Skip to content

build(deps): cap fastmcp <3.4.0 and add CycloneDX SBOM - #16

Merged
setuidloot merged 1 commit into
mainfrom
chore/fastmcp-cap-sbom
Jul 4, 2026
Merged

setuidloot merged 1 commit into
mainfrom
chore/fastmcp-cap-sbom

Conversation

@setuidloot

Copy link
Copy Markdown
Owner

Follow-up to #15 — carries the one commit (343e56b / cherry-picked as f5290f5) that landed on the branch after #15 was merged, rebased onto current main.

Changes

  • Cap fastmcp = ">=2.10.3,<3.4.0" in pyproject.toml. Unbounded, a fresh pip install metasploit-mcp resolves fastmcp 3.4.2, which ships as the broken fastmcp-slim variant and fails from fastmcp import FastMCP. The cap keeps installs on the tested 3.2.x line. poetry.lock is unchanged except its content-hash (already at 3.2.4).
  • Add a CycloneDX 1.5 SBOM (sbom.json) plus its generator (scripts/generate_sbom.py) and a make sbom target. 128 pinned components from poetry.lock with PyPI PURLs and runtime/dev scope (89 required, 39 optional). Offline and deterministic — serial number derives from the lock digest, so regenerating on an unchanged lock is a no-op.

Verification

  • Branch is one commit off main; SBOM regenerates identically (no drift).
  • Imports clean; fastmcp stays at 3.2.4.
  • Full suite was green (370 passed, 39 skipped) on this change set in chore: finalize v3.0.0 public release prep #15's testing.

🤖 Generated with Claude Code

- Cap `fastmcp = ">=2.10.3,<3.4.0"` in pyproject. Unbounded, a fresh
  `pip install metasploit-mcp` would resolve fastmcp 3.4.2, which ships as the
  broken `fastmcp-slim` variant and fails `from fastmcp import FastMCP`. The cap
  keeps installs on the tested 3.2.x line; poetry.lock is unchanged except its
  content-hash (already at 3.2.4).
- Add `scripts/generate_sbom.py` and generated `sbom.json` (CycloneDX 1.5):
  128 pinned components from poetry.lock with PyPI PURLs and runtime/dev scope
  (89 required, 39 optional). Offline and deterministic (serial derived from the
  lock digest). Regenerate with `make sbom`.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@setuidloot
setuidloot merged commit b0c4c74 into main Jul 4, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant