e2 to
3b9529c
Compare
renovate
Bot
force-pushed
the
renovate/github.com-modelcontextprotocol-go-sdk-1.x
branch
from
February 9, 2026 21:51
3b9529c to
e12a866
Compare
Contributor
Author
ℹ️ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
renovate
Bot
force-pushed
the
renovate/github.com-modelcontextprotocol-go-sdk-1.x
branch
from
February 18, 2026 18:53
e12a866 to
bbcc97a
Compare
renovate
Bot
force-pushed
the
renovate/github.com-modelcontextprotocol-go-sdk-1.x
branch
from
February 27, 2026 17:10
bbcc97a to
d765e7d
Compare
renovate
Bot
force-pushed
the
renovate/github.com-modelcontextprotocol-go-sdk-1.x
branch
from
March 13, 2026 15:08
d765e7d to
c9496db
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.5.0→v1.4.1Release Notes
modelcontextprotocol/go-sdk (github.com/modelcontextprotocol/go-sdk)
v1.4.1Compare Source
This release is a patch release for v1.4.0.
It contains cherry-picks for several security improvements. Security advisories will follow.
Fixes
Update of the
segmentio/encodingmodule versionThe JSON parsing library that was adopted to avoid attacks taking advantage of the Go's standard parser being case insensitive turned out to contain an issue itself. We have submitted the fix upstream and this release updates the dependency to the patched version.
Cross-origin requests protection
We have added additional protection against cross origin requests. From now on, we verify that
Content-Typefor JSON-RPCPOSTrequests is set toapplication/jsonand use the newhttp.CrossOriginProtectionfunctionality to verify the origin of the request. Usage of this functionality required increasing the required Go version to 1.25, which is in line with our Go version policy of supporting two newest Go versions. The behavior can be customized by passing a configuredhttp.CrossOriginProtectionobject toStreamableHTTPOptions.Since this is a behavior change, we introduced a compatibility parameter
disablecrossoriginprotectionthat will allow to temporarily disable it. It will be removed inv1.6.0version of the SDK. See here for more details about behavior changes and a history of compatibility parameters across SDK versions.Allowing customization of
http.Clientfor client-side OAuthWe have introduced an optional
http.Clientparameter toAuthorizationCodeHandlerConfig. This allows customization of the transport, for example implementing environment specific protection against Server-Side Request Forgery.Pull requests
Full Changelog: modelcontextprotocol/go-sdk@v1.4.0...v1.4.1
v1.4.0Compare Source
This release marks the completion of the full 2025-11-25 specification implementation, by introducing the support for Sampling with Tools and experimental client-side OAuth support. It also contains multiple bug fixes and improvements. Thanks to all contributors!
Client-side OAuth support
This release introduces experimental support for OAuth on the client side of the SDK. It aims to support the full scope of the current MCP specification for authorization. To use it, you need to compile the SDK with the
-tags mcp_go_client_oauthflag. Some changes may still be applied to this new API, based on developer feedback. The functionality is planned to become stable inv1.5.0release, expected by the end of March 2026. More details can be found at https://github.com/modelcontextprotocol/go-sdk/blob/main/docs/protocol.md#client.Sampling with Tools
Starting from this release, the server use the new
CreateMessageWithToolsmethod to create a sampling request to the client that contains tools that can be used by the client. On the client side,CreateMessageWithToolsHandlermay be used to handle such requests and issueToolUseresponses to the server.Behavior changes
We have two important behavior changes that were introduced to fix a bug or improve security posture. They can be temporarily turned off by specifying a special
MCPGODEBUGenvironment variable when running the SDK. Different options can be added together, separated by a comma.Introduced DNS rebinding protection
The requests arriving via a localhost address (
127.0.0.1,[::1]) that have a non-localhostHostheader will be rejected to protect against DNS rebinding attacks. The protection can be disabled by specifyingStreamableHTTPOptions.DisableLocalhostProtection, but it should be done only if security implications are understood (see documentation for the option).This protection is a behavior change, as the protection is now enabled by default. Because of that, we have introduced an
MCPGODEBUGoption to bring back the previous default behavior for users that need more time to adjust. However, if possible, we recommend specifyingDisableLocalhostProtectiondescribed above, as it is a more future-proof solution. TheMCPGODEBUGoption to remove this protection (disablelocalhostprotection=1) will be removed inv1.6.0.Removed JSON content escaping when marshaling
By default
encoding/jsonescapes the contents of the objects, which causes some servers to fail. We switched to no escaping by default, to be consistent with other SDKs. Since this is a behavior change, we introduced anMCPGODEBUGoption to bring back the previous behavior for users that need more time to adjust to it. That option (jsonescaping=1) will be removed inv1.6.0.Bug fixes
Security vulnerability caused by the case insensitive parsing behavior of
encoding/jsonhas been submitted (also release as a cherry pick inv1.3.1). Security advisory has been posted.Other fixes:
Enhancements
Notably, the SDK now supports the
extensionsfield in client and server capabilities, which should enable creation of MCP Apps.Other enhancements:
Repository organization
Some effort was put into better organization of the repository, as well as making sure it's up to date and secure. As a highlight, the repository is not integrated with OSSF Scorecard with a positive score of 8.7. Additionally, the full conformance test suite is now run on every PR and push to main.
dns-rebinding-protectionscenario as failing by @maciej-kisiel in #775New Contributors
Full Changelog: modelcontextprotocol/go-sdk@v1.3.0...v1.4.0
v1.3.1Compare Source
This release is a patch release for v1.3.0.
It contains a cherry-pick for a security issue reported in #805, which takes advantage of the default behavior of Go's standard library JSON decoder that allows case-insensitive matches to struct field names (or "json" tags). The issue has been addressed by changing the JSON decoder to one that supports case sensitive matching.
Fixes
New external dependencies
Full Changelog: modelcontextprotocol/go-sdk@v1.3.0...v1.3.1
v1.3.0Compare Source
This release is equivalent to v1.3.0-pre.1. Thank you to those who tested the pre-release.
This release includes several enhancements and bugfixes. Worth mentioning is the addition of schema caching, which significantly improves the performance in some stateless server deployment scenarios.
Dependency updates
Enhancements
Bugfixes
Chores
New Contributors
Full Changelog: modelcontextprotocol/go-sdk@v1.2.0...v1.3.0
v1.2.0Compare Source
This release is equivalent to v1.2.0-pre.2. Thank you to those who tested the prerelease.
This release adds partial support for the 2025-11-25 version of the MCP spec and fixes some bugs in the streamable transports. It also includes some minor new APIs, changes to contributing flows, and small bugfixes.
Contributing changes
examples/server/conformance) is added for the new conformance tests at modelcontextprotocol/conformance. Test can be run withscripts/conformance.sh(#650).Partial support for the 2025-11-25 spec
The following SEPs from the 2025-11-25 spec are now supported. Please see #725 for the proposed API additions included to support these SEPs.
Other API additions
jsonrpc.Error(#452)ClientCapabilities.RootsV2and RootCapabilities are added to work around an API bug (#607)Capabilitiesfields are added toServerOptionsandClientOptions, to simplify capability configuration (#706)Streamable fixes
Several bug fixes are included for the streamable transports:
Other notable bugfixes
New Contributors
Full Changelog: modelcontextprotocol/go-sdk@v1.1.0...v1.2.0
v1.1.0Compare Source
This release introduces a few new features, and includes improvements and bug fixes for the streamable transport. Notably, the default behavior of the streamable server transport is changed to disable streams resumption (see #580).
Behavior Changes
Stream resumption disabled by default. In the
StreamableServerTransport, the default value ofnilfor theEventStorefield now disables stream resumption, rather than defaulting to use an in-memory event store. Resumption is not desirable in many cases, particularly for servers that must serve a large number of users and/or streams.If you want to enable resumption, set
StreamableHTTPOptions.EventStore.In general, we will avoid changing behaviors that may be relied upon by users, but in this case the old default was deemed to be an oversight/bug, and fixing it now will benefit future users.
API Additions
IOTransportis a new general-purpose transport constructed from anio.ReadCloserandio.WriteCloser(#444 ).ServerOptions.LoggerandStreamableHTTPOptions.Loggerenable server-side logging (#170).StreamableHTTPOptions.EventStoreenables stream resumption (#587).StreamableHTTPOptions.SessionTimeoutadds a timeout which, when set, causes idle sessions to be automatically closed (#499).Experimental client-side oauth support
The
authpackage now includes experimental APIs when build with themcp_go_client_oauthbuild tag. See auth/client.go for more details. These APIs may change before their official release.New Contributors
Full Changelog: modelcontextprotocol/go-sdk@v1.0.0...v1.1.0
v1.0.0Compare Source
This is a stable release of the Go SDK.
This release is functionally equivalent to v0.8.0, but formalizes a compatibility guarantee: going forward we won’t make breaking API changes. The API we have is not perfect, but it’s important that we commit to supporting it so that others can depend on the SDK without further churn. If we want to improve the current API in the future, we’ll do so in backward compatible ways, such as by deprecating and adding. For example, #396, #460 and #533 propose new functions that improve the ergonomics of the current API. Given the rate of change of the MCP spec, it seems likely that we’ll want to go to v2 at some point, but we should delay that event for as long as possible.
This release also marks a level of relative completeness. You should be able to implement essentially any behavior described in the MCP spec using the SDK (except client-side OAuth—see #19). See our feature documentation for information on how the SDK models different aspects of the spec.
Finally, this release represents a certain level of maturity. With the help of our contributors, we’ve endeavored to be responsive to bug reports, and as of writing have fixed 60 out of 61 bugs that have been reported against the SDK. Furthermore, the SDK is getting real-world usage both at Google and in the broader Go community. Much of this usage appears to be using the simpler
stdioorssetransports; we anticipate further bug reports and feature requests as the SDK is used in larger, distributedstreamableservers.We owe a great deal of thanks to everyone who has filed bugs or contributed to the SDK. To date, we’ve accepted PRs from 58 distinct contributors, and many more people have filed issues or commented. We’d also like to thank those who have helped maintain the many other SDKs that compose the Go MCP ecosystem.
The plan now is to pay close attention to incoming bug reports, finalize client-side OAuth support, revisit our current set of proposals, and prepare for the next version of the MCP spec. Please use the SDK and continue to file issues. Thanks again!
What's Changed
Not much has changed since v0.8.0, though notably #539 partially addresses the security issue described in #526 (see also https://verialabs.com/blog/from-mcp-to-shell).
New Contributors
Full Changelog: modelcontextprotocol/go-sdk@v0.8.0...v1.0.0
v0.8.0Compare Source
This release exists to include the API change from #518, mentioned in the v0.7.0 release. It also includes a small change to remove extraneous API.
This concludes our API audit. Barring a realization over the weekend, we will cut v1.0.0 and any further API changes will be handled in a backwards compatible way.
API Changes
any, to decouple the SDK's API from thegithub.com/google/jsonschema-go/jsonschemapackage. Now that package is only used for inference (inmcp.AddTool) and validation.Full Changelog: modelcontextprotocol/go-sdk@v0.7.0...v0.8.0
v0.7.0Compare Source
This release fixes a couple bugs related to the
StreamableClientTransport, and relaxes it to be less strict so that it can talk to certain servers that don't perfectly conform to the spec. It also updates togoogle/[email protected], which includes a couple backwards incompatible bug fixes (see below).For more details, see the v0.7.0 milestone.
API Changes
No changes in the API of the SDK itself, but the updated google/jsonschema-go@v0.3.0 contained the following incompatible bug fixes:
ForOptions.TypeSchemasmust be areflect.Type, as incomparable values are not valid map keys.See #518 for a proposal to significantly decouple the SDK from the jsonschema-go package (though it would still be used for inference and validation). This decision blocks the v1.0.0 release.
New Contributors
Full Changelog: modelcontextprotocol/go-sdk@v0.6.0...v0.7.0
v0.6.0Compare Source
This release makes a couple minor API tweaks that arose in preparation for v1.0.0, and adds significant feature documentation in the
docs/directory.This is a release candidate, and all release blocking issues have now been addressed. We will tag v1.0.0 following a final audit (see also #328).
For more details, see the v0.6.0 milestone.
API Changes
StreamIDtype, which was inconsistent with (for example) session IDs, which are strings (#484).GetSessionIDontoServerOptions, as that is more generally useful, and sinceServerSessionexposes anIDmethod (#478).Bug fixes
New Contributors
Full Changelog: modelcontextprotocol/go-sdk@v0.5.0...v0.6.0
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.