Skip to content

fix(deps): hold pyjwt>=2.14.0 and document mcp 2.2.0 HTTP session limits - #66

Merged
blackaxgit merged 1 commit into
mainfrom
fix/pyjwt-floor-mcp-2.2-followups
Sep 30, 2026
Merged

blackaxgit merged 1 commit into
mainfrom
fix/pyjwt-floor-mcp-2.2-followups

Conversation

@blackaxgit

Copy link
Copy Markdown
Owner

Why

After merging #62, #63 and #64, main CI is red. The Dependency audit job fails and Docker Build & Push is skipped, so no image has been published from those merges. The cause is ten advisories published today against pyjwt 2.13.0: CVE-2026-101917, CVE-2026-102265..102269 and CVE-2026-102271..102274, all fixed in 2.14.0. They are not introduced by #64: origin/main had the same pyjwt 2.13.0 lock before the merges, and the last green daily audit ran at 12:14Z.

None of them can be reached from ssh-mcp. In mcp 2.2.0 the only import jwt is mcp/client/auth/extensions/client_credentials.py. That is an OAuth client extension, and ssh_mcp never imports it.

What

  • pyproject.toml: adds pyjwt>=2.14.0 under [tool.uv] constraint-dependencies. This is the transitive-floor convention already used for click/cryptography, so the wheel's Requires-Dist does not change. tests/test_dependency_floors.py gets the matching SECURITY_FLOORS entry.
  • uv.lock: uv lock --upgrade-package pyjwt. Only pyjwt moves (2.13.0 -> 2.15.1), plus the manifest constraint.
  • CHANGELOG.md [Unreleased]: a Security entry for the above, and a Changed entry for the stateful-session limits that mcp 2.2.0 (chore(deps): bump the python-version-updates group across 1 directory with 4 updates #64) introduced: a 30-minute idle expiry and a 10,000-session cap, legacy protocol only; stateless mode avoids both. README.md gets the same information in one sentence.
  • Line citations updated to mcp 2.2.0 in AGENTS.md and in comments only in src/ssh_mcp/server.py. The AST is unchanged apart from docstrings. The test count in AGENTS.md is updated to 850.

Verification

  • HYPOTHESIS_PROFILE=ci pytest: 850 passed. ruff format/check, mypy, bandit, uv lock --check, pip-audit (no known vulnerabilities), and gitleaks over origin/main..HEAD are all clean.
  • Smoke test on a loopback HTTP transport with a throwaway config: initialize, tools/list (6 tools), and a bogus session id returns 404 Session not found, as documented.
  • Review panel with no fallbacks: claude-fable-5-1, gpt-6.1-sol and grok-4.7-high in round 1, then fable and sol confirmed the fixes (both PASS).

@blackaxgit
blackaxgit merged commit 906ad8e into main Sep 30, 2026
7 checks passed
@blackaxgit
blackaxgit deleted the fix/pyjwt-floor-mcp-2.2-followups branch September 30, 2026 14:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant