-
Notifications
You must be signed in to change notification settings - Fork 424
Closed
Description
Dependency Audit
Date: 2025-12-31
Summary
- Dependabot PRs: 0 pending
- Package manager: Compliant (pyproject.toml + uv.lock)
- Stale dependencies: 1 flagged
Dependabot PRs
None
Package Manager
Status: Compliant
The repository correctly uses:
pyproject.tomlfor dependency declarationuv.lockfor lock file (251,887 bytes)
No migration needed.
Stale Dependencies
| Package | Current | Latest | Gap |
|---|---|---|---|
| fastmcp | 2.12.5 (exact pin) | 2.14.1 | 2 minor versions behind |
| fastapi | >=0.115.12 | 0.128.0 | Current (within range) |
| google-api-python-client | >=2.168.0 | 2.75.0+ | Manual review needed |
| httpx | >=0.28.1 | 0.28.1 | Current |
| pyjwt | >=2.10.1 | 2.10.1 | Current |
Stale Pins
fastmcp==2.12.5
- Current: Exact pin at 2.12.5
- Latest: 2.14.1 (released Dec 15, 2025)
- Gap: 2 minor versions behind
- Recommendation: Update to
fastmcp>=2.14.1or latest stable
Actions
- Update fastmcp from exact pin 2.12.5 to >=2.14.1 (or latest 2.x)
- Consider removing exact pin constraint to allow patch/minor updates within semver
- Run
uv syncafter updating pyproject.toml to refresh lock file
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels