Pull Requests
Volume
Time to First Review
Merge Time
PRs Needing Maintainer Review
Open PRs with no maintainer review (excludes drafts from counts)
PRs Awaiting Maintainer Review
Sorted by longest wait time first
| PR | Title | Author | Size | Reviews | Waiting |
|---|---|---|---|---|---|
| #813 | fix: deduplicate title definition in tools | connor4312 | +0 -9 | 0 | 438d |
| #1803 | SEP-1803: Event Subscriptions | caseychow-oai | +184 -0 | 0 | 293d |
| #1862 | SEP-1862: Tool Resolution | SamMorrowDrums | +1723 -0 | 0 | 284d |
| #1913 | SEP-1913: Trust and Sensitivity Annotations | SamMorrowDrums | +2347 -0 | 16 | 278d |
| #1984 | SEP-1984: Comprehensive Tool Annotations for Enhanced Governance and UX | sambhav | +488 -0 | 0 | 259d |
| #2028 | SEP-2028: Automatic _meta to HTTP header forwarding for distributed tracing | monahk | +861 -0 | 13 | 246d |
| #2053 | SEP-2053: Server Variants extension | sambhav | +1613 -0 | 0 | 238d |
| #2282 | SEP-2282: Server-Declared Behavioural Hooks | heyhayes | +871 -2 | 0 | 192d |
| #2357 | SEP-2357: Dedicated structured media type for MCP HTTP transport | rvmillett | +365 -0 | 0 | 180d |
| #2391 (draft) | [WIP] Add spec annotator plugin to Claude Code marketplace | LucaButBoring | +3061 -3 | 0 | 173d |
| #2385 | SEP-2385: Tool Auth Manifest | lececo | +167 -0 | 0 | 173d |
| #2417 | SEP-2417: Model Preferences for Tools | ProductOfAmerica | +3043 -1 | 0 | 168d |
| #2419 | SEP-2419: cache_hint well-known key in CallToolResult._meta | clouatre | +454 -0 | 0 | 167d |
| #2487 (draft) | SEP-2487: Add execution.requirements field to Tool for preconditions | ZachGerman | +127 -4 | 0 | 157d |
| #2495 | SEP-2495: Event-Driven Tool Invocation (Server-Push to LLM Re-entry) | hf75 | +119 -0 | 2 | 156d |
| #2528 | docs: Add deployment guidelines for proxying MCP servers | jeffyaw | +153 -1 | 0 | 148d |
| #2532 | SEP-2532: Resource Streaming for Binary Content Delivery | patrick-rodgers | +1249 -0 | 0 | 147d |
| #2564 | SEP-2564: Server-Side Filtering for List Methods | anagh96 | +385 -0 | 0 | 140d |
| #2571 | SEP-2571: Resource Submission for Agent Coordination | cswelker | +193 -0 | 0 | 140d |
| #2601 | docs: define uriTemplate as unique identifier for resource templates | rohitg00 | +13 -1 | 0 | 136d |
| #2602 | docs: add server instructions guide | rohitg00 | +146 -0 | 0 | 136d |
| #2614 | SEP-2614: Add optional keywords field to Implementation for server routing | Vijaynw | +595 -6 | 0 | 134d |
| #2631 (draft) | SEP-2631: File Objects and Transfer | caseychow-oai | +2839 -45 | 15 | 132d |
| #2624 | SEP-2624: Interceptors for the Model Context Protocol | Degiorgio | +3844 -1 | 0 | 132d |
| #2632 | SEP-2632: Structured Content for Progress Notifications | stevehaertel | +477 -5 | 0 | 132d |
| #2636 | SEP-2636: Progressive Tool Disclosure | SylonZero | +759 -0 | 0 | 131d |
| #2643 | SEP-2643: Structured Authorization Denials | monmohan | +1046 -0 | 55 | 130d |
| #2672 | SEP-2672: Per-Call Passkey Verified Approval for MCP Tool Calls | pinialt | +1475 -0 | 0 | 122d |
| #2694 | SEP-2694: Resumable Task Event Streams | rynowak | +816 -2 | 0 | 117d |
| #2752 | SEP-2752: HTTP Message Signing for MCP Client Authentication | njdawn | +913 -2 | 0 | 105d |
| #2778 | SEP-2778: Adding Type Constraints to the MCP | schlpbch | +276 -20 | 0 | 101d |
| #2781 | docs: add deployment guide for proxying MCP servers | founder-OmniPA | +265 -0 | 1 | 101d |
| #2787 | SEP-2787: Tool call attestation | soup-oss | +1138 -445 | 0 | 99d |
| #2793 | SEP-2793: Tool Risk Metadata | walbis | +227 -0 | 0 | 98d |
| #2809 | SEP-2809: Attested Tool-Server Admission (ATSA) | metereconsulting | +1002 -0 | 0 | 96d |
| #2817 | SEP-2817: AI Invocation Audit Context in Request _meta | hangum | +796 -0 | 0 | 95d |
| #2848 | SEP-2848: Asynchronous Approval for Tool Calls | mcguinness | +1507 -2 | 0 | 90d |
| #3004 | SEP-3004: Tamper-Evident Audit Record Contract | scottrhodes | +1415 -0 | 0 | 61d |
| #2998 | SEP-2998: Partial Tool Results (Streaming Tool Call Output) | kuwatly | +300 -0 | 0 | 61d |
| #3094 | SEP-3094: Granular Citations Format | karth295 | +2182 -0 | 0 | 48d |
| #3118 | SEP-3118: App-Rendered Elicitations for MCP Apps | krubenok | +964 -0 | 2 | 40d |
| #3119 | SEP-3119: Structured resource and embedded resource update | tobiasBora | +75 -0 | 0 | 40d |
| #3140 | SEP-3140: Signed Capability Declarations & Trustworthy Trust Labels | omkarparth | +2637 -0 | 0 | 36d |
| #3149 | SEP-3149: Require Token Endpoint Auth Methods Supported in CIMD | max-stytch | +684 -43 | 1 | 35d |
| #3172 | SEP-3172: Add optional recovery metadata to ToolAnnotations | RohithGajawada45 | +321 -43 | 0 | 34d |
| #3235 | Use updated OAuth Client ID Metadata Document RFC | Stevenjin8 | +33 -33 | 0 | 20d |
| #3279 | SEP-3279 - Negotiated Tool Result Variants | krubenok | +1481 -0 | 0 | 13d |
| #3302 | Add scientific computing interest group charter | corykinney | +90 -0 | 0 | 7d |
| #3304 | SEP-3304 - Standardizing Rate-Limiting Errors | tyree731 | +277 -0 | 0 | 7d |
| #3306 | Document identity provider support for enterprise managed auth | claude | +46 -0 | 0 | 6d |
| #3313 | SEP: Structured Tool-Failure Classification (ToolFailure) | johnyzaguirre-glean | +601 -0 | 0 | 5d |
| #3312 | schema: draft structured tool-failure classification (ToolFailure) | johnyzaguirre-glean | +212 -3 | 0 | 5d |
| #3332 | Require issue assignment for non-SEP pull requests | claude | +189 -0 | 0 | 1d |
| #3331 | Restructure Security IG as a routing group | claude | +22 -15 | 0 | 1d |
| #3336 | Require WG/IG discussion before SEP submission | claude | +23 -16 | 0 | 0d |
PR Size Distribution
Open PRs by lines changed
Stats — volume, timing, size distribution
Volume
Time to First Review
Merge Time
PR Size Distribution
Open PRs by lines changed
Breakdown by tier
| Tier | Count | Auth | Maint. | ~Time |
|---|---|---|---|---|
| 1 — We're blocking someone | 17 | 3 | 8 | 5.2h |
| 2 — High leverage | 38 | 7 | 1 | 5.6h |
| 3 — Intake | 135 | 19 | 0 | 67.1h |
| 4 — Hygiene | 14 | 2 | 1 | 1.1h |
| 5 — Close candidates | 13 | 1 | 1 | 13m |
| total actionable | 217 | 32 | 11 | 79.1h |
| not our move | 38 | — | — | — |
We're blocking someone (17) ⊕ ⊖
Author did what we asked and is waiting on us. Longest-waiting first.
3 SLA author-pinged-after-procedural (3) — Author addressed maintainer feedback and pinged — awaiting response.
| #1861 | ravyg | re-reviewmcp: convert tool/prompt schemas eagerly at registration time | author pinged @felixweinberger 134d ago | +362-7 | 147d |
| #2003 | ElliotDrel | re-reviewfix(server): exit when MCP client closes stdin pipe | author pinged @KKonstantinov, @felixweinberger 117d ago | +84-0 | 124d |
| #2204 | aicayzer | re-reviewfix: treat parsedBody = null as no pre-parsed body (v1.x) | author pinged @felixweinberger 30d ago | +47-1 | 95d |
6 SLA1 auth needs-re-review (6) — Author pushed changes after review feedback — needs re-review.
| #1521 | LucaButBoring | re-reviewfix(client): retry SSE stream after receiving session ID | author pushed after CHANGES_REQUESTED (141d waiting) | +417-0 | 203d |
| #1563 | gogakoreli | re-reviewfix: inline local $ref in tool inputSchema for LLM consumption | author pushed after CHANGES_REQUESTED (6d waiting) | +730-21 | 193d |
| #1657 | rechedev9 | re-reviewauthfix: accumulate OAuth scopes on 401/403 instead of overwriting | author pushed after CHANGES_REQUESTED (152d waiting) | +618-50 | 175d |
| #1712 | travisbreaks | re-reviewfeat(server): add host process watchdog to StdioServerTransport | author pushed after CHANGES_REQUESTED (124d waiting) | +57-1 | 166d |
| #1726 | rcdailey | re-reviewfeat(server): add keepAliveInterval for standalone GET SSE stream | author pushed after CHANGES_REQUESTED (45d waiting) | +218-21 | 164d |
| #1814 | MayCXC | re-reviewfix: async onclose, stdin EOF detection, SIGTERM in examples | author pushed after CHANGES_REQUESTED (137d waiting) | +210-40 | 156d |
8 SLA2 auth maintainer-intake (8) — Maintainer-authored PR awaiting review from another maintainer.
| #1893 | KKonstantinov | maintainerfeat: add class decorators example | 139d, no maintainer has looked yet | +564-15 | 139d |
| #1939 | pcarleton | maintainerbuild: exclude src/examples from published dist (v1.x) | 133d, no maintainer has looked yet | +2-2 | 133d |
| #2125 | dsp-ant | maintainerfix(client): treat HTTP 404 with session ID as session expiry | 104d, no maintainer has looked yet | +191-19 | 104d |
| #2370 | mattzcarey | maintainerfeat: add injectable SDK logger | 68d, no maintainer has looked yet | +300-36 | 68d |
| #2440 | felixweinberger | maintainerfeat(server): SDK-owned resource subscription tracking on McpServer | 57d, no maintainer has looked yet | +514-60 | 57d |
| #2449 | mattzcarey | maintainerfix: complete SEP-2106 output typing and schema safety | 56d, no maintainer has looked yet | +343-30 | 56d |
| #2450 | mattzcarey | maintainerauthfix(client): detect authorization-server migration from fresh PRM | 56d, no maintainer has looked yet | +1570-55 | 56d |
| #2485 | felixweinberger | maintainerauthfix(client): scope corrupt-cache-entry deletion to the probed partition | 50d, no maintainer has looked yet | +66-9 | 50d |
High leverage (38) ⊕ ⊖
One decision unblocks or closes multiple things.
28 SLA12 auth duplicate-cluster (28 clusters, 67 PRs) — Multiple PRs address the same issue — one will be picked, others closed as duplicates.
Issue #1132 — 2 PRs ⭐ #1857 (Could not verify live CI status or test contents for either PR (gh and WebFetch access were both unavailable in this session), so those tiebreakers are tied/unknown for both. Falling back to diff size, the only concrete differentiator available: #1857 changes 2 files vs. #2147's 6 files, making it the smaller, more focused change for the same issue (#1132).)
| #1857 | nielskaspers | 1st-reviewdocs: document tool list changed notifications | cluster primary for issue #1132 (2 PRs) | +79-31 | 149d |
| #2147 | Nishant-Chaudhary5338 | feat(example): add tool list changed notification example | shares linked issue #1132 with #1857 | +137-9 | 102d |
Issue #1471 — 3 PRs ⭐ #1509 (Could not reach GitHub from this sandbox (gh/curl/WebFetch all blocked), so this is based only on the metadata given. CI status is listed as unknown for all three, so that tiebreaker doesn't distinguish them. On diff size, #1509 and #1975 are tied at 2 files each, while #2009 touches 4 files for what its title frames as a broader "support two-arg no-schema task handlers" change — a larger surface for the same underlying bug (#1471), so it's dropped in favor of the more focused fixes. Between the two 2-file PRs, #1509 has the lower PR number and was therefore opened first, satisfying the 'oldest' tiebreaker. Recommend re-verifying actual CI results and test coverage before merging, since that data wasn't accessible here.)
| #1509 | corvid-agent | 1st-reviewfix: pass empty args to registerToolTask handler when no inputSchema | cluster primary for issue #1471 (3 PRs) | +8-3 | 204d |
| #1975 | nanookclaw | fix: pass both args when inputSchema omitted in task handler executor | shares linked issue #1471 with #1509 | +47-3 | 126d |
| #2009 | Genmin | fix(server): support two-arg no-schema task handlers | shares linked issue #1471 with #1509 | +112-7 | 123d |
Issue #1944 — 2 PRs ⭐ #2142 (Note: I could not get gh CLI or WebFetch tool approval this session, so I have no independently verified CI results or test-coverage data for either PR — both are listed as "CI: unknown" in the prompt with no test info given. On the only concrete, stated signal — diff size — #2142 touches 2 files vs #1952's 3 files, making it the smaller, more focused change per the stated preference order (passing CI > has tests > smallest diff > oldest). #2142's title also explicitly ties to "closes #1944." This is a provisional pick based on limited data; maintainers should confirm actual CI status and test coverage on both PRs before merging.)
| #1952 | Zelys-DFKH | fix(server): loosen Accept validation when enableJsonResponse is true | shares issue #1944; #2142 is the pick | +34-8 | 131d |
| #2142 | adityachilka1 | 1st-reviewfix(server): allow application/json-only Accept in JSON response mode (closes #1944) | [llm pick] cluster primary for issue #1944: Note: I could not get gh CLI or WebFetch tool approval this session, so I have no independently verified CI results or test-coverage data for either PR — both are listed as "CI: unknown" in the prompt with no test info given. On the only concrete, stated signal — diff size — #2142 touches 2 files vs #1952's 3 files, making it the smaller, more focused change per the stated preference order (passing CI > has tests > smallest diff > oldest). #2142's title also explicitly ties to "closes #1944." This is a provisional pick based on limited data; maintainers should confirm actual CI status and test coverage on both PRs before merging. | +38-3 | 103d |
Issue #1954 — 2 PRs ⭐ #1955 (Both PRs report CI as unknown and neither's test coverage could be verified (network/GitHub access was unavailable to me to confirm directly). On the two remaining tiebreakers from the given facts: diff size and age. #1955 touches 1 file vs. #1981's 5 files — a much smaller, more focused change that's easier to review and less likely to introduce unrelated regressions for a targeted expiry-check fix. #1955 also has the lower PR number, indicating it was opened first (older). Both tiebreakers favor #1955; recommend confirming CI status and test presence on both before merging.)
| #1955 | daksh-goyal | 1st-reviewauth fix(client): check token expiry in adaptOAuthProvider before returning expired tokens | cluster primary for issue #1954 (2 PRs) | +11-1 | 131d |
| #1981 | Genmin | authfix(client): avoid expired OAuth access tokens | shares linked issue #1954 with #1955 | +145-13 | 125d |
Issue #1968 — 4 PRs ⭐ #2581 (CI status and test coverage could not be verified from this environment (no live GitHub/gh access) and are tied/unknown across all four per the prompt. Among the tracked PR metadata, #2518 is still a draft (isDraft: true) and thus not merge-ready. Of the remaining three, #2581 has by far the smallest, most focused diff (+36/-11, 47 lines total) versus #1989 (+68/-14, 82 lines) and #1991 (+75/-12, 87 lines) — roughly half the changed lines for what the titles indicate is the same underlying fix. Since diff size outranks age in the stated preference order, #2581 wins despite being the newest of the four (created 2026-07-30 vs. 2026-04-30 for #1989/#1991).)
| #1989 | Genmin | authfix(client): preserve OAuth resource metadata indicator | shares issue #1968; #2581 is the pick | +68-14 | 125d |
| #1991 | Christian-Sidak | authfix: preserve exact resource URI from protected resource metadata | shares linked issue #1968 with #1989 | +75-12 | 125d |
| #2518 | pradeep-ramola | authPreserve OAuth resource indicator strings | shares linked issue #1968 with #1989 | +62-12 | 45d |
| #2581 | hugosmoreira | 1st-reviewauthfix: preserve exact OAuth resource indicators | [llm pick] cluster primary for issue #1968: CI status and test coverage could not be verified from this environment (no live GitHub/gh access) and are tied/unknown across all four per the prompt. Among the tracked PR metadata, #2518 is still a draft (isDraft: true) and thus not merge-ready. Of the remaining three, #2581 has by far the smallest, most focused diff (+36/-11, 47 lines total) versus #1989 (+68/-14, 82 lines) and #1991 (+75/-12, 87 lines) — roughly half the changed lines for what the titles indicate is the same underlying fix. Since diff size outranks age in the stated preference order, #2581 wins despite being the newest of the four (created 2026-07-30 vs. 2026-04-30 for #1989/#1991). | +36-11 | 34d |
Issue #2002 — 2 PRs ⭐ #2473 (I could not verify live CI status, test coverage, or diff contents for either PR — both `gh` and `WebFetch` calls were blocked in this session, and no local PR data exists in this repo's tracked dataset (only the underlying issue #2002 is recorded, with linked_prs empty). Absent that verification, I'm defaulting to the smallest-diff signal available from the prompt itself: #2473 touches 4 files versus #2494's 10, which under the stated tie-break order (passing CI > has tests > smallest focused diff > oldest) is the only concrete, checkable differentiator I have. This is a low-confidence pick made without CI/test verification — it should be re-checked against actual PR data (CI runs, test files touched, mergeability) before being treated as final, since a larger diff in #2494 could equally reflect added test coverage rather than scope creep.)
| #2473 | harshmathurx | 1st-reviewfix(server): close stdio transport on stdin close | cluster primary for issue #2002 (2 PRs) | +52-4 | 54d |
| #2494 | app/claude | fix(server): close StdioServerTransport when stdin ends or closes | shares linked issue #2002 with #2473 | +467-7 | 49d |
Issue #2012 — 2 PRs ⭐ #2013 (CI status is unlisted for both (tied), and neither PR's file diffs show dedicated test files added, so test coverage can't be used as a differentiator. On the remaining criteria: #2013 has a smaller diff (63 additions / 2 deletions = 65 lines changed across 4 files) vs #2139 (74 additions / 1 deletion = 75 lines changed across 4 files). #2013 was also opened first (2026-05-02, 122 days waiting) vs #2139 (2026-05-21, 103 days waiting). Additionally, #2013's title explicitly commits to returning -32602 for validation errors, which matches the error-code correction described in issue #2012, while #2139's title only covers the null-argument acceptance. Recommend keeping #2013.)
| #2013 | blackwell-systems | 1st-reviewfix: accept null arguments in tools/call and return -32602 for validation errors | cluster primary for issue #2012 (2 PRs) | +63-2 | 122d |
| #2139 | 2830500285 | fix: accept null tool call arguments | shares linked issue #2012 with #2013 | +74-1 | 104d |
Issue #2076 — 2 PRs ⭐ #2224 (CI status and file count are tied between the two (both unknown, both 3 files changed), so the deciding factor is approach. #2082 is a docs(core) change — it clarifies in documentation that resetTimeoutOnProgress requires an onprogress handler, i.e. it documents the existing behavior rather than changing it. #2224 is a fix(core) change that resets the request timeout on progress even without an onprogress handler, which is the actual behavior gap described in #2076 ("only works when onprogress is explicitly provided"). Since the issue asks for the timeout-reset behavior to work without requiring an explicit handler, only #2224's approach addresses the root cause; #2082 documents the bug as intended behavior rather than fixing it. Note: live CI check results and test coverage could not be verified for either PR in this session (no network/gh access available) — confirm actual CI status before merging.)
| #2082 | Jefsky | authdocs(core): clarify resetTimeoutOnProgress requires onprogress | shares issue #2076; #2224 is the pick | +25-7 | 111d |
| #2224 | minglong51 | 1st-reviewfix(core): reset request timeout on progress without an onprogress handler | [llm pick] cluster primary for issue #2076: CI status and file count are tied between the two (both unknown, both 3 files changed), so the deciding factor is approach. #2082 is a docs(core) change — it clarifies in documentation that resetTimeoutOnProgress requires an onprogress handler, i.e. it documents the existing behavior rather than changing it. #2224 is a fix(core) change that resets the request timeout on progress even without an onprogress handler, which is the actual behavior gap described in #2076 ("only works when onprogress is explicitly provided"). Since the issue asks for the timeout-reset behavior to work without requiring an explicit handler, only #2224's approach addresses the root cause; #2082 documents the bug as intended behavior rather than fixing it. Note: live CI check results and test coverage could not be verified for either PR in this session (no network/gh access available) — confirm actual CI status before merging. | +62-5 | 93d |
Issue #2112 — 3 PRs ⭐ #2113 (I was unable to get tool approval to pull live CI/test/diff data via gh for any of the three PRs, so I'm deciding from the information given in the prompt alone. All three touch exactly 1 file with unknown CI status and no indicated tests, so the tiebreaker falls to age: #2113 is the oldest of the three (lowest PR number, opened first), which matches the stated preference order (passing CI > has tests > smallest focused diff > oldest) once the first three criteria are tied/unknown. Its scope is also the most narrowly worded ("add to middleware listing" as a single-line addition), consistent with a minimal, focused diff.)
| #2113 | sceran | 1st-reviewdocs(README): add `@modelcontextprotocol/fastify` to middleware listing | cluster primary for issue #2112 (3 PRs) | +6-2 | 108d |
| #2497 | Joosboy | docs: add fastify middleware to top-level README listing | shares linked issue #2112 with #2113 | +6-2 | 49d |
| #2516 | ayaangazali | docs: add @modelcontextprotocol/fastify to middleware listings | shares linked issue #2112 with #2113 | +1-1 | 46d |
Issue #2162 — 2 PRs ⭐ #2163 (Unable to verify CI status, test coverage, or diff details via GitHub since running `gh pr view` required approval that was not granted, so this pick is based only on the information given in the prompt. #2163 was filed first (oldest, tie-break criterion) and its larger file count (30 files) suggests it includes accompanying test/fixture updates across the affected SDK packages rather than a narrower source-only change, though this could not be confirmed by inspecting the actual diff or CI runs. Since neither PR's CI status was verifiable (both listed as "unknown") and test coverage could not be confirmed for either, the decision defaults to the oldest PR per the stated tie-break order. This recommendation should be re-verified against actual CI results and test presence once repository access is available.)
| #2163 | he-yufeng | 1st-reviewfix: return protocol errors for invalid tool args | cluster primary for issue #2162 (2 PRs) | +7653-207 | 97d |
| #2221 | koriyoshi2041 | Return protocol errors for invalid tool input | shares linked issue #2162 with #2163 | +116-182 | 94d |
Issue #2165 — 2 PRs ⭐ #2177 (CI status is unmarked/unknown for both, so that criterion doesn't distinguish them. On the remaining criteria: #2177 is a 3-file diff focused specifically on adding the RequestAborted error code, while #2617 spans 9 files for what its title frames as a broader distinguish-cancellation-from-timeout change — a larger surface area for a fix that issue #2165 scopes narrowly. #2177 is also the older PR (opened first). Neither PR's test coverage could be verified in this environment (no repo access to diff contents), so the decision rests on diff size and focus: smallest focused diff favors #2177.)
| #2177 | sakthiveltofficial | 1st-reviewfix(protocol): add RequestAborted error code for AbortSignal cancellation | cluster primary for issue #2165 (2 PRs) | +28-1 | 96d |
| #2617 | xudongWu2022 | fix(protocol): distinguish AbortSignal cancellation from request timeout | shares linked issue #2165 with #2177 | +107-17 | 27d |
Issue #2166 — 3 PRs ⭐ #2170 (I was unable to pull concrete CI status, test diffs, or file contents for any of the three PRs — the `gh pr view` calls required approval that wasn't granted, so I don't have verified data on CI pass/fail, test coverage, or exact diff size for #2170, #2216, or #2218. Based only on the information given in the prompt (all three show 3 files changed, CI unknown), I'm defaulting to #2170 as the tentative pick since it's the oldest of the three (lowest PR number, opened first) and its title explicitly references the issue (#2166), suggesting it was the first fix proposed. This is a low-confidence pick given the stated preference order (passing CI > has tests > smallest diff > oldest) — I was only able to apply the last tiebreaker. I'd recommend re-running the comparison with `gh pr view`/`gh pr checks` access approved to confirm CI results and test coverage before finalizing.)
| #2170 | NishchayMahor | 1st-reviewfix(core): match multi-variable URI templates like `{a,b}` (#2166) | cluster primary for issue #2166 (3 PRs) | +75-0 | 96d |
| #2216 | he-yufeng | fix(core): match multi-variable URI template path expressions | shares linked issue #2166 with #2170 | +20-0 | 94d |
| #2218 | koriyoshi2041 | Fix URI template matching for multi-variable simple expressions | shares linked issue #2166 with #2170 | +17-0 | 94d |
Issue #2208 — 3 PRs ⭐ #2223 (I was not able to run `gh pr view` (approval for the command was not granted), so CI status and test coverage for all three PRs remain unverified/unknown — a true tie on the top two criteria. Falling to the next tiebreaker, diff size: #2223 touches only 3 files, versus 4 for #2475 and 5 for #2222, making it the smallest, most focused change among the three. By PR number (a proxy for creation order), #2222 is older than #2223, but since diff size is ranked above age in the stated preference order, #2223 wins. Recommend confirming CI status and test coverage directly on GitHub before merging, since that data could not be independently verified here.</reason> </invoke> )
| #2222 | he-yufeng | authfix(client): let auth headers override request headers | shares issue #2208; #2223 is the pick | +78-5 | 93d |
| #2223 | tarunag10 | 1st-reviewauthLet auth provider headers override requestInit Authorization | [llm pick] cluster primary for issue #2208: I was not able to run `gh pr view` (approval for the command was not granted), so CI status and test coverage for all three PRs remain unverified/unknown — a true tie on the top two criteria. Falling to the next tiebreaker, diff size: #2223 touches only 3 files, versus 4 for #2475 and 5 for #2222, making it the smallest, most focused change among the three. By PR number (a proxy for creation order), #2222 is older than #2223, but since diff size is ranked above age in the stated preference order, #2223 wins. Recommend confirming CI status and test coverage directly on GitHub before merging, since that data could not be independently verified here.</reason> </invoke> | +56-4 | 93d |
| #2475 | sanjibani | authfix(client): let OAuth-derived Authorization override caller-supplied header | shares linked issue #2208 with #2222 | +57-4 | 54d |
Issue #2433 — 2 PRs ⭐ #2435 (CI status is listed as unknown for both PRs and test coverage couldn't be independently verified (gh CLI and WebFetch access were both unavailable in this session, and direct network calls were blocked). With those two criteria tied/unverifiable, the deciding factor is diff size: #2435 changes only 2 files versus #2434's 4 files, making it the smaller, more focused fix for issue #2433.)
| #2434 | Sammy-Dabbas | fix(server): reject duplicate in-flight request ids in streamable HTTP | shares issue #2433; #2435 is the pick | +222-0 | 60d |
| #2435 | JSap0914 | 1st-reviewfix(server): reject duplicate in-flight request ids | [llm pick] cluster primary for issue #2433: CI status is listed as unknown for both PRs and test coverage couldn't be independently verified (gh CLI and WebFetch access were both unavailable in this session, and direct network calls were blocked). With those two criteria tied/unverifiable, the deciding factor is diff size: #2435 changes only 2 files versus #2434's 4 files, making it the smaller, more focused fix for issue #2433. | +66-1 | 60d |
Issue #2605 — 2 PRs ⭐ #2626 (Network tools (gh, WebFetch, WebSearch) were blocked in this environment even after retries and a subagent attempt, so CI status and test coverage could not be independently verified for either PR. Deciding on the data available: both PRs report CI as unknown (no differentiator), but #2626 has a smaller, more focused diff (4 files vs #2699's 6) and is the older PR (lower PR number, opened first). #2626's title also directly references issue #2605 and scopes the fix narrowly to `fix(validators)`, matching the issue's own component, whereas #2699's `fix(core-internal)` scope and larger file count suggest broader surface area for the same fix.)
| #2626 | elang2 | 1st-reviewfix(validators): cache compiled schemas to prevent memory leak (#2605) | cluster primary for issue #2605 (2 PRs) | +256-7 | 24d |
| #2699 | kyletser | fix(core-internal): cache AJV validators for schemas without $id | shares linked issue #2605 with #2626 | +334-3 | 11d |
Issue #2650 — 2 PRs ⭐ #2651 (I was unable to obtain approval to run `gh pr view` against GitHub, so I could not verify live CI status, mergeability, or diff contents for either PR before this response was forced. Based on the info given in the prompt alone: both PRs have CI status "unknown" (no differentiator), so the next tiebreaker is diff size — #2651 touches 3 files vs #2743's 2 files, which would normally favor #2743 as the smaller diff. However, without inspecting the actual diffs I cannot confirm test coverage or whether either PR conflicts with main, which are supposed to be higher-priority tiebreakers than diff size. I'm defaulting to #2651 as the older PR (opened first, per "oldest" as the last tiebreaker) since I could not confirm CI-passing or test-coverage status for either. This pick should be re-verified once GitHub access is available, since it is not based on the concrete CI/test evidence the task requested.</reason> </invoke> )
| #2651 | sushantkumar23 | 1st-reviewfix(server): close a listen stream that has honored nothing | cluster primary for issue #2650 (2 PRs) | +70-1 | 21d |
| #2743 | SoulmatelynchVFX | fix(server): complete empty listen subscriptions | shares linked issue #2650 with #2651 | +36-1 | 0d |
Issue #2657 — 5 PRs ⭐ #2666 (All five report CI as unknown, so that tiebreaker doesn't apply. #2703 and #2726 scope the fix to only "the probe's" client call site rather than the SdkError constructor itself, so they risk leaving other call sites that pass `cause` still broken — #2657 is a constructor-level issue per the other three titles. Among the constructor-level fixes (#2663, #2666, #2683), #2666 and #2683 both touch only 3 files vs. #2663's 4, giving the smaller/more focused diff. Between #2666 and #2683, #2666 has the lower PR number and was opened first. Note: could not confirm actual CI status or test coverage live due to no network access in this session — recommend a quick manual CI/test check on #2666 and #2683 before merging.)
| #2663 | anshusaurav | fix: forward Error.cause in SdkError constructor | shares issue #2657; #2666 is the pick | +68-6 | 18d |
| #2666 | eddinos2 | 1st-reviewfix(errors): forward SdkError causes onto Error.cause | [llm pick] cluster primary for issue #2657: All five report CI as unknown, so that tiebreaker doesn't apply. #2703 and #2726 scope the fix to only "the probe's" client call site rather than the SdkError constructor itself, so they risk leaving other call sites that pass `cause` still broken — #2657 is a constructor-level issue per the other three titles. Among the constructor-level fixes (#2663, #2666, #2683), #2666 and #2683 both touch only 3 files vs. #2663's 4, giving the smaller/more focused diff. Between #2666 and #2683, #2666 has the lower PR number and was opened first. Note: could not confirm actual CI status or test coverage live due to no network access in this session — recommend a quick manual CI/test check on #2666 and #2683 before merging. | +100-11 | 17d |
| #2683 | xiangnuans | fix(core): forward `cause` from the SdkError data slot to Error.cause | shares linked issue #2657 with #2663 | +69-1 | 15d |
| #2703 | likalight | fix(client): put the probe's network failure on Error.cause, not data | shares linked issue #2657 with #2663 | +28-7 | 10d |
| #2726 | LuckTerence | fix(client): surface underlying network error via Error.cause on probe failures (#2657) | shares linked issue #2657 with #2663 | +28-5 | 6d |
Issue #2661 — 2 PRs ⭐ #2662 (Unable to verify: both gh CLI and WebFetch access were blocked in this environment, so I could not retrieve actual CI status, diff sizes, or approach details for either PR. Defaulting to #2662 as the older PR (lower number, likely opened first) per the "oldest" tiebreaker, but this pick is NOT verified against the stated criteria (passing CI > has tests > smallest diff > oldest) and should be re-checked with live data before acting on it.)
| #2662 | app/claude | 1st-reviewtest(node): read SSE streams until expected events arrive instead of assuming one fetch chunk | cluster primary for issue #2661 (2 PRs) | +48-51 | 19d |
| #2707 | mukktinaadh | Fix streamable HTTP SSE tests for Node v26.7.0+ (Fixes #2661) | shares linked issue #2661 with #2662 | +41-7 | 9d |
Issue #740 — 3 PRs ⭐ #2103 (I attempted to pull live GitHub data (gh CLI and WebFetch were both blocked/unauthorized in this environment) so I could not independently verify CI status or test coverage for any of the three PRs — all three remain "CI: unknown" as given. Falling through the stated priority order to the first criterion I can actually verify: diff size. #2103 touches 2 files versus 8 files for both #1691 and #2148, making it the smallest, most focused change addressing #740 (a docs/example addition rather than a broader 8-file feature change). Absent verifiable CI or test-coverage data to break the tie earlier in the priority list, smallest diff is the deciding factor, so #2103 is the recommended keeper. If CI/test data becomes available, this pick should be revisited.)
| #1691 | travisbreaks | feat: add multi-server routing example | shares issue #740; #2103 is the pick | +211-1 | 169d |
| #2103 | lil-goat | 1st-reviewdocs: add multi-server tool routing example | [llm pick] cluster primary for issue #740: I attempted to pull live GitHub data (gh CLI and WebFetch were both blocked/unauthorized in this environment) so I could not independently verify CI status or test coverage for any of the three PRs — all three remain "CI: unknown" as given. Falling through the stated priority order to the first criterion I can actually verify: diff size. #2103 touches 2 files versus 8 files for both #1691 and #2148, making it the smallest, most focused change addressing #740 (a docs/example addition rather than a broader 8-file feature change). Absent verifiable CI or test-coverage data to break the tie earlier in the priority list, smallest diff is the deciding factor, so #2103 is the recommended keeper. If CI/test data becomes available, this pick should be revisited. | +219-0 | 109d |
| #2148 | Nishant-Chaudhary5338 | feat(examples): multi-server chatbot with tool routing (closes #740) | shares linked issue #740 with #1691 | +518-12 | 101d |
Issue #842 — 2 PRs ⭐ #1983 (Both PRs show CI status as unknown, so that criterion doesn't distinguish them, and neither description confirms test coverage. On the remaining tiebreakers, #1983 wins on both: it's the smaller, more focused diff (3 files changed vs. 6 for #2706), and it's the older PR (#1983 < #2706 by PR number, meaning it was opened first). #2706's broader 6-file change to share a drain listener across stdio transport carries more surface area for regressions/merge conflicts than #1983's targeted debounce fix. Recommend keeping #1983 and closing #2706 as a duplicate of #842, but re-verify CI status and test presence on #1983 before merging since that data wasn't available at review time.)
| #1983 | Genmin | 1st-reviewfix(server): debounce list changed notifications | cluster primary for issue #842 (2 PRs) | +50-1 | 125d |
| #2706 | Gursimrxn | fix(stdio): share a single drain listener under backpressure | shares linked issue #842 with #1983 | +250-28 | 9d |
Issue #943 — 2 PRs ⭐ #1978 (Could not verify CI/test/diff details directly (gh and WebFetch tool access was unavailable this session), so ranking relies on the metadata given: both PRs report 3 files changed and CI status unknown — a tie on the first three criteria. The one objective differentiator available is PR number ordering: #1978 was opened before #1984 against the same issue (#943), so by the stated 'oldest' tiebreaker, #1978 is the pick. Recommend re-checking CI/test coverage directly on GitHub before merging, since that data couldn't be confirmed here.)
| #1978 | Genmin | 1st-reviewfix: make in-memory event replay use stored stream ids | cluster primary for issue #943 (2 PRs) | +37-10 | 126d |
| #1984 | Genmin | fix: resume in-memory event streams with underscored ids | shares linked issue #943 with #1978 | +47-17 | 125d |
Semantic: Same base lockfile (pnpm-lock.yaml @ 4baf23d803) has two audit-flagged deps: @hono/node-server (1.19.11) and vite (7.3.0). #1894 (dependabot) bumps @hono/node-server to 1.19.14 and hono to 4.12.14. #2050 pins vite to ^7.3.2. #2089 ('clear high severity audit findings') independently makes the identical @hono/node-server change (specifier ^1.19.9→^1.19.13, version 1.19.11→1.19.14 — byte-identical diff hunk to #1894) AND pins vite to 7.3.2 (same target version as #2050), plus adds resolutions for defu/fast-uri/kysely that neither other PR touches. (3 PRs) — 3 PRs ⭐ #2089 (2089's pnpm-lock.yaml hunk for @hono/node-server is line-for-line identical to 1894's, and its vite pin resolves to the same 7.3.2 target as 2050 — merging any two of these three would produce conflicting or redundant lockfile edits on the same lines. 2089 is the only one of the three that also adds resolutions for defu, fast-uri, and kysely, making it the most complete fix for the stated goal of clearing all high-severity audit findings rather than just one dependency.)
| #1894 | app/dependabot | chore(deps): bump the npm_and_yarn group across 1 directory with 2 updates | [llm] duplicates #2089: Same base lockfile (pnpm-lock.yaml @ 4baf23d803) has two audit-flagged deps: @hono/node-server (1.19.11) and vite (7.3.0). #1894 (dependabot) bumps @hono/node-server to 1.19.14 and hono to 4.12.14. #2050 pins vite to ^7.3.2. #2089 ('clear high severity audit findings') independently makes the identical @hono/node-server change (specifier ^1.19.9→^1.19.13, version 1.19.11→1.19.14 — byte-identical diff hunk to #1894) AND pins vite to 7.3.2 (same target version as #2050), plus adds resolutions for defu/fast-uri/kysely that neither other PR touches. | +27-11 | 139d |
| #2050 | raashish1601 | fix: pin vite to patched version | [llm] duplicates #2089: Same base lockfile (pnpm-lock.yaml @ 4baf23d803) has two audit-flagged deps: @hono/node-server (1.19.11) and vite (7.3.0). #1894 (dependabot) bumps @hono/node-server to 1.19.14 and hono to 4.12.14. #2050 pins vite to ^7.3.2. #2089 ('clear high severity audit findings') independently makes the identical @hono/node-server change (specifier ^1.19.9→^1.19.13, version 1.19.11→1.19.14 — byte-identical diff hunk to #1894) AND pins vite to 7.3.2 (same target version as #2050), plus adds resolutions for defu/fast-uri/kysely that neither other PR touches. | +36-32 | 113d |
| #2089 | ya-nsh | 1st-reviewfix: clear high severity audit findings | [llm] cluster primary: Same base lockfile (pnpm-lock.yaml @ 4baf23d803) has two audit-flagged deps: @hono/node-server (1.19.11) and vite (7.3.0). #1894 (dependabot) bumps @hono/node-server to 1.19.14 and hono to 4.12.14. #2050 pins vite to ^7.3.2. #2089 ('clear high severity audit findings') independently makes the identical @hono/node-server change (specifier ^1.19.9→^1.19.13, version 1.19.11→1.19.14 — byte-identical diff hunk to #1894) AND pins vite to 7.3.2 (same target version as #2050), plus adds resolutions for defu/fast-uri/kysely that neither other PR touches. (3 PRs) | +108-98 | 110d |
Semantic: McpServer unconditionally overwrites the listChanged capability to true when registering tools/resources/prompts, ignoring an explicit listChanged:false set at construction. Both PRs target the v1.x branch (same index.ts base hash 531a559dd5, same @@ -464,7 hunk offset) and land byte-identical mcp.ts changes (target hash cf46173285), showing they implement the same registration-time fix. (2 PRs) — 2 PRs ⭐ #1948 (Both PRs produce an identical resulting mcp.ts (hash cf46173285), so the core registration fix is equivalent between them. #1948 additionally guards sendResourceListChanged/sendToolListChanged/sendPromptListChanged so notifications aren't emitted when the corresponding capability is disabled - a case #1937's diff does not cover - making it the more complete fix for the same v1.x listChanged problem. One gap: #1948's diff shows no .changeset entry, whereas #1937 and #2625 both include one, so that should be added before merging #1948.)
| #1937 | Zelys-DFKH | [v1.x backport] fix(server): respect explicit listChanged: false in McpServer | [llm] duplicates #1948: McpServer unconditionally overwrites the listChanged capability to true when registering tools/resources/prompts, ignoring an explicit listChanged:false set at construction. Both PRs target the v1.x branch (same index.ts base hash 531a559dd5, same @@ -464,7 hunk offset) and land byte-identical mcp.ts changes (target hash cf46173285), showing they implement the same registration-time fix. | +102-4 | 134d |
| #1948 | paulelliotco | 1st-reviewfix: respect disabled listChanged capabilities on v1.x | [llm] cluster primary: McpServer unconditionally overwrites the listChanged capability to true when registering tools/resources/prompts, ignoring an explicit listChanged:false set at construction. Both PRs target the v1.x branch (same index.ts base hash 531a559dd5, same @@ -464,7 hunk offset) and land byte-identical mcp.ts changes (target hash cf46173285), showing they implement the same registration-time fix. (2 PRs) | +221-9 | 131d |
Semantic: Both patch the exact same bug at the exact same location in src/client/streamableHttp.ts: the SSE reader obtained via .getReader() around line 328 is never released, leaking a ~50MB reader-tied buffer per long-lived client connection. Both wrap the identical read loop (`while (true) { const { value: event, done } = await reader.read(); ... }`) in a try block so the lock can be released when the loop exits. (2 PRs) — 2 PRs ⭐ #1998 (Same fix, smaller footprint: PR #1998's hunk is @@ -328,40 +328,44 @@ (net +4 lines) versus PR #1961's @@ -328,40 +328,47 @@ (net +7 lines) for the identical loop, so #1998 reaches the same reader.releaseLock()-on-exit behavior with less code changed and less surface area for merge conflicts. Its changeset note also explicitly scopes the fix to both exit paths ('graceful closes or read errors'), matching what a bare try/finally actually covers, while #1961's note only mentions the disconnect path.)
| #1961 | MukundaKatta | fix(client/sse): release reader lock on disconnect to prevent ~50MB leak | [llm] duplicates #1998: Both patch the exact same bug at the exact same location in src/client/streamableHttp.ts: the SSE reader obtained via .getReader() around line 328 is never released, leaking a ~50MB reader-tied buffer per long-lived client connection. Both wrap the identical read loop (`while (true) { const { value: event, done } = await reader.read(); ... }`) in a try block so the lock can be released when the loop exits. | +100-27 | 129d |
| #1998 | Genmin | 1st-reviewfix(client): release SSE reader locks | [llm] cluster primary: Both patch the exact same bug at the exact same location in src/client/streamableHttp.ts: the SSE reader obtained via .getReader() around line 328 is never released, leaking a ~50MB reader-tied buffer per long-lived client connection. Both wrap the identical read loop (`while (true) { const { value: event, done } = await reader.read(); ... }`) in a try block so the lock can be released when the loop exits. (2 PRs) | +111-27 | 124d |
Semantic: Streamable HTTP JSON response mode rejects requests whose Accept header only lists 'application/json' (without also listing 'text/event-stream'), returning a 406 error. Both PRs relax the same Accept-header validation check in webStandardStreamableHttp.ts. (2 PRs) — 2 PRs ⭐ #1996 (Both patch the identical validation block in webStandardStreamableHttp.ts, but #1996 implements a dedicated acceptsMediaType() helper that does proper media-type negotiation (splits on ';' params, honors q=0 exclusion, normalizes case/whitespace, supports wildcard subtypes), whereas #2046 uses a plain acceptHeader.includes('application/json') substring check that does not account for q=0 (a client explicitly declining JSON would still pass) or parameterized/whitespace variants. #1996's approach handles a strict superset of the cases #2046 covers, so it is the one to keep; #2046 should be closed as covered by #1996.)
| #1996 | Genmin | 1st-reviewfix(server): allow JSON Accept in JSON response mode | [llm] cluster primary: Streamable HTTP JSON response mode rejects requests whose Accept header only lists 'application/json' (without also listing 'text/event-stream'), returning a 406 error. Both PRs relax the same Accept-header validation check in webStandardStreamableHttp.ts. (2 PRs) | +89-8 | 124d |
| #2046 | raashish1601 | fix: accept JSON-only Accept in streamable JSON mode | [llm] duplicates #1996: Streamable HTTP JSON response mode rejects requests whose Accept header only lists 'application/json' (without also listing 'text/event-stream'), returning a 406 error. Both PRs relax the same Accept-header validation check in webStandardStreamableHttp.ts. | +37-8 | 113d |
Semantic: Both fix trailing-slash handling when building OAuth discovery well-known paths (buildWellKnownPath/buildDiscoveryUrls), stripping trailing slash(es) from the pathname to avoid malformed discovery URLs. (2 PRs) — 2 PRs ⭐ #2215 (#2214 changes buildWellKnownPath/buildDiscoveryUrls to strip trailing slashes via regex but leaves shouldAttemptFallback's root check as `pathname === '/'`; after normalization a root path becomes '' rather than '/', so that check would stop matching and silently reintroduce a redundant fallback request it was meant to prevent. #2215 makes the equivalent stripping fix through a shared normalizeDiscoveryPath() helper and also updates shouldAttemptFallback to check `pathname === ''`, keeping the root short-circuit correct — a strict superset of #2214's change with no regression.)
| #2214 | raashish1601 | authchore(client): normalize trailing slashes in discovery paths | [llm] duplicates #2215: Both fix trailing-slash handling when building OAuth discovery well-known paths (buildWellKnownPath/buildDiscoveryUrls), stripping trailing slash(es) from the pathname to avoid malformed discovery URLs. | +31-9 | 94d |
| #2215 | raashish1601 | 1st-reviewauthfix(client): avoid redundant fallback on root-like discovery paths | [llm] cluster primary: Both fix trailing-slash handling when building OAuth discovery well-known paths (buildWellKnownPath/buildDiscoveryUrls), stripping trailing slash(es) from the pathname to avoid malformed discovery URLs. (2 PRs) | +67-12 | 94d |
Semantic: Both bump the pnpm/action-setup GitHub Action pin in conformance.yml and deploy-docs.yml from v5.0.0 to a v6.x release — same dependency, same files, same underlying 'outdated pnpm/action-setup' issue, just two different target patch versions opened close together (likely by automated dependency updates). (2 PRs) — 2 PRs ⭐ #2635 (Targets pnpm/action-setup v6.0.10, a strictly newer patch release than #2301's v6.0.9, against the same v5.0.0 baseline in the same two workflow files (conformance.yml, deploy-docs.yml). Merging #2635 makes #2301 a no-op/redundant bump.)
| #2301 | app/dependabot | chore(deps): bump pnpm/action-setup from 5.0.0 to 6.0.9 | [llm] duplicates #2635: Both bump the pnpm/action-setup GitHub Action pin in conformance.yml and deploy-docs.yml from v5.0.0 to a v6.x release — same dependency, same files, same underlying 'outdated pnpm/action-setup' issue, just two different target patch versions opened close together (likely by automated dependency updates). | +12-12 | 78d |
| #2635 | app/dependabot | 1st-reviewchore(deps): bump pnpm/action-setup from 5.0.0 to 6.0.10 | [llm] cluster primary: Both bump the pnpm/action-setup GitHub Action pin in conformance.yml and deploy-docs.yml from v5.0.0 to a v6.x release — same dependency, same files, same underlying 'outdated pnpm/action-setup' issue, just two different target patch versions opened close together (likely by automated dependency updates). (2 PRs) | +12-12 | 22d |
Semantic: Both fix WebStandardStreamableHTTPServerTransport.close() leaving a pending JSON-response-mode POST's handleRequest() Promise<Response> unresolved, so the HTTP request hangs until the platform's own timeout instead of being settled when the transport closes. (2 PRs) — 2 PRs ⭐ #2692 (#2692 settles each outstanding request id with a JSON-RPC -32000 'Connection closed' error and explicitly groups outstanding ids by stream to handle batched POSTs, reusing an id's already-computed real response instead of overwriting it with an error. #2600's changeset describes a flat 404 'Session not found' response for parked POSTs with no mention of per-id/batch handling, and also bundles in an unrelated change (clearing _requestToStreamMapping / re-checking correlation after eventStore.storeEvent() to fix a separate leak), which increases the diff's blast radius and overlaps the same close() code path as #2692, making the two mutually conflicting.)
| #2600 | rxits | fix(server): retire in-flight request state when the streamable HTTP transport closes | [llm] duplicates #2692: Both fix WebStandardStreamableHTTPServerTransport.close() leaving a pending JSON-response-mode POST's handleRequest() Promise<Response> unresolved, so the HTTP request hangs until the platform's own timeout instead of being settled when the transport closes. | +130-4 | 31d |
| #2692 | retif | 1st-reviewfix(server): settle pending JSON-mode responses when the streamable HTTP transport closes | [llm] cluster primary: Both fix WebStandardStreamableHTTPServerTransport.close() leaving a pending JSON-response-mode POST's handleRequest() Promise<Response> unresolved, so the HTTP request hangs until the platform's own timeout instead of being settled when the transport closes. (2 PRs) | +171-0 | 12d |
3 SLA2 auth needs-decision (4) — Maintainer discussed but hasn't approved or requested changes yet.
| #2448 | mattzcarey | maintainerauthfix(client): preserve scopes across authorization retries | maintainer COMMENTED but took no stance | +437-37 | 56d |
| #1624 | SamMorrowDrums | authfeat(server): add request-time OAuth scope challenges | maintainer COMMENTED but took no stance | +1148-106 | 181d |
| #1717 | travisbreaks | re-reviewfeat(core): add opt-in periodic ping for connection health monitoring | maintainer COMMENTED but took no stance | +383-1 | 166d |
| #2595 | MathurAditya724 | re-reviewfeat(hono): add mcp() middleware to serve an McpServer in one call | maintainer COMMENTED but took no stance | +346-32 | 32d |
6 SLA1 auth backport-follows-primary (6) — v1.x sibling of a main-branch PR. Review together — backport diff is usually mechanical.
| #1083 | mgyarmathy | 1st-review[v1.x] fix: Update UriTemplate implementation to handle optional/omitted, out-of-order, and encoded query parameters | follows #2429 (same issue #1079, different branch) | +164-11 | 300d |
| #1520 | LucaButBoring | 1st-review[1.x] fix(client): retry SSE stream after receiving session ID | follows #1521 | +419-0 | 203d |
| #1926 | tonxxd | 1st-reviewfix(sse): escape U+2028 / U+2029 in SSE data lines (V1) | follows #1925 | +61-2 | 137d |
| #2461 | app/claude | 1st-reviewauthfix(auth): treat null optional fields in token responses as absent | follows #2462 | +311-6 | 56d |
| #2587 | axits-lab | 1st-reviewfix(server): fire onsessionclosed once when DELETEs overlap (v1.x) | follows #2583 | +69-1 | 33d |
| #2588 | axits-lab | 1st-reviewfix(server): settle in-flight JSON-mode requests on transport close (v1.x) | follows #2584 | +98-0 | 33d |
Intake (135) ⊕ ⊖
PRs not yet reviewed by a maintainer. Oldest first.
121 SLA18 auth needs-first-review (130) — Not yet reviewed by a maintainer.
| #1889 | app/dependabot | 1st-reviewchore(deps): bump actions/upload-pages-artifact from 4 to 5 | 141d | +1-1 | 141d |
| #1911 | langverse2023 | 1st-reviewfix(express): add CJS exports to resolve ERR_PACKAGE_PATH_NOT_EXPORTED | 139d | +7-3 | 139d |
| #1923 | billyriaz | 1st-reviewauthfix: accept null introspection_endpoint in OAuthMetadataSchema | 137d | +1-1 | 138d |
| #1925 | tonxxd | 1st-reviewfix(server): escape U+2028 / U+2029 in SSE data lines (v2) | 137d | +59-1 | 137d |
| #1932 | ameenalkhaldi | 1st-reviewfix(core): skip cancellation notification for initialize requests | 135d | +79-13 | 135d |
| #1933 | Jim1874 | 1st-reviewauthfix(client): prevent duplicate Auth headers in SSE transport | 135d | +8-1 | 135d |
| #1935 | Jim1874 | 1st-reviewfix(server): handle undefined args in prompts handler | 135d | +8-1 | 135d |
| #1940 | harshkatakwar | 1st-reviewfeat: add beforeToolCall and afterToolCall lifecycle hooks to McpServer | 133d | +451-24 | 133d |
| #1945 | bokelley | 1st-reviewfix(client): skip outputSchema validation when result is an error | 133d | +153-3 | 132d |
| #1949 | Zelys-DFKH | 1st-reviewfix(core): allow extra JSON Schema keywords on elicitation primitive schemas | 131d | +104-25 | 131d |
| #1951 | Zelys-DFKH | 1st-reviewauthfix(client): preserve resource_metadata URL across non-Bearer WWW-Authenticate challenges | 131d | +160-22 | 131d |
| #1953 | Jim1874 | 1st-reviewfix(server): disable listChanged capability in V1x protocol mode (closes #1819) | 131d | +47-2 | 131d |
| #1958 | mhegazy | 1st-reviewauthfix(client/auth): use .set() for prompt=consent instead of .append() to avoid duplicating | 130d | +22-1 | 130d |
| #1966 | MukundaKatta | 1st-reviewfix(server): return Tool Execution Errors for input validation failures (SEP-1303) | 128d | +154-8 | 128d |
| #1967 | MukundaKatta | 1st-reviewauthdocs(examples): add external auth resource server example (closes #658) | 128d | +361-0 | 128d |
| #1969 | nanookclaw | 1st-reviewfix: handle 404 and 406 gracefully in SSE stream initialization | 127d | +5-3 | 127d |
| #1971 | MukundaKatta | 1st-reviewfix(server): handle ZodObject in RegisteredTool.update (#1960) | 127d | +77-6 | 127d |
| #1972 | MukundaKatta | 1st-reviewauthfix(auth): preserve resource URI without trailing slash (#1968) | 127d | +78-13 | 127d |
| #1982 | Genmin | 1st-reviewfix: enforce monotonic progress notifications | 125d | +86-7 | 125d |
| #1985 | Genmin | 1st-reviewfix: align zod object schemas with stripped properties | 125d | +36-1 | 125d |
| #1986 | Genmin | 1st-reviewfix: avoid duplicate SSE close callbacks | 125d | +42-2 | 125d |
| #1990 | Genmin | 1st-reviewfix(server): accept structurally compatible Zod v4 schemas | 125d | +57-6 | 125d |
| #1995 | Genmin | 1st-reviewfix(server): surface stateless transport reuse errors | 124d | +75-1 | 124d |
| #1997 | Genmin | 1st-reviewauthfix(server): validate OAuth code redirect URI | 124d | +210-16 | 124d |
| #1999 | Genmin | 1st-reviewfix: preserve elicit string pattern constraints | 124d | +24-1 | 124d |
| #2000 | Genmin | 1st-reviewFix invalid JSON-RPC request errors | 124d | +105-9 | 124d |
| #2001 | Genmin | 1st-reviewfix(server): validate wrapped output schemas on v1 | 124d | +78-3 | 124d |
| #2010 | aayushbaluni | 1st-reviewfix: detect plain JSON Schema objects in tool() overload resolution | 123d | +335-2 | 123d |
| #2014 | fengfeng-zi | 1st-reviewfix(core): remove duplicate zod dependency declaration | 121d | +6-2 | 121d |
| #2015 | morozow | 1st-reviewfeat(tasks): add task streaming with partial result notifications | 120d | +3021-7 | 120d |
| #2017 | ankitvirdi4 | 1st-reviewfix(server): preserve inputSchema for z.discriminatedUnion / z.union | 120d | +179-14 | 120d |
| #2026 | Zelys-DFKH | 1st-reviewtest(@modelcontextprotocol/node): cover pre-read body pattern in stateless mode | 118d | +71-8 | 118d |
| #2027 | app/github-actions | 1st-reviewchore: update spec.types.ts from upstream | 118d | +16-3 | 118d |
| #2030 | cyphercodes | 1st-reviewfix: add root package export barrel | 117d | +19-0 | 117d |
| #2039 | navalerakesh | 1st-reviewfix: use constant-time comparison for session ID validation | 115d | +23-1 | 115d |
| #2043 | ChrisJr404 | 1st-reviewfix(client): add missing Windows env vars to DEFAULT_INHERITED_ENV_VARS | 113d | +42-2 | 113d |
| #2044 | raashish1601 | 1st-reviewfix: replay in-memory events for underscore stream ids | 113d | +37-2 | 113d |
| #2045 | raashish1601 | 1st-reviewfix: accept omitted optional prompt and tool arguments | 113d | +114-2 | 113d |
| #2079 | Zelys-DFKH | 1st-reviewfix(test): extend cloudflare workers retry to cover full request cycle | 112d | +27-8 | 112d |
| #2080 | Jefsky | 1st-reviewfix(server): preserve icons in registerPrompt() | 111d | +12-1 | 111d |
| #2085 | rsalus | 1st-review[v1.x] fix(server): emit JSON Schema 2020-12 in tools/list (SEP-1613) | 111d | +87-2 | 111d |
| #2091 | RomKadria | 1st-reviewfix(node): reuse getRequestListener instead of creating one per request | 110d | +22-27 | 110d |
| #2092 | bishnubista | 1st-reviewauthfix(client,core): tighten OAuth PRM resource validation per RFC 8707 §2 | 110d | +147-4 | 110d |
| #2102 | pragnyanramtha | 1st-reviewPass request context to completion callbacks | 109d | +173-11 | 109d |
| #2104 | pragnyanramtha | 1st-reviewfix(server): allow streamable HTTP JSON without content type | 109d | +49-23 | 109d |
| #2105 | pragnyanramtha | 1st-reviewfix: tighten request handler result types on v1.x | 109d | +295-40 | 109d |
| #2106 | pragnyanramtha | 1st-reviewfix: validate wrapped Zod output schemas | 109d | +54-2 | 109d |
| #2107 | pragnyanramtha | 1st-reviewfix: accept omitted prompt arguments | 109d | +59-1 | 109d |
| #2109 | leehpham | 1st-reviewfix(server): derive standalone SSE streamId per-session to prevent EventStore collisions | 108d | +76-1 | 108d |
| #2111 | dparikh79 | 1st-reviewfix(server): reject initialize with mismatched MCP-Protocol-Version header | 108d | +82-0 | 108d |
| #2114 | pragnyanramtha | 1st-reviewfix(server): track renamed registered item keys | 108d | +104-16 | 108d |
| #2136 | malventano | 1st-reviewfix: resetTimeoutOnProgress does nothing without onprogress callback | 104d | +10-6 | 104d |
| #2152 | fallintoplace | 1st-reviewfix(server): replay request SSE responses after closeSSEStream | 100d | +180-20 | 100d |
| #2154 | cyq1017 | 1st-reviewAlign Streamable HTTP onclose type with Transport contract | 100d | +14-3 | 100d |
| #2159 | cogeor | 1st-reviewfix(server): emit object schema for wrapped Zod inputs in tools/list | 98d | +149-13 | 98d |
| #2168 | jstar0 | 1st-reviewfix(server): guard no-schema tool handler signatures | 96d | +19-0 | 96d |
| #2171 | FU-max-boop | 1st-reviewauthContinue OAuth discovery on non-JSON metadata responses | 96d | +27-4 | 96d |
| #2174 | FU-max-boop | 1st-reviewAllow streamable HTTP transport restart after close | 96d | +24-4 | 96d |
| #2418 | pablopupo | 1st-reviewfix(client): fire onerror only once when the standalone GET stream fails | 61d | +136-14 | 61d |
| #2429 | vivekjm | 1st-reviewfix: match optional URI template query params | 61d | +59-9 | 61d |
| #2436 | KlyneChrysler | 1st-reviewauthfix(client): decompress gzip token response bodies in oauth flows | 58d | +134-2 | 58d |
| #2438 | Grmiade | 1st-reviewfix: type registerTool output from outputSchema | 57d | +107-37 | 57d |
| #2462 | app/claude | 1st-reviewauthfix(auth): treat null optional fields in token responses as absent | 56d | +506-20 | 56d |
| #2467 | chakshu-dhannawat | 1st-reviewfix(server): honor Zod v4 toJSONSchema output semantics to match raw structuredContent | 55d | +102-2 | 55d |
| #2481 | SnowSky1 | 1st-reviewfix(server): parse Accept media types exactly | 51d | +145-5 | 51d |
| #2490 | morluto | 1st-reviewfix(server): reject userinfo in Origin and Host headers | 50d | +63-6 | 50d |
| #2492 | earfman | 1st-reviewAnswer -32602 Invalid params for schema-invalid spec-method requests | 50d | +65-13 | 50d |
| #2500 | rohitjio4g3540-arch | 1st-reviewAdd SLSA generic generator workflow | 49d | +66-0 | 49d |
| #2503 | VihaanAgarwal | 1st-reviewauthfix(client): don't match WWW-Authenticate field names inside longer param names | 48d | +29-1 | 48d |
| #2509 | vishnujayvel | 1st-reviewfix(client): seed SSE resumption tracker from resumptionToken (#2499) | 47d | +62-1 | 47d |
| #2517 | pradeep-ramola | 1st-reviewFix streamable HTTP SSE exhaustion | 45d | +197-18 | 45d |
| #2519 | lntutor | 1st-reviewfix(client): thread onresumptiontoken and onRequestStreamEnd through the send() resume path | 45d | +59-1 | 45d |
| #2522 | Srinu0342 | 1st-reviewfix(server): tag list_changed notifications with the in-flight request id | 43d | +218-5 | 43d |
| #2524 | app/dependabot | 1st-reviewchore(deps): bump actions/setup-node from 6 to 7 | 43d | +12-12 | 43d |
| #2535 | tylergibbs1 | 1st-reviewauthfix(client): accept form-encoded token responses | 41d | +37-1 | 41d |
| #2540 | piyushbag | 1st-reviewfix(stdio): release ReadBuffer backing after final byte | 40d | +17-1 | 40d |
| #2546 | mturac | 1st-reviewdocs: validate input-required wipe-cache responses | 39d | +45-26 | 39d |
| #2550 | arimu1 | 1st-reviewfix(server): throw when resource subscribe capability is missing | 38d | +67-2 | 38d |
| #2552 | ondraulehla | 1st-reviewfix(client): reject stdio send() when the write fails instead of waiting for 'drain' | 37d | +53-4 | 37d |
| #2554 | colinaaa | 1st-reviewfix(server): leave SSE connection policy to adapters | 37d | +11-6 | 37d |
| #2556 | app/claude | 1st-reviewfix(core-internal): make zod toJSONSchema conversion wire-truthful for tool schemas | 36d | +3509-32 | 36d |
| #2567 | patrickswedish | 1st-reviewfix(examples): resume streams whose IDs contain underscores | 36d | +45-6 | 36d |
| #2570 | kocaemre | 1st-reviewfix: avoid DOM-only HeadersInit in v1 declarations | 35d | +9-4 | 35d |
| #2571 | app/claude | 1st-reviewfix(client): fall back to initialize when the discover probe gets a completed non-modern answer | 35d | +831-72 | 35d |
| #2572 | coding-bobo | 1st-reviewauthfeat(client): SEP-1933 workload identity federation via the jwt-bearer grant | 35d | +1419-17 | 35d |
| #2574 | ANcpLua | 1st-reviewfix(node): widen @hono/node-server past GHSA-frvp-7c67-39w9 | 35d | +40-25 | 35d |
| #2582 | axits-lab | 1st-reviewfix(codemod): keep a file's leading comment block above rewritten imports | 33d | +118-0 | 33d |
| #2585 | katayama8000 | 1st-reviewdocs(core): note that the protocol version constants are legacy-era only | 33d | +25-0 | 33d |
| #2586 | qiushui7 | 1st-reviewfix(protocol): ignore late progress for recently completed tokens | 33d | +202-5 | 33d |
| #2596 | siddheshbandgar | 1st-reviewfeat(client/stdio): opt-in process-tree teardown on close() | 32d | +97-2 | 32d |
| #2599 | freya0926 | 1st-reviewfix(core-internal): let explicit-schema handlers/calls escape the era-universe gate | 31d | +146-31 | 31d |
| #2601 | appflowsolution | 1st-reviewfix: register google-duration format to silence unknown format warnings | 31d | +21-0 | 31d |
| #2603 | javier20dev25 | 1st-reviewPin GitHub Actions to immutable SHAs | 30d | +29-29 | 30d |
| #2610 | hamzashah-dev | 1st-reviewfix(server): install createMcpHandler's onclose hook once per instance | 30d | +73-6 | 30d |
| #2616 | app/claude | 1st-reviewfix(client): abort legacy SSE reconnect chain when the originating request times out | 27d | +2685-310 | 27d |
| #2618 | harshasiddartha | 1st-reviewfix(client): keep tool metadata intact when a listTools() refresh fails (v1.x) | 27d | +97-6 | 27d |
| #2620 | rajanpanth | 1st-reviewfix(client): fall back to legacy when the negotiation probe answer is an unusable 2xx | 26d | +192-0 | 26d |
| #2621 | dielduarte | 1st-reviewfix(server): thread responseMode into the legacy stateless fallback | 26d | +132-7 | 26d |
| #2625 | LizunovSergey | 1st-reviewfix(server): preserve explicit tool listChanged capability | 24d | +57-2 | 24d |
| #2630 | gbshankar | 1st-reviewfeat(server): add DPoP (RFC 9449) proof validation | 23d | +1858-23 | 23d |
| #2632 | ousamabenyounes | 1st-reviewfix: add root src/index.ts so the advertised root export resolves (#2273) | 23d | +58-0 | 23d |
| #2633 | nyxst4ck | 1st-reviewfix(core-internal): percent-encode multi-variable URI template expansions | 23d | +18-1 | 23d |
| #2638 | latent-9 | 1st-reviewfix(client): treat a JSON-RPC error response as a terminal response | 22d | +64-2 | 22d |
| #2642 | app/claude | 1st-reviewfix(client): stop listen() rejections escaping as unhandledRejection during an in-flight send | 22d | +137-10 | 22d |
| #2644 | app/claude | 1st-reviewauthfix(client): make streamable HTTP auth awaits abortable by requestSignal | 22d | +586-69 | 22d |
| #2645 | app/claude | 1st-reviewfix(client): bound McpSubscription.close()'s wait on the cancelled-notification send | 22d | +105-2 | 22d |
| #2653 | amitfin | 1st-reviewfix: default Zod v4 JSON Schema target to draft-2020-12 | 20d | +88-2 | 20d |
| #2660 | Azazi | 1st-reviewfix(client): treat HTTP 404 with session ID as session expiry | 19d | +201-6 | 19d |
| #2667 | edenbuilds | 1st-reviewfix(client): preserve Streamable HTTP request provenance | 17d | +308-8 | 17d |
| #2669 | ez-lbz | 1st-reviewfix(server): reject DELETE requests in stateless streamable HTTP mode | 16d | +31-0 | 16d |
| #2678 | yigiterturk-dev | 1st-reviewfix(core): surface protocol errors when no onerror handler is set | 15d | +53-1 | 15d |
| #2681 | app/dependabot | 1st-reviewchore(deps): bump changesets/action from 1.9.0 to 2.1.0 | 15d | +2-2 | 15d |
| #2684 | app/claude | 1st-reviewfix(client): persist SSE reconnection attempt count across idle-close cycles | 15d | +727-60 | 15d |
| #2687 | uczltw6 | 1st-reviewfix(core): merge request headers case-insensitively | 14d | +32-1 | 14d |
| #2688 | tandede | 1st-reviewfix(client): serialize response cache invalidation | 13d | +137-22 | 13d |
| #2690 | mrpmohiburrahman | 1st-reviewfix(server): enforce Mcp-Param-* parity for numbers the header codec cannot represent | 13d | +107-8 | 13d |
| #2694 | sainikhiljuluri | 1st-reviewfix(server): honour enabled on resource templates | 12d | +193-8 | 12d |
| #2702 | johnhenry | 1st-reviewfix(exports): resolve .js subpath imports to real declaration files | 10d | +95-0 | 10d |
| #2708 | OllieinCanada | 1st-reviewfix(client): pin output schema for in-flight tool calls (v1.x) | 9d | +79-2 | 9d |
| #2709 | BerkantACUN | 1st-reviewdocs: NodeStreamableHTTPServerTransport's own examples now show DNS rebinding protection | 8d | +64-0 | 8d |
| #2710 | VedantMadane | 1st-reviewfix: normalize paramsSchema in RegisteredTool.update | 8d | +1-1 | 8d |
| #2720 | app/claude | authfix(client): send the scope parameter on refresh-token requests | 7d | +212-2 | 7d |
| #2725 | teddiesloco | fix(transport): validate redirect targets to prevent SSRF and protocol confusion (#2700) | 6d | +234-12 | 6d |
| #2727 | FenjuFu | docs: explain v1 empty inputSchema / `_def` crash from z.object() raw-shape misuse | 6d | +33-0 | 6d |
| #2729 | app/claude | authdocs(client): correct the registerClient deprecation citation to spec PR #2858 | 6d | +20-6 | 6d |
| #2731 | jinghuan-Chen | docs(subscriptions): fix client HTTP URL to point at /mcp endpoint | 6d | +1-1 | 6d |
| #2732 | xianjianlf2 | fix(core): decode URI template match values | 6d | +33-1 | 6d |
| #2734 | app/claude | authfix(client): validate discovered AS metadata by document shape, not well-known path | 5d | +457-13 | 5d |
| #2741 | 0717lee | fix(client): follow repeated opaque cursors in the list auto-aggregate walk | 3d | +108-7 | 3d |
| #2744 | andriyor | chore(deps): update eventsource to ^4.1.1, eventsource-parser to ^3.1.1 | 0d | +23-15 | 0d |
4 SLA1 auth community-reviewed (5) — Community members have reviewed, but no maintainer has engaged yet.
| #1870 | techtoboggan | 1st-reviewfix: inject progressToken when resetTimeoutOnProgress is set (not only onprogress) | 145d, reviewed by travisbreaks (SLA breach) | +4-2 | 145d |
| #2028 | sfrangulov | 1st-reviewfix(client): stop propagating transport AbortController to POST/DELETE | 118d, reviewed by HarperZ9, StantonMatt (SLA breach) | +82-6 | 118d |
| #2544 | GhagSagar23 | 1st-reviewauthFix tests timing out during interactive OAuth flow (#2510) | 39d, reviewed by gnanirahulnutakki (SLA breach) | +380-127 | 40d |
| #2634 | uuzzrm | 1st-reviewfix(server): validate low-level tool inputs | 23d, reviewed by pacocartones (SLA breach) | +321-93 | 23d |
| #2724 | YatsukBogdan1 | fix(server): keep the registry key current when a handle is renamed | 6d, reviewed by koriyoshi2041 | +154-3 | 6d |
Hygiene (14) ⊕ ⊖
Batchable procedural ops — pings, rebases, peer reviews.
2 auth stale-awaiting-author (13) — Changes requested over two weeks ago with no author response.
| #1776 | KKonstantinov | v2 remove console warns on middleware | 152d since feedback | +135-116 | 159d |
| #1283 | evalstate | Fix/onprogress error handling | 154d since feedback | +23-1 | 265d |
| #1493 | TheodorNEngoy | hono: add maxBodyBytes guard for JSON parsing | 155d since feedback | +88-3 | 206d |
| #1496 | TheodorNEngoy | server: add maxBodyBytes guard to WebStandardStreamableHTTPServerTransport | 155d since feedback | +132-2 | 206d |
| #1500 | TheodorNEngoy | ci: retry pkg-pr-new publish on transient 5xx | 155d since feedback | +30-3 | 206d |
| #1664 | Vadaski | fix: surface input validation errors for task-augmented tool calls | 158d since feedback | +107-0 | 174d |
| #1666 | Vadaski | fix: allow registering tools/resources/prompts after connect when capabilities pre-declared (#893) | 152d since feedback | +218-19 | 174d |
| #1669 | Vadaski | authfix: include scope parameter in OAuth authorization code token exchange | 155d since feedback | +122-6 | 174d |
| #1681 | meirk-brd | fix(server): stop replay cleanly when streamable HTTP replay stream c… | 158d since feedback | +131-23 | 171d |
| #1813 | Aboudjem | authfix(auth): deduplicate concurrent token refresh requests | 152d since feedback | +386-0 | 156d |
| #1854 | haydenrear | Added default mcp tool call timeout from env | 145d since feedback | +133-2 | 149d |
| #1865 | pch007 | fix(server): handle ZodEffects in normalizeObjectSchema and getObjectShape | 145d since feedback | +246-0 | 146d |
| #2150 | he-yufeng | fix: reinitialize expired streamable sessions | author self-diagnosed CI 17d ago, never fixed | +182-62 | 100d |
ci-red-silent (1) — CI failing, not yet flagged to the author.
| #2611 | octo-patch | Add MiniMax provider to the cli-client example host | red CI 29d | +103-9 | 29d |
Close candidates (13) ⊕ ⊖
Likely to be closed — inactive, stale, or needing more context. Reviewed before closing.
1 auth stale-ci-abandoned (12) — CI has been failing for over a month with no activity.
| #2421 | felixweinberger | fix(server): restore v1 transport lifecycle parity: single-use stateless transports, fail-fast on double connect | red CI 61d, no activity | +1479-260 | 61d |
| #1335 | LucaButBoring | [v1.x] Fix registerToolTask's getTask and getTaskResult handlers not being invoked | red CI 252d, no activity | +311-167 | 252d |
| #1878 | dagangtj | feat(hono): add generic Env type support to createMcpHonoApp | red CI 143d, no activity | +68-3 | 143d |
| #1884 | vrv | Reject standalone GET in stateless streamable HTTP mode | red CI 142d, no activity | +11-0 | 142d |
| #1963 | MukundaKatta | feat(client): add idle timeout to SSE stream reader | red CI 128d, no activity | +192-0 | 128d |
| #1964 | MukundaKatta | feat(deps): make HTTP/SSE transport deps optional for stdio-only consumers | red CI 128d, no activity | +154-13 | 128d |
| #1965 | MukundaKatta | feat(client): honor Retry-After on HTTP 429 responses | red CI 128d, no activity | +383-8 | 128d |
| #2019 | blackwell-systems | fix: check AbortSignal in handleAutomaticTaskPolling to stop cancelled requests | red CI 120d, no activity | +8-0 | 120d |
| #2118 | nielskaspers | authdocs(client): clarify private_key_jwt reserved-claim behavior | red CI 107d, no activity | +7-0 | 107d |
| #2122 | he-yufeng | fix(server): reject requests before initialization | red CI 106d, no activity | +86-4 | 106d |
| #2178 | he-yufeng | fix(client): send MCP standard POST headers | red CI 96d, no activity | +135-0 | 96d |
| #2488 | utkarshsharma19 | fix(server): reply to invalid stdio JSON-RPC frames | red CI 50d, no activity | +146-14 | 50d |
pre-ci-ghost (1) — Over 90 days old and CI never ran.
| #1627 | nielskaspers | docs(server): add unit testing guide using InMemoryTransport | CI never ran, 181d old | +110-3 | 181d |
Not our move (38) ⊕ ⊖
Clock is on the author or blocked externally. No action owed today.
2 auth stale-draft (28) — Draft with no activity for over a week.
| #872 | LucaButBoring | feat: use informative user agent in HTTP requests | draft idle 385d | +407-142 | 385d |
| #1169 | domdomegg | fix: allow any JSON Schema type for outputSchema | draft idle 280d | +6-17 | 280d |
| #1416 | maxisbey | ci: use conformance composite action | draft idle 223d | +68-41 | 223d |
| #2096 | MukundaKatta | authdocs(client): clarify private_key_jwt custom claim precedence | draft idle 109d | +37-2 | 109d |
| #2158 | SamMorrowDrums | SEP-2792: Reference implementation for per-request language negotiation | draft idle 98d | +2010-116 | 98d |
| #2474 | Sammy-Dabbas | fix(server): reject duplicate in-flight request ids, v1.x backport of #2434 | draft idle 54d | +254-0 | 54d |
| #2495 | app/claude | fix: stop shipping declaration source maps that reference unshipped src/ | draft idle 49d | +154-9 | 49d |
| #2506 | MustafaKemal0146 | fix(packaging): exclude examples from v1 package artifacts | draft idle 47d | +76-2 | 47d |
| #2520 | lntutor | fix(client): validate Content-Type on GET/resume SSE responses | draft idle 44d | +43-0 | 44d |
| #2521 | lntutor | fix(core): send an error response when a request handler rejects with a nullish reason | draft idle 44d | +37-3 | 44d |
| #2527 | app/claude | Add experimental Server Card extension support (SEP-2127) | draft idle 43d | +4116-16 | 43d |
| #2533 | pradeep-ramola | test(server): cover non-object output schemas | draft idle 42d | +226-3 | 42d |
| #2578 | krubenok | Add app-rendered elicitation MRTR example | draft idle 34d | +280-0 | 34d |
| #2579 | ondraulehla | fix(server): handle stdout errors in StdioServerTransport (v1.x backport of #1568) | draft idle 34d | +130-3 | 34d |
| #2583 | axits-lab | fix(server): fire onsessionclosed once when DELETEs overlap | draft idle 33d | +48-1 | 33d |
| #2584 | axits-lab | fix(server): settle in-flight JSON-mode requests on transport close | draft idle 33d | +70-0 | 33d |
| #2597 | arimu1 | authfix(client): treat *.localhost as loopback for OAuth token endpoints | draft idle 32d | +42-22 | 32d |
| #2606 | rxits | fix(server): answer a close() during the priming write as Session not… | draft idle 30d | +85-4 | 30d |
| #2609 | rxits | fix(server): tear down the request stream when an event store write rejects | draft idle 30d | +74-1 | 30d |
| #2631 | gbshankar | Feat/dpop server conformance fixture | draft idle 23d | +1963-17 | 23d |
| #2649 | LizunovSergey | fix(core): keep resumption options off cancellation notifications | draft idle 21d | +31-1 | 21d |
| #2670 | ez-lbz | fix(server): reject JSON-RPC batch requests in streamable HTTP transport | draft idle 16d | +86-71 | 16d |
| #2671 | ez-lbz | feat(server): limit streamable HTTP request body size | draft idle 16d | +130-1 | 16d |
| #2672 | ez-lbz | fix(server): validate Accept header by parsed media ranges | draft idle 16d | +97-4 | 16d |
| #2673 | ez-lbz | fix(client): cap and reset server-provided SSE retry delay | draft idle 16d | +62-3 | 16d |
| #2674 | ez-lbz | fix(validators): key compiled validators by schema body, not $id | draft idle 16d | +116-4 | 16d |
| #2675 | ez-lbz | fix(protocol): drop never-released 2024-10-07 protocol version | draft idle 16d | +21-14 | 16d |
| #2676 | ez-lbz | fix(server): enable DNS rebinding protection by default | draft idle 16d | +201-11 | 16d |
5 auth parked (9) — Maintainer draft >30d, intentionally shelved.
| #1292 | ochafik | feat: generate schemas from types, improve type definitions | maintainer draft, 263d | +9663-3551 | 263d |
| #1492 | ochafik | Add request/response compression support for HTTP transports | maintainer draft, 207d | +1253-10 | 207d |
| #1597 | pcarleton | examples: MRTR backwards-compatibility exploration demos | maintainer draft, 186d | +1185-0 | 186d |
| #1633 | ochafik | [SEP-2356] File input support for tools and elicitation | maintainer draft, 180d | +147-4 | 180d |
| #1721 | pcarleton | authfix(xaa): address review nits from #1593 & use discoveryState | maintainer draft, 165d | +55-153 | 165d |
| #1722 | pcarleton | auth[v1.x backport] SEP-990 Cross-App Access | maintainer draft, 165d | +874-3 | 165d |
| #1957 | pcarleton | authfeat(client/auth): RFC 9207 iss parameter validation (SEP-2468 reference impl) | maintainer draft, 130d | +6790-907 | 130d |
| #2465 | felixweinberger | authfix(client): scope transport headers to MCP requests and handle redirects explicitly | maintainer draft, 55d | +1749-83 | 55d |
| #2470 | felixweinberger | authrefactor(core): extract connection-scoped state into a private Connection owner | maintainer draft, 54d | +1220-222 | 54d |
draft-active (1) — Author is still working. Fresh draft.
| #2738 | SnowSky1 | [v1.x] fix(server): parse Accept media types exactly | 3d old | +160-6 | 3d |
Stats — volume, timing, size distribution
Volume
Time to First Review
Merge Time
PR Size Distribution
Open PRs by lines changed
Breakdown by tier
| Tier | Count | Auth | Maint. | ~Time |
|---|---|---|---|---|
| 1 — We're blocking someone | 21 | 5 | 11 | 5.8h |
| 2 — High leverage | 15 | 6 | 3 | 2.4h |
| 3 — Intake | 101 | 22 | 0 | 47.0h |
| 4 — Hygiene | 3 | 0 | 0 | 20m |
| 5 — Close candidates | 10 | 3 | 1 | 10m |
| total actionable | 150 | 36 | 15 | 55.7h |
| not our move | 25 | — | — | — |
We're blocking someone (21) ⊕ ⊖
Author did what we asked and is waiting on us. Longest-waiting first.
7 SLA1 auth author-pinged-after-procedural (7) — Author addressed maintainer feedback and pinged — awaiting response.
| #1486 | daamitt | re-reviewfeat: Add support for specifying NotificationOptions | author pinged @felixweinberger, @maxisbey 290d ago | +16-4 | 321d |
| #1810 | punitmahes | re-reviewauthfeat(cmid-server): Implement Server-Side Support for Client ID Metadata Documents (CIMD) | author pinged @maxisbey 181d ago | +189-1 | 255d |
| #1856 | codefromthecrypt | re-reviewfix: suppress GeneratorExit during client cleanup | author pinged @Kludex 210d ago | +180-13 | 230d |
| #2099 | dgenio | re-reviewfeat: expand InitializationState with explicit lifecycle state machine | author pinged @maxisbey 185d ago | +421-9 | 194d |
| #2147 | akshan-main | re-reviewshutdown CPU busy-loop in HTTP/SSE transports | author pinged @maxisbey 147d ago | +156-18 | 188d |
| #2327 | mrutunjay-kinagi | re-reviewfeat(client): add explicit session_id support for Streamable HTTP resumption | author pinged @maxisbey 141d ago | +244-7 | 164d |
| #2657 | truffle-dev | re-review[v1.x] fix(streamable-http): reject duplicate JSON-RPC ids with 409 | author pinged @maxisbey 92d ago | +100-2 | 103d |
3 SLA1 auth needs-re-review (3) — Author pushed changes after review feedback — needs re-review.
| #1721 | BinoyOza-okta | re-reviewauthImplement SEP-990 Enterprise Managed OAuth | author pushed after CHANGES_REQUESTED (160d waiting) | +2988-3 | 271d |
| #2119 | jonathanhefner | re-reviewType-check docstring code examples via companion files and unified sync script | author pushed after CHANGES_REQUESTED (189d waiting) | +1306-270 | 193d |
| #2198 | Varun6578 | re-reviewfix: prevent tool exceptions from leaking internal details to client | author pushed after CHANGES_REQUESTED (91d waiting) | +53-11 | 184d |
10 SLA3 auth maintainer-intake (11) — Maintainer-authored PR awaiting review from another maintainer.
| #3018 | maxisbey | maintainerExtend the interaction suite to the 2026-07-28 spec | 65d, community reviewed (cubic-dev-ai) | +5896-478 | 65d |
| #3048 | maxisbey | maintainerAdd the todos-server reference example | 62d, community reviewed (cubic-dev-ai) | +923-0 | 62d |
| #3161 | maxisbey | maintainerLet a legacy-era tools/call answer with a CreateTaskResult | 39d, community reviewed (cubic-dev-ai) | +441-27 | 39d |
| #3172 | maxisbey | maintainerauthFall back to the caller-configured scope when the server advertises none | 38d, community reviewed (cubic-dev-ai) | +188-21 | 38d |
| #3173 | maxisbey | maintainerTyped custom server notifications; warn on unbound client-side drops | 38d, community reviewed (cubic-dev-ai) | +171-31 | 38d |
| #3183 | maxisbey | maintainerTrim the migration guide to genuine v1-to-v2 breaking changes | 37d, community reviewed (cubic-dev-ai) | +1070-1491 | 37d |
| #3192 | maxisbey | maintainerRebuild the streamable HTTP server transport around per-request dispatch | 36d, community reviewed (cubic-dev-ai) | +2481-1125 | 36d |
| #3204 | maxisbey | maintainerDeprecate the legacy HTTP+SSE transport | 35d, community reviewed (cubic-dev-ai) | +238-78 | 35d |
| #3343 | maxisbey | maintainerauthResolve dot-segments when deriving and matching OAuth resource URLs | 12d, community reviewed (cubic-dev-ai) | +138-9 | 12d |
| #3398 | maxisbey | maintainerauthValidate the authorization server metadata issuer on every discovery path | 6d, community reviewed (cubic-dev-ai) | +760-135 | 6d |
| #3426 | maxisbey | [v1.x] Expire idle Streamable HTTP sessions by default and cap concurrent sessions | 0d, community reviewed (cubic-dev-ai) | +883-208 | 0d |
High leverage (15) ⊕ ⊖
One decision unblocks or closes multiple things.
12 SLA11 auth duplicate-cluster (12 clusters, 24 PRs) — Multiple PRs address the same issue — one will be picked, others closed as duplicates.
Issue #1265 — 2 PRs ⭐ #1938 (Live CI/test data wasn't reachable (gh and WebFetch network access were both blocked in this session), so this comes from the repo's own tracked PR metrics rather than a live check — worth confirming CI status directly before merging. On the data available: #1938 changes 4 files (+28/-10 lines), while #3013 changes 20 files (+93/-39 lines) for the same trailing-slash-stripping fix — a diff roughly 5x larger in file count and 3x+ larger in line count for an equivalent scope, which raises review burden and regression surface. #1938 was also opened first (age_days 221.3 vs. 65.4, i.e. ~156 days earlier against the same issue #1265). Neither PR's description shows explicit test additions, so that criterion doesn't distinguish them. On the two verifiable tiebreakers — diff size and age — both favor #1938.)
| #1938 | maxisbey | maintainerauthfix: strip trailing slashes from OAuth metadata URL fields | cluster primary for issue #1265 (2 PRs) | +28-10 | 222d |
| #3013 | piyushbag | authfix(auth): strip trailing slashes from OAuth metadata URLs | shares linked issue #1265 with #1938 | +93-39 | 66d |
Issue #1656 — 2 PRs ⭐ #2503 (CI status isn't resolvable from this environment for either PR (GitHub API/web access is unavailable here), and neither PR's tracked metadata shows added test files, so those two criteria are tied. Falling to diff size: #2503 is a 38+/4- change across 3 files vs. #2532's 124+/9- across 5 files — roughly 3x smaller for the same fix (avoiding logging configuration during MCPServer/FastMCP init, issue #1656). #2503 was also opened first (2026-04-25 vs. 2026-05-01). Recommend a human confirm live CI/test status on github.com before merging, since that data couldn't be verified here.)
| #2503 | fungi8 | 1st-reviewAvoid configuring logging during MCPServer initialization | cluster primary for issue #1656 (2 PRs) | +38-4 | 130d |
| #2532 | Genmin | Stop FastMCP from configuring application logging | shares linked issue #1656 with #2503 | +124-9 | 123d |
Issue #1933 — 2 PRs ⭐ #2040 (Network access (gh CLI, curl, WebFetch) was unavailable in this session, so CI results, test coverage, and exact diff line-counts for both PRs couldn't be independently verified beyond what was given. On the stated tie-break data, CI is unknown for both and files changed is tied at 2 for each, so no differentiation there. The one objectively verifiable fact from the PR numbers themselves is age: PR numbers are monotonically assigned per repo, so #2040 is unambiguously older than #3090 (opened earlier against the same issue). Per the stated preference order (passing CI > tests > diff size > oldest), with the first three criteria tied, oldest breaks the tie in favor of #2040. Additionally, #2040's title ("prevent stdio_server from closing process stdio handles") maps directly onto the issue's described root cause ("Using transport=\"stdio\" closes real stdio, causing ValueError after server exits"), whereas #3090's framing ("serve bufferless std streams as text instead of crashing") targets a related but distinct symptom (a crash from missing buffer semantics) rather than the closing-handles root cause itself.)
| #2040 | adityuhkapoor | 1st-reviewfix: prevent stdio_server from closing process stdio handles | cluster primary for issue #1933 (2 PRs) | +66-10 | 202d |
| #3090 | steps-re | fix(stdio): serve bufferless std streams as text instead of crashing | shares linked issue #1933 with #2040 | +45-4 | 50d |
Issue #2605 — 2 PRs ⭐ #2606 (Both PRs show CI as unknown and neither has confirmed test coverage in the provided metadata, so the deciding factor is diff size. #2606 touches only 2 files and its title maps directly to issue #2605 ("reject changed duplicate initialize"), making it a focused, easily reviewable fix. #2999 spans 30 files under a broader "work through spec-conformance gaps" scope, which bundles unrelated changes beyond #2605, increasing review burden and merge-conflict risk. Per the stated preference order (passing CI > tests > smallest focused diff > oldest), with the first two tied/unknown, the smallest focused diff wins: #2606.)
| #2606 | he-yufeng | 1st-reviewfix: reject changed duplicate initialize | cluster primary for issue #2605 (2 PRs) | +25-1 | 109d |
| #2999 | maxisbey | authWork through the spec-conformance gaps recorded by the interaction suite | shares linked issue #2605 with #2606 | +3804-1033 | 67d |
Issue #3240 — 2 PRs ⭐ #3263 (I was unable to independently verify CI status or diff contents — both `gh` and WebFetch were blocked by permissions in this session, so this is based solely on the stated facts: CI is listed as unknown for both, so that tiebreaker doesn't distinguish them. Falling to the next criterion, diff size: #3263 touches 2 files versus #3328's 7 files, making #3263 the smaller, more focused change addressing the same root cause (AS metadata discovery ordering relative to token refresh in issue #3240). A smaller, more targeted diff is easier to review line-by-line, carries less merge-conflict surface, and is less likely to bundle unrelated refactoring alongside the actual fix. Note: this pick should be re-verified against actual CI results and test coverage once that data is accessible, since those are weighted above diff size in the stated preference order.)
| #3263 | app/claude | 1st-reviewauthfix(client/auth): discover AS metadata before cold-start token refresh, with issuer-binding check | cluster primary for issue #3240 (2 PRs) | +596-7 | 26d |
| #3328 | maxisbey | authOAuth client: refresh before re-authorizing, and discover before refreshing | shares linked issue #3240 with #3263 | +548-45 | 15d |
Semantic: When OAuth tokens are reloaded from storage (e.g. after a client restart), `token_expiry_time` is never restored, so `is_token_valid()` incorrectly treats an already-expired stored token as valid. That causes the client to skip its proactive refresh check, send requests with a dead token, hit a 401, and then fall through to full interactive re-authorization instead of silently using the stored refresh_token. (2 PRs) — 2 PRs ⭐ #1784 (#1784 fixes the defect at its source: a 2-line change in `_initialize` calls `context.update_token_expiry()` on stored tokens so `is_token_valid()` evaluates correctly everywhere downstream, and it ships a matching `expired_tokens` test fixture. #2875 patches around the same root cause with a larger diff, inserting a new 'Step 3.5' branch inside `async_auth_flow`'s 401-handling path that retries with the stored refresh_token before full re-auth — it doesn't correct `is_token_valid()`/`_initialize` itself, so the proactive-refresh path stays broken, and most of its new branch becomes dead code once expiry is restored correctly at init.)
| #1784 | keurcien | 1st-reviewauthFix `token_expiry_time` upon context initialization for stored tokens. | [llm] cluster primary: When OAuth tokens are reloaded from storage (e.g. after a client restart), `token_expiry_time` is never restored, so `is_token_valid()` incorrectly treats an already-expired stored token as valid. That causes the client to skip its proactive refresh check, send requests with a dead token, hit a 401, and then fall through to full interactive re-authorization instead of silently using the stored refresh_token. (2 PRs) | +109-0 | 263d |
| #2875 | beraterkanelcelik | authfix(client/auth): use stored refresh_token on 401 instead of full re-authorization | [llm] duplicates #1784: When OAuth tokens are reloaded from storage (e.g. after a client restart), `token_expiry_time` is never restored, so `is_token_valid()` incorrectly treats an already-expired stored token as valid. That causes the client to skip its proactive refresh check, send requests with a dead token, hit a 401, and then fall through to full interactive re-authorization instead of silently using the stored refresh_token. | +175-2 | 78d |
Semantic: pre_parse_json() in func_metadata.py JSON-decodes string arguments before Pydantic validation, and for fields typed as a union containing str (e.g. `str | None`), a plain string value that happens to look like JSON (e.g. "123", "true", "null", "[1,2]") gets silently corrupted into an int/bool/None/list instead of staying a str. Both PRs add a helper to `pre_parse_json`'s call site to skip pre-parsing when the annotation is such a union. (2 PRs) — 2 PRs ⭐ #2032 (Both add a helper consulted at the same call site (`field_info.annotation is not str` -> helper) in pre_parse_json, so they are alternate fixes for the identical bug, not complementary. #2032's `_should_pre_parse_json` generalizes via a `_SIMPLE_TYPES` frozenset {str, int, float, bool, NoneType} and skips pre-parsing whenever *every* union member is a JSON-primitive type, so it covers `str | None`, `str | int`, `str | bool`, and `str | float` in one pass. #3056's `_is_optional_str` only special-cases the exact `str | None` shape, so it leaves `str | int`/`str | bool`/`str | float` unions still vulnerable to the same corruption this issue is about. #3056 does add `_unwrap_annotated` to strip `Annotated[...]` off individual union members before the check, a case #2032's plain `arg not in _SIMPLE_TYPES` membership test misses (e.g. `Annotated[str, Field(...)] | None`), but that's a narrower edge case than the multi-type coverage gap it leaves open. Recommend keeping #2032 and, if the Annotated-member edge case matters, folding #3056's `_unwrap_annotated` step into #2032's broader check rather than merging #3056 as-is.)
| #2032 | adityuhkapoor | 1st-reviewfix: skip JSON pre-parsing for str union annotations in pre_parse_json | [llm] cluster primary: pre_parse_json() in func_metadata.py JSON-decodes string arguments before Pydantic validation, and for fields typed as a union containing str (e.g. `str | None`), a plain string value that happens to look like JSON (e.g. "123", "true", "null", "[1,2]") gets silently corrupted into an int/bool/None/list instead of staying a str. Both PRs add a helper to `pre_parse_json`'s call site to skip pre-parsing when the annotation is such a union. (2 PRs) | +38-1 | 203d |
| #3056 | vientooscuro | Fix pre_parse_json corrupting str | None values that look like JSON | [llm] duplicates #2032: pre_parse_json() in func_metadata.py JSON-decodes string arguments before Pydantic validation, and for fields typed as a union containing str (e.g. `str | None`), a plain string value that happens to look like JSON (e.g. "123", "true", "null", "[1,2]") gets silently corrupted into an int/bool/None/list instead of staying a str. Both PRs add a helper to `pre_parse_json`'s call site to skip pre-parsing when the annotation is such a union. | +79-1 | 61d |
Semantic: Both touch the write_stream memory-object-stream buffer size in stdio_server. #2215 makes both read/write buffer sizes configurable via new parameters (default remains 0, i.e. unbuffered). #2654 hardcodes the write_stream buffer to 1 specifically to fix a deadlock where a handler can't enqueue its final response while stdout_writer is still flushing an earlier message (e.g. a progress notification) - the same root blocking behavior #2215's knob could be used to work around, but only if a caller opts in. (2 PRs) — 2 PRs ⭐ #2654 (#2654 fixes the write_stream blocking/deadlock by default (buffer=1) with no API change required from callers, and adds a regression test (BlockingStdout) that reproduces the exact stuck-write scenario during a progress notification. #2215's default buffer size stays 0, so the same blocking bug persists unless a caller explicitly passes write_stream_buffer_size>0; its test diff only covers the new parameters, not a reproduction of the blocking case #2654 targets.)
| #2215 | yaowubarbara | fix(stdio): allow configurable memory stream buffer size | [llm] duplicates #2654: Both touch the write_stream memory-object-stream buffer size in stdio_server. #2215 makes both read/write buffer sizes configurable via new parameters (default remains 0, i.e. unbuffered). #2654 hardcodes the write_stream buffer to 1 specifically to fix a deadlock where a handler can't enqueue its final response while stdout_writer is still flushing an earlier message (e.g. a progress notification) - the same root blocking behavior #2215's knob could be used to work around, but only if a caller opts in. | +85-3 | 180d |
| #2654 | 2830500285 | 1st-reviewfix: buffer stdio server writes during progress notifications | [llm] cluster primary: Both touch the write_stream memory-object-stream buffer size in stdio_server. #2215 makes both read/write buffer sizes configurable via new parameters (default remains 0, i.e. unbuffered). #2654 hardcodes the write_stream buffer to 1 specifically to fix a deadlock where a handler can't enqueue its final response while stdout_writer is still flushing an earlier message (e.g. a progress notification) - the same root blocking behavior #2215's knob could be used to work around, but only if a caller opts in. (2 PRs) | +43-2 | 103d |
Semantic: Both fix the same root cause: when SSE reconnection in _handle_reconnection() permanently fails (max attempts exceeded), the in-flight request is never resolved. Before either fix, the code path hit by exhausted retries just logged and returned, leaving the caller awaiting a response that would never arrive. #2395 fixes this by constructing a JSONRPCError and pushing it onto ctx.read_stream_writer so the specific pending request unblocks with an error. #3098 fixes the same dead-end by adding _unwrap_exception() to pull a StreamableHTTPError out of the anyio ExceptionGroup so the failure propagates as a clean exception instead. Both react to the identical trigger point (MAX_RECONNECTION_ATTEMPTS exceeded) and both are titled around surfacing reconnection failure. (2 PRs) — 2 PRs ⭐ #2395 (#2395's fix stays inside the existing per-request error-delivery path (build a JSONRPCError, send it on ctx.read_stream_writer) that the codebase already uses elsewhere for this exact failure class -- PR #3092 in this same batch adds a non-2xx HTTP handler using that identical JSONRPCError-via-read_stream_writer pattern, so #2395 is consistent with the established convention. #3098's alternative (raise StreamableHTTPError out of the task group via exception-group unwrapping) changes the failure mode for the whole transport/session rather than just resolving the one stuck request, a larger-blast-radius change for the same trigger. #2395 is also the smaller, more contained diff (single conditional block reusing existing types) versus #3098 which introduces a new recursive helper function.)
| #2395 | Dharit13 | 1st-reviewFix infinite reconnection loop in StreamableHTTP client | [llm] cluster primary: Both fix the same root cause: when SSE reconnection in _handle_reconnection() permanently fails (max attempts exceeded), the in-flight request is never resolved. Before either fix, the code path hit by exhausted retries just logged and returned, leaving the caller awaiting a response that would never arrive. #2395 fixes this by constructing a JSONRPCError and pushing it onto ctx.read_stream_writer so the specific pending request unblocks with an error. #3098 fixes the same dead-end by adding _unwrap_exception() to pull a StreamableHTTPError out of the anyio ExceptionGroup so the failure propagates as a clean exception instead. Both react to the identical trigger point (MAX_RECONNECTION_ATTEMPTS exceeded) and both are titled around surfacing reconnection failure. (2 PRs) | +62-9 | 149d |
| #3098 | wukath | fix: Raise StreamableHTTPError on reconnection failure | [llm] duplicates #2395: Both fix the same root cause: when SSE reconnection in _handle_reconnection() permanently fails (max attempts exceeded), the in-flight request is never resolved. Before either fix, the code path hit by exhausted retries just logged and returned, leaving the caller awaiting a response that would never arrive. #2395 fixes this by constructing a JSONRPCError and pushing it onto ctx.read_stream_writer so the specific pending request unblocks with an error. #3098 fixes the same dead-end by adding _unwrap_exception() to pull a StreamableHTTPError out of the anyio ExceptionGroup so the failure propagates as a clean exception instead. Both react to the identical trigger point (MAX_RECONNECTION_ATTEMPTS exceeded) and both are titled around surfacing reconnection failure. | +192-39 | 48d |
Semantic: Both patch validate_tool_use_result_messages() in src/mcp/server/validation.py to fix the same trigger case: an assistant message with tool_use followed by a next message that has NO tool_result blocks. Currently this falls through to the id-matching check, where empty tool_result_ids never equals non-empty tool_use_ids, producing a misleading 'ids ... do not match' ValueError. (2 PRs) — 2 PRs ⭐ #2962 (#2962 gates the id-matching block on has_tool_results, so a tool_use with no following tool_result no longer raises at all -- its regression test cites SEP-1577 explicitly: a tool_result must be preceded by tool_use, but a tool_use is NOT required to be followed by a tool_result. #3053 keeps this case as an error (just reworded to 'tool_use blocks must be followed by matching tool_result blocks'), which contradicts that spec requirement rather than fixing it. The two diffs edit the same lines with opposite intended behavior and cannot both be merged; #2962 is the spec-compliant fix and should be kept, #3053 closed.)
| #2962 | Bartok9 | 1st-reviewfix(server): don't raise when tool_use is not followed by tool_result | [llm] cluster primary: Both patch validate_tool_use_result_messages() in src/mcp/server/validation.py to fix the same trigger case: an assistant message with tool_use followed by a next message that has NO tool_result blocks. Currently this falls through to the id-matching check, where empty tool_result_ids never equals non-empty tool_use_ids, producing a misleading 'ids ... do not match' ValueError. (2 PRs) | +25-1 | 69d |
| #3053 | HarperZ9 | Clarify missing tool_result validation error | [llm] duplicates #2962: Both patch validate_tool_use_result_messages() in src/mcp/server/validation.py to fix the same trigger case: an assistant message with tool_use followed by a next message that has NO tool_result blocks. Currently this falls through to the id-matching check, where empty tool_result_ids never equals non-empty tool_use_ids, producing a misleading 'ids ... do not match' ValueError. | +19-0 | 62d |
Semantic: Both PRs replace regex/substring-based extraction of parameters from the WWW-Authenticate response header with a quote-aware, comma-splitting parser, fixing the same underlying bug where the old code could match parameter values or scheme names that were only substrings of the real token (e.g. a quoted value containing a comma or another scheme's name). (2 PRs) — 2 PRs ⭐ #3041 (3041's _split_www_authenticate_segments splits the ENTIRE header (not just the text after the first space) on top-level commas and then _extract_bearer_auth_params walks the resulting segments to find where the 'Bearer' scheme token starts before collecting its auth-params. 3012's _iter_www_auth_params only looks for the first space in the header and treats everything after it as one flat list of comma-separated params, so it has no scheme-boundary logic and would misparse a header containing multiple challenges (e.g. 'Bearer ..., DPoP ...' or 'Basic ..., Bearer ...') by folding a second scheme's tokens into the Bearer param list. 3041 directly targets that multi-challenge substring-matching failure mode, matching its own PR title, while 3012 only handles the single-challenge case.)
| #3012 | tarunag10 | authfix(auth): match complete WWW-Authenticate parameters | [llm] duplicates #3041: Both PRs replace regex/substring-based extraction of parameters from the WWW-Authenticate response header with a quote-aware, comma-splitting parser, fixing the same underlying bug where the old code could match parameter values or scheme names that were only substrings of the real token (e.g. a quoted value containing a comma or another scheme's name). | +196-7 | 66d |
| #3041 | Whning0513 | 1st-reviewauthFix substring matches in WWW-Authenticate parsing | [llm] cluster primary: Both PRs replace regex/substring-based extraction of parameters from the WWW-Authenticate response header with a quote-aware, comma-splitting parser, fixing the same underlying bug where the old code could match parameter values or scheme names that were only substrings of the real token (e.g. a quoted value containing a comma or another scheme's name). (2 PRs) | +191-9 | 62d |
Semantic: Both PRs fix the same underlying issue: the client's httpx.AsyncClient was configured with follow_redirects=True, which would follow HTTP redirects to any origin. Both change this to scope redirect-following to the same origin as the original request, and both update docs/client/transports.md's description of the production client's `httpx.AsyncClient` configuration to reflect the new same-origin redirect behavior. (2 PRs) — 2 PRs ⭐ #3075 (PR #3075's diff to docs/client/transports.md applies cleanly against the current file (old text reads `httpx.AsyncClient`), and it additionally updates docs/migration.md to show the correct import path (`from mcp import create_mcp_http_client`) for the new redirect-scoping helper, giving more complete doc coverage of the change. PR #3397's diff to the same transports.md line shows stale/mismatched base content (`httpx2.AsyncClient`, truncated line), indicating it was not rebased against current main and will likely conflict on merge; its extra oauth-clients.md note about redirect behavior during auth requests can be ported into #3075 if wanted.)
| #3075 | maxisbey | maintainerauthScope HTTP client redirect following to the request's origin | [llm] cluster primary: Both PRs fix the same underlying issue: the client's httpx.AsyncClient was configured with follow_redirects=True, which would follow HTTP redirects to any origin. Both change this to scope redirect-following to the same origin as the original request, and both update docs/client/transports.md's description of the production client's `httpx.AsyncClient` configuration to reflect the new same-origin redirect behavior. (2 PRs) | +878-57 | 56d |
| #3397 | maxisbey | authFollow redirects only within the MCP endpoint's origin | [llm] duplicates #3075: Both PRs fix the same underlying issue: the client's httpx.AsyncClient was configured with follow_redirects=True, which would follow HTTP redirects to any origin. Both change this to scope redirect-following to the same origin as the original request, and both update docs/client/transports.md's description of the production client's `httpx.AsyncClient` configuration to reflect the new same-origin redirect behavior. | +715-166 | 6d |
2 SLA needs-decision (2) — Maintainer discussed but hasn't approved or requested changes yet.
| #3005 | Kludex | maintainerAdd the SEP-2663 Tasks extension (core) | maintainer COMMENTED but took no stance | +3275-74 | 67d |
| #2075 | BabyChrist666 | re-reviewReject JSON-RPC requests with null id instead of misclassifying as notifications | maintainer COMMENTED but took no stance | +60-1 | 196d |
1 SLA1 auth backport-follows-primary (1) — v1.x sibling of a main-branch PR. Review together — backport diff is usually mechanical.
| #3130 | vishnujayvel | 1st-reviewauthfix: include RFC 6750 scope parameter in insufficient_scope challenge | follows #3277 (same issue #3103, different branch) | +60-2 | 45d |
Intake (101) ⊕ ⊖
PRs not yet reviewed by a maintainer. Oldest first.
57 SLA14 auth needs-first-review (59) — Not yet reviewed by a maintainer.
| #1531 | vincent0426 | 1st-reviewauthfix: Add accept json headers for token request | 308d | +10-2 | 308d |
| #1570 | carlosemart | 1st-reviewDisable logs reconfigure on startup | 302d | +45-7 | 302d |
| #1608 | cbcoutinho | 1st-reviewfeat: propagate session_id from transport to tool context | 295d | +330-1 | 295d |
| #1611 | kylestratis | 1st-reviewClient notification support | 295d | +889-4 | 295d |
| #1647 | FanisPapakonstantinou | 1st-reviewImprove exception handling for ClientDisconnect errors | 285d | +10-1 | 285d |
| #1666 | matthew-gries | 1st-reviewfix: Fix logic that determines standard resource vs. resource template to account for context param (#1635) | 281d | +280-58 | 281d |
| #1674 | AydarAkhmetzyanov | 1st-reviewRace condition in streamable http | 279d | +73-2 | 279d |
| #1817 | challenger71498 | 1st-reviewfix: cleanup resources properly on `BaseSession::_receive_loop` cleanup | 250d | +89-11 | 250d |
| #1818 | jayhemnani9910 | 1st-reviewfix: auto-reinitialize client session on HTTP 404 | 245d | +671-9 | 245d |
| #1846 | jayhemnani9910 | 1st-reviewauthfix: respect token_endpoint_auth_method=none when client_secret exists | 235d | +72-3 | 235d |
| #1847 | challenger71498 | 1st-reviewauthfeat: fully support Basic Authorization header at token request | 233d | +148-58 | 234d |
| #1934 | williamomeara | 1st-reviewauthFix RFC 8252 Section 7.3 compliance for loopback redirect URIs | 222d | +229-4 | 222d |
| #2041 | BryceEWatson | 1st-reviewfeat: expose progress_callback in ServerSession methods | 202d | +148-1 | 202d |
| #2078 | BabyChrist666 | 1st-reviewauthfix: restore eager OAuth discovery to avoid slow unauthenticated roundtrip | 196d | +303-99 | 196d |
| #2187 | Br1an67 | 1st-reviewfix: preserve notification metadata when related_request_id is 0 | 184d | +43-1 | 184d |
| #2191 | Br1an67 | 1st-reviewfix: reject unsupported HTTP methods early in session manager | 184d | +88-0 | 184d |
| #2196 | Varun6578 | 1st-reviewauthfix: only retry 403 responses for insufficient_scope error | 184d | +53-5 | 184d |
| #2261 | namabile | 1st-reviewauthfix: include "none" in token_endpoint_auth_methods_supported metadata | 176d | +9-5 | 176d |
| #2281 | omar-y-abdi | 1st-reviewAdd client callbacks for list_changed notifications | 174d | +179-4 | 174d |
| #2335 | rgoldstein1989 | 1st-reviewfeat: add remove_prompt(), remove_resource(), and remove_resource_template() | 163d | +242-1 | 163d |
| #2357 | BlocksecPHD | 1st-reviewfix(streamable-http): reduce stateless termination log noise | 159d | +44-1 | 159d |
| #2410 | RudrenduPaul | 1st-reviewfix: allow integer file descriptors for errlog in stdio_client | 146d | +13-4 | 146d |
| #2418 | manjunathgujjar | 1st-reviewfix: silence respond() when concurrent cancellation already completed request | 145d | +108-2 | 145d |
| #2428 | KeWang0622 | 1st-reviewfix: remove JSON-RPC ID type coercion for spec-compliant strict matching | 142d | +40-64 | 142d |
| #2441 | atishay2 | 1st-reviewfix: invalidate tool schema cache on ToolListChangedNotification; paginate all pages in _validate_tool_result | 141d | +121-2 | 141d |
| #2448 | MukundaKatta | 1st-reviewfeat(tools): inline local $ref in tool inputSchema (#2384) | 140d | +328-4 | 140d |
| #2449 | ddullah | 1st-review[v1.x] fix(stdio): handle BrokenResourceError in stdout_reader race (#1960) | 139d | +52-3 | 139d |
| #2456 | shaun0927 | 1st-reviewfix(stdio_client): tolerate invalid UTF-8 from child stdout | 138d | +41-4 | 138d |
| #2457 | shaun0927 | 1st-reviewfix(streamable-http): expose session_idle_timeout and pause idle reaping during active requests | 138d | +106-11 | 138d |
| #2466 | kimsehwan96 | 1st-reviewfix: skip output schema validation when tool returns is_error=True | 137d | +27-2 | 137d |
| #2467 | kimsehwan96 | 1st-reviewfix: [v1.x backport] skip output schema validation when tool returns isError=True | 137d | +27-2 | 137d |
| #2484 | sakenuGOD | 1st-reviewfix(client/stdio): allow FIFO cleanup of multiple transports on asyncio (#577) | 134d | +272-30 | 134d |
| #2499 | Zelys-DFKH | 1st-reviewfix(mcpserver): advertise capabilities only for registered primitives | 131d | +117-2 | 131d |
| #2502 | bobbyo | 1st-review[v1.x] Drop responses/notifications when write stream is already closed | 131d | +98-4 | 131d |
| #2506 | GitAashishG | 1st-reviewfeat(cli): support env vars in `mcp dev` (#339) | 129d | +130-22 | 129d |
| #2524 | Genmin | 1st-reviewfix(cli): avoid Windows shell for mcp dev | 124d | +147-19 | 124d |
| #2552 | Maanik23 | 1st-reviewfix: disable newline translation in stdio TextIOWrapper to prevent CRLF on Windows | 117d | +56-2 | 117d |
| #2565 | blackwell-systems | 1st-reviewfix: chain exceptions with `from` in 12 remaining raise sites | 116d | +15-15 | 116d |
| #2573 | charles-adedotun | 1st-reviewfix(shared): strip envelope fields when forwarding JSONRPCRequest | 114d | +59-0 | 114d |
| #2612 | pragnyanramtha | 1st-reviewfix: handle Image helpers in mixed return annotations | 109d | +88-3 | 109d |
| #2616 | pragnyanramtha | 1st-reviewauth[v1.x] fix(auth): request JSON token responses | 109d | +6-0 | 109d |
| #2623 | pragnyanramtha | 1st-reviewfix: detect context on callable tool instances | 108d | +26-1 | 108d |
| #2624 | FU-max-boop | 1st-reviewFix completed request cancellation cleanup | 108d | +57-2 | 108d |
| #2631 | Epochex | 1st-reviewfix: fail fast when session is not started | 106d | +51-4 | 106d |
| #2651 | pragnyanramtha | 1st-reviewauthfix(auth): avoid SSE OAuth refresh deadlock | 104d | +507-0 | 104d |
| #2698 | Epochex | 1st-reviewfix(client): respect negotiated capabilities in ClientSessionGroup | 98d | +109-26 | 98d |
| #2709 | haoxuw | 1st-reviewauthauth: improve ClientAuthenticator error messaging | 96d | +59-0 | 96d |
| #2729 | Bartok9 | 1st-reviewfix(client): send same-origin Origin header from streamable HTTP client | 95d | +43-2 | 95d |
| #2808 | he-yufeng | 1st-reviewauthfix(auth): normalize redirect URI URL subclasses | 87d | +38-3 | 87d |
| #2846 | nikodemas | 1st-reviewauthFix/simple auth example | 82d | +5-6 | 82d |
| #2852 | anneheartrecord | 1st-reviewfix: correlate invalid JSON-RPC envelope errors with the original request id | 81d | +154-9 | 81d |
| #2916 | ly-wang19 | 1st-reviewfix(server): match Content-Type case-insensitively in StreamableHTTP | 74d | +27-1 | 74d |
| #2939 | anneheartrecord | 1st-reviewfix(mcpserver): preserve Annotated/Field metadata for dict[str, T] return types | 73d | +30-3 | 73d |
| #3264 | app/claude | 1st-reviewauthfix(client/auth): discard stored client registrations whose secret has expired | 26d | +1191-129 | 26d |
| #3277 | app/claude | 1st-reviewauthfix(auth): include RFC 6750 scope attribute in WWW-Authenticate challenges | 22d | +210-52 | 22d |
| #3278 | app/claude | 1st-reviewfix(client): surface HTTP errors on resumption GET and SSE message POST | 22d | +585-47 | 22d |
| #3285 | app/dependabot | 1st-reviewBump pymdown-extensions from 11.0 to 11.0.1 | 21d | +4-4 | 21d |
| #3413 | Viicos | Do not parameterize `RootModel` bases in generated types | 3d | +123-236 | 4d |
| #3424 | app/dependabot | Bump the github-actions group with 6 updates | 0d | +33-33 | 0d |
42 SLA8 auth community-reviewed (42) — Community members have reviewed, but no maintainer has engaged yet.
| #2065 | IT-HONGREAT | 1st-reviewauthfeat: add auth parameter to ClientSessionGroup server parameters | 199d, reviewed by PsymoNiko (SLA breach) | +107-1 | 199d |
| #2401 | enjoykumawat | 1st-reviewauthfix: prefix auth routes with issuer_url base path for gateway deployments | 147d, reviewed by cubic-dev-ai (SLA breach) | +68-6 | 147d |
| #2633 | Epochex | 1st-reviewfix(streamable-http): close SSE responses on errors | 106d, reviewed by cubic-dev-ai (SLA breach) | +146-14 | 106d |
| #2652 | STiFLeR7 | 1st-reviewfeat: add protocol version override support for client session initialization | 104d, reviewed by cubic-dev-ai (SLA breach) | +209-11 | 104d |
| #2675 | Epochex | 1st-reviewauthfix(auth): get_access_token reflects current request in stateful sessions | 100d, reviewed by cubic-dev-ai (SLA breach) | +181-1 | 100d |
| #2680 | Epochex | 1st-reviewfix(stdio): drain responses after stdin EOF | 99d, reviewed by StantonMatt (SLA breach) | +453-47 | 99d |
| #2732 | Epochex | 1st-reviewfix(streamable-http): fail request when resumable SSE stream can't complete | 94d, reviewed by cubic-dev-ai (SLA breach) | +229-8 | 94d |
| #2745 | he-yufeng | 1st-reviewfix: exit stdio server cleanly on interrupt | 93d, reviewed by ErenAta16 (SLA breach) | +41-12 | 93d |
| #2749 | vidigoat | 1st-reviewfix(resources): escape literal regex metacharacters in ResourceTemplate.matches | 93d, reviewed by Robin1987China, StantonMatt (SLA breach) | +41-0 | 93d |
| #2766 | he-yufeng | 1st-reviewfix(server): return stdio parse errors | 91d, reviewed by StantonMatt (SLA breach) | +34962-15 | 91d |
| #2772 | mengyunxie | 1st-reviewfix: propagate McpError from tool handlers as JSON-RPC error | 91d, reviewed by StantonMatt (SLA breach) | +37-16 | 91d |
| #2779 | Bartok9 | 1st-reviewauthfix(client): preserve existing query params on OAuth authorization_endpoint | 90d, reviewed by STiFLeR7, cubic-dev-ai (SLA breach) | +293-310 | 90d |
| #2853 | fede-kamel | 1st-reviewauthfix: retry token refresh without RFC 8707 resource param when the AS rejects it | 81d, reviewed by cubic-dev-ai (SLA breach) | +161-3 | 81d |
| #2918 | ly-wang19 | 1st-reviewfix(server): treat text/* mime types case-insensitively for FileResource | 73d, reviewed by dchou1618 (SLA breach) | +43-2 | 73d |
| #2951 | SamMorrowDrums | 1st-reviewAdd experimental Server Cards support (SEP-2127) | 71d, reviewed by cubic-dev-ai, tadasant (SLA breach) | +2024-0 | 71d |
| #2979 | syf2211 | 1st-reviewfix(server): validate elicitation form/url sub-capabilities in check_capability | 68d, reviewed by cubic-dev-ai (SLA breach) | +39-2 | 68d |
| #2983 | Bartok9 | 1st-reviewfix(server): guard error-path send into closed session stream | 68d, reviewed by cubic-dev-ai (SLA breach) | +81-45 | 68d |
| #2984 | RaidLZ | 1st-reviewfeat(mcpserver): let ToolError carry content for is_error results | 68d, reviewed by cubic-dev-ai, pwdh2026 (SLA breach) | +58-3 | 68d |
| #3021 | CJGjr | 1st-reviewAdd list_all_* helpers that drain pagination on the client | 64d, reviewed by cubic-dev-ai (SLA breach) | +788-22 | 64d |
| #3025 | devansh-dek | 1st-reviewfix(client): catch httpx transport errors in streamable HTTP post_writer | 64d, reviewed by cubic-dev-ai (SLA breach) | +48-4 | 64d |
| #3059 | raphaelOhana | 1st-reviewfix: prevent session + task leak on GET/DELETE without session-id | 60d, reviewed by cubic-dev-ai (SLA breach) | +225-1 | 60d |
| #3063 | Sammy-Dabbas | 1st-reviewfix(streamable-http): reject duplicate in-flight request ids | 60d, reviewed by cubic-dev-ai (SLA breach) | +258-10 | 60d |
| #3064 | akminx | 1st-reviewfix(dispatcher): reject duplicate in-flight request ids | 59d, reviewed by cubic-dev-ai (SLA breach) | +110-85 | 59d |
| #3066 | mayankbohradev | 1st-reviewauthPreserve query components in PRM resource URLs | 58d, reviewed by cubic-dev-ai (SLA breach) | +102-12 | 58d |
| #3068 | elbachir-salik | 1st-reviewfix: forbid extra arguments in FastMCP tool arg models (#3067) | 57d, reviewed by cubic-dev-ai (SLA breach) | +41-14 | 57d |
| #3069 | isheng-eqi | 1st-reviewauthfix(server): guard GET SSE response with CancelScope to prevent Windows deadlock (#2653) | 57d, reviewed by cubic-dev-ai (SLA breach) | +25-4 | 57d |
| #3077 | Joosboy | 1st-reviewdocs: clarify OpenTelemetry spans for resources and prompts | 55d, reviewed by cubic-dev-ai (SLA breach) | +50-4 | 55d |
| #3078 | ychampion | 1st-reviewfix(server): reject changed duplicate initialize | 55d, reviewed by cubic-dev-ai (SLA breach) | +129-17 | 55d |
| #3092 | himanshu-commits | 1st-reviewfix(client): surface non-2xx HTTP responses to the waiting caller | 50d, reviewed by afterrburn, cubic-dev-ai (SLA breach) | +275-17 | 50d |
| #3097 | Lexus2016 | 1st-reviewfix: catch BrokenPipeError in stdio stdout_writer | 48d, reviewed by cubic-dev-ai (SLA breach) | +7-1 | 48d |
| #3118 | jayzuccarelli | 1st-reviewfix(server): generate tool output schema in serialization mode | 47d, reviewed by cubic-dev-ai (SLA breach) | +82-3 | 47d |
| #3124 | rahul188 | 1st-reviewfix: prevent infinite warning-logging loop in _handle_message | 46d, reviewed by cubic-dev-ai (SLA breach) | +89-2 | 46d |
| #3127 | ayaangazali | 1st-reviewfix: never mint a request id already used by a completed caller-supplied id | 45d, reviewed by cubic-dev-ai (SLA breach) | +47-13 | 46d |
| #3128 | MrSampson | 1st-reviewfix: self-describing error for requests before session initialization (was generic -32602) | 45d, reviewed by cubic-dev-ai (SLA breach) | +144-25 | 45d |
| #3129 | dosvk | 1st-reviewfix: return 405 for pre-session GET the server won't serve as SSE | 45d, reviewed by cubic-dev-ai (SLA breach) | +258-4 | 45d |
| #3135 | sandole | 1st-reviewperf: discriminate JSONRPCMessage union by key presence instead of smart-union scoring | 44d, reviewed by cubic-dev-ai (SLA breach) | +315-3 | 44d |
| #3147 | g0rdonL | 1st-reviewfix: make deeply-nested-body test platform-independent (fixes #3146) | 41d, reviewed by cubic-dev-ai, opensource-joe (SLA breach) | +40-2 | 41d |
| #3148 | Aaron-Oh | 1st-reviewAdd a runtime create_model variant to the schema_validators example | 41d, reviewed by cubic-dev-ai (SLA breach) | +64-12 | 41d |
| #3155 | olaservo | 1st-reviewAdd opt out for mirroring structuredContent into Content automatically | 40d, reviewed by cubic-dev-ai (SLA breach) | +83-14 | 40d |
| #3156 | dongjiang1989 | 1st-reviewmcp/client: add list_all_* helpers with pagination safety guards | 40d, reviewed by cubic-dev-ai (SLA breach) | +342-1 | 40d |
| #3175 | manjunathbhaskar | 1st-reviewauthfix(client): don't send client_id in token body under client_secret_b… | 38d, reviewed by cubic-dev-ai (SLA breach) | +51-28 | 38d |
| #3182 | tirthfx | 1st-reviewfix: return HTTP 400 PARSE_ERROR for non-UTF-8 POST bodies | 37d, reviewed by cubic-dev-ai, iamroylim (SLA breach) | +74-3 | 37d |
Hygiene (3) ⊕ ⊖
Batchable procedural ops — pings, rebases, peer reviews.
stale-awaiting-author (2) — Changes requested over two weeks ago with no author response.
| #2253 | weiguangli-io | fix: terminate active StreamableHTTP sessions during shutdown | author self-diagnosed CI 130d ago, never fixed | +14-0 | 176d |
| #2514 | dragogargo | fix: send notifications/cancelled on request timeout and caller cancellation | author self-diagnosed CI 127d ago, never fixed | +121-2 | 127d |
approved-rotted (1) — Was approved, now conflicting. Rebase or ask author.
| #1872 | DePasqualeOrg | fix: correct unknown tool/prompt/resource error handling | approved 172d ago, now conflicting | +63-35 | 229d |
Close candidates (10) ⊕ ⊖
Likely to be closed — inactive, stale, or needing more context. Reviewed before closing.
2 auth stale-ci-abandoned (8) — CI has been failing for over a month with no activity.
| #2387 | Kludex | Add richer OTel MCP span attributes | red CI 152d, no activity | +196-17 | 152d |
| #2077 | mrutunjay-kinagi | authfix(auth): forward user-agent to oauth flow requests | red CI 196d, no activity | +104-3 | 196d |
| #2145 | wiggzz | Fix stateless HTTP task accumulation causing memory leak | red CI 188d, no activity | +296-20 | 188d |
| #2245 | Varun6578 | fix: collapse single-exception ExceptionGroups from task groups | red CI 179d, no activity | +333-23 | 178d |
| #2551 | namor5772 | fix(client/stdio): fall back to os.devnull when sys.stderr is None | red CI 117d, no activity | +23-2 | 118d |
| #2712 | whocareyw | fix(streamable-http): drain SSE response to EOF instead of closing early | red CI 96d, no activity | +24-12 | 96d |
| #2726 | he-yufeng | fix: explain transport host rejections | red CI 95d, no activity | +53-7 | 95d |
| #2858 | Bartok9 | authfix(oauth): narrow context.lock scope in async_auth_flow (rebase of #2660 by @peisuke, closes #2847) | red CI 80d, no activity | +533-342 | 80d |
Not our move (25) ⊕ ⊖
Clock is on the author or blocked externally. No action owed today.
2 auth stale-draft (15) — Draft with no activity for over a week.
| #1998 | bgaidioz | authFix: Refresh auth context per Streamable HTTP request | draft idle 208d | +196-0 | 208d |
| #2130 | jonathanhefner | Import "Build an LLM-powered chatbot" quickstart guide | draft idle 190d | +2024-268 | 190d |
| #2138 | jonathanhefner | Import "Build a weather server" quickstart guide | draft idle 189d | +2600-268 | 189d |
| #2139 | jonathanhefner | Replace Claude for Desktop with VS Code + Copilot in server quickstart | draft idle 189d | +2514-268 | 189d |
| #2509 | faridun-ag2 | fix(server): return 405 on GET/DELETE in stateless HTTP mode | draft idle 128d | +136-0 | 128d |
| #2598 | MukundaKatta | docs: add server instructions example | draft idle 110d | +58-0 | 110d |
| #2959 | nZiben | Fix SSE gateway endpoint resolution | draft idle 69d | +153-4 | 69d |
| #3087 | heyhayes | fix: stop the standalone GET stream reconnecting forever on empty connections | draft idle 53d | +44-4 | 53d |
| #3094 | himanshu-commits | feat(client): carry the originating HTTP status in ErrorData.data | draft idle 49d | +125-5 | 49d |
| #3119 | jayzuccarelli | fix(server): forward tool args under the real parameter name, not the… | draft idle 47d | +42-9 | 47d |
| #3139 | app/claude | Add experimental Server Card extension support (SEP-2127) | draft idle 43d | +3671-0 | 43d |
| #3153 | dchou1618 | fix: Streamable HTTP Accept negotiation handling | draft idle 40d | +70-3 | 40d |
| #3242 | maxisbey | Cut import and startup cost with deferred model builds and lazy imports | draft idle 29d | +1003-191 | 29d |
| #3292 | maxisbey | authLet a token verifier gate the server without AuthSettings | draft idle 21d | +276-94 | 21d |
| #3338 | maxisbey | Lift httpx2's default SSE event size cap on every client SSE reader | draft idle 13d | +130-10 | 13d |
1 auth parked (9) — Maintainer draft >30d, intentionally shelved.
| #2238 | maxisbey | Truncate untrusted peer-controlled values before logging/raising | maintainer draft, 179d | +41-38 | 179d |
| #2263 | maxisbey | fix: eliminate test port allocation race by running uvicorn in-thread | maintainer draft, 175d | +152-279 | 175d |
| #2264 | maxisbey | tests: eliminate port-allocation races in SSE/StreamableHTTP tests | maintainer draft, 175d | +647-1119 | 175d |
| #2320 | maxisbey | Extract JSON-RPC wrapping into a Dispatcher component | maintainer draft, 165d | +523-223 | 166d |
| #2322 | maxisbey | draft: MRTR (SEP-2322) lowlevel plumbing + handler-shape comparison | maintainer draft, 165d | +2609-14 | 165d |
| #2388 | Kludex | Add MCP proxy helper | maintainer draft, 151d | +699-12 | 151d |
| #2717 | maxisbey | [v1.x] tests: backport interaction-model suite from main (527 tests, src/ untouched) | maintainer draft, 95d | +17006-2605 | 95d |
| #3220 | maxisbey | [experimental - do not merge] Cut startup cost: lazy exports, pay-for-what-you-use imports, deferred model builds | maintainer draft, 33d | +3759-1050 | 33d |
| #3222 | maxisbey | authDelegate authorize-time scope policy to the provider | maintainer draft, 33d | +247-35 | 33d |
stale-draft-pinged (1) — Draft; maintainer pinged for status over a week ago with no response.
| #1222 | wenxuwan | fix: Handle SSE Disconnects Properly When use starlette middleware | pinged 337d ago | +26-20 | 397d |
Volume
Time to First Review
Merge Time
PRs Needing Maintainer Review
Open PRs with no maintainer review (excludes drafts from counts)
PRs Awaiting Maintainer Review
Sorted by longest wait time first
| PR | Title | Author | Size | Reviews | Waiting |
|---|---|---|---|---|---|
| #1444 | fix: propagate auth errors (401/403) immediately instead of falling b… | xue-cai | +72 -1 | 0 | 169d |
| #1496 | feature: Added configurable token endpoint auth method selection | RobotechUSA | +26 -1 | 0 | 152d |
| #1615 | Allow setting token endpoint auth method on ClientOAuthOptions (#1612) | mikeholczer | +393 -10 | 0 | 92d |
| #1675 | Apply default tool annotation hints from McpServerToolAttribute | goutamadwant | +12 -27 | 0 | 65d |
| #1713 | Allow Streamable HTTP GET reconnection | lntutor | +113 -0 | 0 | 44d |
| #1710 | Allow HttpClient BaseAddress as transport endpoint | lntutor | +105 -25 | 0 | 44d |
| #1723 (draft) | Add app-rendered elicitation support to MCP Apps | krubenok | +1675 -4 | 0 | 40d |
| #1761 | Add custom tool result marshaling | andyst-dev | +34 -1 | 0 | 35d |
| #1760 | Document Windows stdio command-shell parsing | andyst-dev | +20 -0 | 0 | 35d |
| #1780 | Make the alternate-result seam method-agnostic | onatozmenn | +500 -35 | 0 | 31d |
| #1798 | Add typed MCP Apps metadata for resources | wWzZb | +325 -14 | 0 | 25d |
| #1803 | Add McpClientTool.WithResultMarshaling to let hosts control what InvokeAsync returns | PederHP | +130 -5 | 1 | 24d |
| #1802 | Serve the sample authorization server over loopback HTTP | anneheartrecord | +193 -14 | 1 | 24d |
| #1816 | Gate application result fields by protocol version | KirschBluteX | +885 -120 | 1 | 19d |
| #1815 | Add WithAppTool helper for MCP Apps | KirschBluteX | +823 -2 | 0 | 19d |
| #1814 | Compose MRTR input requests with task-backed tools | KirschBluteX | +1497 -307 | 0 | 19d |
| #1822 | Bump System.Linq.AsyncEnumerable from 10.0.10 to 10.0.11 | dependabot | +1 -1 | 0 | 15d |
| #1821 | Bump Microsoft.NET.Test.Sdk, xunit.runner.visualstudio and xunit.v3 | dependabot | +3 -3 | 0 | 15d |
| #1825 | Bump Microsoft.Extensions.Caching.Abstractions from 10.0.10 to 10.0.11 | dependabot | +1 -1 | 0 | 15d |
| #1824 | Bump Microsoft.Extensions.AI.Abstractions from 10.8.3 to 10.9.0 | dependabot | +1 -1 | 0 | 15d |
| #1823 | Bump Microsoft.Extensions.AI from 10.8.3 to 10.9.0 | dependabot | +1 -1 | 0 | 15d |
| #1831 | Keep interactive OAuth flows alive when the triggering request is canceled | PederHP | +739 -24 | 12 | 12d |
| #1829 (draft) | Support configurable subject token types in identity assertion grants | zhenyu-02 | +153 -23 | 0 | 12d |
| #1832 | Fix RequestOptions writing an integer progress token as a JSON string | dfedoryshchev | +21 -1 | 1 | 11d |
| #1833 | test(oauth): extend metadata discovery probe timeout | jstar0 | +84 -61 | 0 | 11d |
| #1834 | Document Streamable HTTP integration testing | luisangelrod | +121 -0 | 0 | 8d |
| #1838 | Close stdio input before waiting for server exit | luisangelrod | +45 -0 | 0 | 6d |
| #1841 | Dispose the POST response in SseClientSessionTransport to stop leaking a connection per message | yalcinfu22 | +59 -1 | 0 | 5d |
| #1843 | Add IMcpTaskExecutor for delegating task execution to an external runtime | trey-herrington | +803 -7 | 9 | 4d |
| #1845 | Use none as the token-endpoint auth method for CIMD public clients | ump45nose | +47 -1 | 0 | 4d |
| #1844 | Surface JSON parse detail in streamable-HTTP 400 responses | ump45nose | +35 -3 | 0 | 4d |
| #1849 | fix: fall back to SSE when AutoDetect probe gets 405 with JSON-RPC error body | ump45nose | +91 -6 | 0 | 0d |
PR Size Distribution
Open PRs by lines changed
Stats — volume, timing, size distribution
Volume
Time to First Review
Merge Time
PR Size Distribution
Open PRs by lines changed
Breakdown by tier
| Tier | Count | Auth | Maint. | ~Time |
|---|---|---|---|---|
| 1 — We're blocking someone | 9 | 4 | 6 | 2.8h |
| 2 — High leverage | 1 | 0 | 0 | 8m |
| 3 — Intake | 27 | 4 | 0 | 13.3h |
| 4 — Hygiene | 2 | 1 | 0 | 10m |
| 5 — Close candidates | 11 | 2 | 0 | 11m |
| total actionable | 50 | 11 | 6 | 16.6h |
| not our move | 8 | — | — | — |
We're blocking someone (9) ⊕ ⊖
Author did what we asked and is waiting on us. Longest-waiting first.
1 SLA author-pinged-after-procedural (1) — Author addressed maintainer feedback and pinged — awaiting response.
| #402 | rinaldofesta | re-reviewfeat(tier-check): validate the submitted SDK release against the target spec version | author pinged @pcarleton 23d ago | +1124-52 | 49d |
2 SLA1 auth needs-re-review (2) — Author pushed changes after review feedback — needs re-review.
| #346 | canardleteer | re-reviewci: smoke-test client CLI path and fix everything-client core drift | push after approval (1 commits, 32d waiting) | +49-100 | 77d |
| #423 | logiscapedev | re-reviewauthfix(auth): add issuer to pre-registration context | push after approval (1 commits, 32d waiting) | +50-3 | 35d |
6 SLA3 auth maintainer-intake (6) — Maintainer-authored PR awaiting review from another maintainer.
| #73 | pcarleton | maintainerAdd SSE polling Phase 2 and Phase 3 tests (SEP-1699) | 273d, no maintainer has looked yet | +691-1 | 273d |
| #106 | pcarleton | maintainerauthfeat: add step-up auth scenario for server auth testing | 230d, no maintainer has looked yet | +346-1 | 230d |
| #203 | pcarleton | maintainerauthfix: rename routePrefix to issuerPath and add issuer-mismatch scenario | 155d, no maintainer has looked yet | +150-20 | 155d |
| #241 | pja-ant | maintainerfeat: conformance scenario for MCP-Protocol-Version header 400 | 132d, no maintainer has looked yet | +461-0 | 132d |
| #350 | pja-ant | maintainerauthfix(sep-2243): scope Mcp-Method to requests only; add Base64 Mcp-Name checks | 75d, community reviewed (LucaButBoring) | +227-8 | 75d |
| #420 | pcarleton | maintainerfeat(cli): --extensions/--exclude-extensions scenario selection | 36d, no maintainer has looked yet | +394-55 | 36d |
High leverage (1) ⊕ ⊖
One decision unblocks or closes multiple things.
1 SLA duplicate-cluster (1 clusters, 2 PRs) — Multiple PRs address the same issue — one will be picked, others closed as duplicates.
Issue #428 — 2 PRs ⭐ #455 (I was unable to retrieve live data for either PR — the `gh pr view` commands for #455 and #469 required approval that wasn't granted, so I have no confirmed CI status, test coverage, or diff details to compare. Based solely on the titles provided: #455 ("bound the session-id probe and release its response body") is the lower-numbered (older) PR, which is the tiebreaker criterion when CI status and test coverage are both unknown/unverified. This pick should be treated as provisional — please confirm CI status and diff specifics before merging, since I could not verify them directly.)
| #455 | aviseth | 1st-reviewfix(lifecycle): bound the session-id probe and release its response body | cluster primary for issue #428 (2 PRs) | +56-1 | 20d |
| #469 | jstar0 | fix: bound raw session ID initialize probe | shares linked issue #428 with #455 | +34-3 | 6d |
Intake (27) ⊕ ⊖
PRs not yet reviewed by a maintainer. Oldest first.
20 SLA4 auth needs-first-review (25) — Not yet reviewed by a maintainer.
| #264 | app/dependabot | 1st-reviewchore(deps): bump the npm_and_yarn group across 2 directories with 1 update | 118d | +14-14 | 118d |
| #330 | panyam | 1st-reviewfeat(sep-2640): skills server conformance — index, manifest, directory scenarios | 90d | +2522-2 | 90d |
| #340 | jstar0 | 1st-reviewSend initialized notification in DNS rebinding scenario | 78d | +286-4 | 78d |
| #358 | jstar0 | 1st-reviewFix custom-header schema freshness | 74d | +86-4 | 74d |
| #380 | canardleteer | 1st-reviewFix tools-name-format for spec Tool Names SHOULD rules on 2025-11-25+ | 62d | +293-33 | 62d |
| #381 | canardleteer | 1st-reviewAdd json-rpc-batch-rejection scenario for 2025-06-18+ | 62d | +509-0 | 62d |
| #392 | howardjohn | 1st-reviewtest_streaming_elicitation: use proper SSE instead of NDJSON | 57d | +53-56 | 57d |
| #395 | PieterKas | 1st-reviewauthServer Auth: DPoP Proof Validation (SEP-1932) | 56d | +4517-5 | 56d |
| #396 | PieterKas | 1st-reviewauthAuthorization Server: DPoP Support (SEP-1932) | 56d | +3770-5 | 56d |
| #411 | hashemix | 1st-reviewfix(tier-check): extract semver from monorepo release tags, add --tag-prefix | 37d | +278-29 | 38d |
| #432 | shoemoney | 1st-reviewfeat: add swift-sdk to the built-in SDK matrix | 32d | +31-1 | 32d |
| #442 | marcus-kepler-92 | 1st-reviewfix(input-required-result): report the capability check as untestable when nothing is requested | 28d | +54-4 | 28d |
| #449 | elang2 | 1st-reviewfeat: add logging conformance scenarios (capability, invalid level, threshold filtering) | 24d | +484-0 | 24d |
| #450 | elang2 | 1st-reviewfeat: add cancellation and progress notification conformance scenarios | 24d | +684-32 | 24d |
| #454 | aviseth | 1st-reviewfix(runner): bound server scenarios with a per-scenario timeout | 20d | +105-4 | 20d |
| #457 | koic | 1st-reviewfeat: add ruby-sdk to the known SDKs registry | 18d | +33-1 | 18d |
| #462 | lucarlig | 1st-reviewfix(everything-server): normalize streamed tool responses | 15d | +80-39 | 14d |
| #463 | hwkiem | 1st-reviewfix(tier-check): strip package-name prefixes from monorepo release tags | 14d | +133-1 | 14d |
| #464 | LucaButBoring | 1st-reviewfeat: add MCP version compatibility scenarios | 14d | +1246-20 | 14d |
| #466 | tylerklose | 1st-reviewauthfeat(authorization): send the RFC 8707 `resource` parameter | 11d | +151-0 | 11d |
| #468 | jstar0 | fix(validation): accept extension result envelopes | 6d | +34-8 | 6d |
| #473 | benoitc | fix(validation): validate a task-augmented result against the tasks extension schema | 3d | +3260-5 | 3d |
| #476 | JosephDoUrden | fix(http-base): return valid empty results for unhandled list methods | 2d | +195-3 | 2d |
| #479 | dulrajnr | Docs: optional TOA verify after conformance | 2d | +76-0 | 2d |
| #481 | SamMorrowDrums | authfeat(server): add SEP-2350 scope challenge scenario | 1d | +1193-75 | 1d |
2 SLA community-reviewed (2) — Community members have reviewed, but no maintainer has engaged yet.
| #405 | brixton-guns | 1st-reviewAdd client conformance for SEP-2663 task results | 44d, reviewed by LucaButBoring (SLA breach) | +557-23 | 44d |
| #444 | halter73 | 1st-reviewfix(sep-2243): reject x-mcp-header on number-typed params | 27d, reviewed by JosephDoUrden (SLA breach) | +72-4 | 27d |
Hygiene (2) ⊕ ⊖
Batchable procedural ops — pings, rebases, peer reviews.
1 auth stale-awaiting-author (2) — Changes requested over two weeks ago with no author response.
| #139 | jdmaturen | authfeat: add token refresh and rotation conformance scenarios | 200d since feedback | +612-47 | 205d |
| #375 | maxisbey | fix(sse-retry): gate retry timing only on the early side | author self-diagnosed CI 63d ago, never fixed | +11-36 | 63d |
Close candidates (11) ⊕ ⊖
Likely to be closed — inactive, stale, or needing more context. Reviewed before closing.
2 auth pre-ci-ghost (11) — Over 90 days old and CI never ran.
| #64 | tobinsouth | authAdd server OAuth protection conformance tests | CI never ran, 279d old | +4101-9 | 279d |
| #155 | wdawson | authImprovements to the Draft Server Auth Conformance tests | CI never ran, 194d old | +8122-2049 | 194d |
| #165 | lux999 | fix: tools-call-simple-text now fails when tool returns isError: true | CI never ran, 190d old | +10-2 | 190d |
| #222 | codefromthecrypt | Add stateless server conformance test | CI never ran, 145d old | +609-1 | 144d |
| #224 | alexdoroshevich | feat: add version negotiation conformance tests (closes #102) | CI never ran, 142d old | +1210-0 | 142d |
| #257 | malladinagarjuna2 | feat: Add multi-stage Docker build and GHCR publishing workflow | CI never ran, 128d old | +86-0 | 128d |
| #263 | blackwell-systems | fix(tier-check): swap server/client scenario lists in conformance reconciliation | CI never ran, 119d old | +7-7 | 119d |
| #299 | adityachilka1 | fix(initialize scenario): return 202 No Content for notifications (closes #274) | CI never ran, 103d old | +6-0 | 103d |
| #325 | rinaldofesta | feat(scenarios/server): cover the two untested SEP-2243 server param-presence requirements | CI never ran, 93d old | +248-5 | 93d |
| #326 | rinaldofesta | feat(client): add session renegotiation on HTTP 404 conformance scenario | CI never ran, 93d old | +560-0 | 93d |
| #327 | rinaldofesta | Standardize scenario setup/execution failure reporting (#248) | CI never ran, 92d old | +193-49 | 92d |
Not our move (8) ⊕ ⊖
Clock is on the author or blocked externally. No action owed today.
2 auth stale-draft (4) — Draft with no activity for over a week.
| #308 | olaservo | feat: add SEP-2106 structuredContent wire-shape scenario (complements #295) | draft idle 102d | +679-0 | 102d |
| #393 | app/claude | authAdd client check: preserve query params in protected resource metadata discovery URL | draft idle 57d | +286-15 | 57d |
| #400 | app/claude | authclient/dpop: follow-ups from review (stacked on #394) | draft idle 54d | +520-123 | 54d |
| #410 | maxisbey | fix(sep-2575): report a schema-valid serverInfo accurately, and count warnings in the server summary | draft idle 41d | +193-18 | 41d |
1 auth parked (4) — Maintainer draft >30d, intentionally shelved.
| #105 | pcarleton | authfeat: Add server auth conformance tests | maintainer draft, 230d | +1756-55 | 230d |
| #137 | pcarleton | feat: add notification isolation tests for GHSA-345p-7cg4-v4c7 | maintainer draft, 208d | +1607-19 | 208d |
| #351 | pja-ant | feat: SEP-2575 subscriptionId value assertion + server-sent cancelled restriction | maintainer draft, 75d | +184-22 | 75d |
| #352 | pja-ant | feat(sep-2243): add x-mcp-header static-reachability checks | maintainer draft, 75d | +331-6 | 75d |
Volume
Time to First Review
Merge Time
PRs Needing Maintainer Review
Open PRs with no maintainer review (excludes drafts from counts)
PRs Awaiting Maintainer Review
Sorted by longest wait time first
| PR | Title | Author | Size | Reviews | Waiting |
|---|---|---|---|---|---|
| #103 | Add Python package MCP server example with bundling support | stephaneberle9 | +256 -6 | 0 | 351d |
| #134 | chore(lint): upgrade ESLint prettier rule to error | loc | +2 -3 | 3 | 308d |
| #170 | build(deps): bump tar from 7.5.1 to 7.5.2 in the npm_and_yarn group across 1 directory | dependabot | +3 -3 | 0 | 271d |
| #181 | fix(Validation): Make "mcp_config" optional when using uv | daemuth | +122 -52 | 0 | 226d |
| #195 | Fix PKCS#7 signature verification | vcolin7 | +190 -61 | 0 | 192d |
| #222 | feat: add prepare-for-signing and apply-signature for enterprise HSM signing | bryan-anthropic | +519 -1 | 1 | 158d |
| #227 | fix: validate version field is valid semver | bryan-anthropic | +112 -0 | 1 | 140d |
| #237 | Fix `approrpiate` -> `appropriate` typo in MANIFEST.md | pikammmmm | +1 -1 | 1 | 122d |
| #242 | fix: add field descriptions to v0.4 manifest schema | pl4nty | +108 -44 | 1 | 114d |
| #253 | fix: keep runtime files in mcpb packages | he-yufeng | +33 -2 | 0 | 93d |
| #252 | fix: resolve user config placeholders | he-yufeng | +74 -8 | 0 | 93d |
| #254 | fix: preserve zip modes when packing on Windows | he-yufeng | +100 -16 | 0 | 93d |
| #255 | fix: make `mcpb verify`/`info` actually verify PKCS#7 signatures | andy-liner | +141 -44 | 1 | 92d |
| #259 | Fix $-pattern corruption of user_config values in replaceVariables | aosmcleod | +14 -1 | 2 | 85d |
| #257 | Add npm source and issue metadata | wowsofine | +8 -0 | 1 | 85d |
| #274 | Redact secrets from substitution warning; fix manifest version precedence | aosmcleod | +74 -14 | 0 | 85d |
| #273 | Bound mcpb unpack against decompression bombs and malformed central directories | aosmcleod | +149 -36 | 0 | 85d |
| #272 | Drop platform_overrides from resolved mcp_config; honour empty-string overrides | aosmcleod | +75 -2 | 0 | 85d |
| #271 | Preserve unknown nested manifest keys in loose schemas (mcpb clean) | aosmcleod | +266 -169 | 0 | 85d |
| #270 | Make server.mcp_config optional for uv server type (strict 0.4 schema) | aosmcleod | +53 -6 | 0 | 85d |
| #269 | Escape regex metacharacters in the variable key during substitution | aosmcleod | +26 -1 | 0 | 85d |
| #268 | Skip directory entries when unpacking (fixes mcpb unpack on standard ZIP archives) | aosmcleod | +49 -0 | 0 | 85d |
| #286 | Verify signed MCPB bundles | jstar0 | +179 -109 | 0 | 74d |
| #293 | fix: skip symlink cycles during pack instead of failing with ELOOP | gagan-53 | +154 -2 | 0 | 50d |
| #295 | docs: add Korean MCP setup guide for Claude Desktop | pluslove0557-stack | +276 -0 | 0 | 46d |
PR Size Distribution
Open PRs by lines changed
Volume
Time to First Review
Merge Time
PRs Needing Maintainer Review
Open PRs with no maintainer review (excludes drafts from counts)
PRs Awaiting Maintainer Review
Sorted by longest wait time first
| PR | Title | Author | Size | Reviews | Waiting |
|---|---|---|---|---|---|
| #189 | fix: defer initial size measurement to ResizeObserver | nidhiyashwanth | +1 -2 | 0 | 255d |
| #214 | Examples: D3 graph and Recharts chart | iamfiscus | +3265 -18 | 0 | 236d |
| #273 | Enforce correct UI resource. Remove backwards compatibility in `getToolUiResourceUri`. | matteo8p | +6 -25 | 0 | 230d |
| #291 | chore: :lock: npm audit fix | james-lafferty | +24 -3 | 0 | 228d |
| #296 | Add Resource Template support to basic-host | rinormaloku | +23 -6 | 0 | 227d |
| #378 | Create initial proposal for apps declaring trusted types | connor4312 | +124 -3 | 0 | 217d |
| #377 | build(deps): bump hono from 4.11.6 to 4.11.7 in the npm_and_yarn group across 1 directory | dependabot | +3 -387 | 0 | 217d |
| #390 | Add a pattern for a deferred tool resulting using UI interaction | connor4312 | +213 -1 | 0 | 216d |
| #384 | fix: update Playwright snapshots for ShaderToy and Wiki Explorer | yaniv-golan | +0 -0 | 0 | 216d |
| #405 | New example MCP App: DICOM Viewer | ThalesMMS | +1707 -1 | 6 | 214d |
| #425 (draft) | Fetch That Works in MCP Apps | MiguelsPizza | +9835 -630 | 0 | 210d |
| #424 | Add cross-host portability guide for MCP Apps | hatgit | +75 -0 | 0 | 210d |
| #432 | fix(examples): resolve CSP 'unsafe-eval' violation in threejs-server | Robloncz | +32 -10 | 2 | 208d |
| #453 | feat: Add basic-server-angular example | Avcharov | +17874 -6785 | 0 | 200d |
| #468 | Add Stitch Design server example | jayeshvpatil | +3512 -0 | 0 | 195d |
| #473 | Rename apps.mdx to ext-apps.mdx | jabidahscreationssystems | +0 -0 | 0 | 194d |
| #531 | Feat/create elicitation UI | Avcharov | +377 -24 | 0 | 179d |
| #553 | feat(spec): add renderTiming to McpUiToolMeta for deferred View rendering | netanelavr | +113 -0 | 0 | 170d |
| #596 | Add tananchadevelopment.link file | Bang2985 | +0 -0 | 0 | 152d |
| #608 | Rename tsconfig.json to tsconfig.json | akonjet5 | +0 -0 | 0 | 144d |
| #609 | --- name: create-mcp-app description: This skill should be used when … | akonjet5 | +185 -0 | 0 | 144d |
| #610 | example dotnet angular host | halllo | +10826 -1 | 0 | 143d |
| #636 | feat: add angular basic example | dalenguyen | +2319 -3 | 0 | 132d |
| #641 | feat(transport): add forHostIframe helper and improve init timeout message | netanelavr | +168 -0 | 0 | 127d |
| #656 | feat(types,spec): add tools field to McpUiHostCapabilities | saaage | +17 -0 | 1 | 117d |
| #663 | Allows passing input as a query param like other options from the demo app | katerberg | +13 -6 | 0 | 103d |
| #690 | Add linkTrustedDomains view property | fredericbarthelet | +182 -27 | 3 | 76d |
| #691 | feat: add support for 'tools' permission | beaufortfrancois | +63 -1 | 0 | 75d |
| #695 | fix: don't fail install when running npm install in an example workspace (#687) | d-turley | +159 -11 | 0 | 61d |
| #705 | fix: add explicit .js extensions to relative imports so declarations resolve under NodeNext/Node16 | ken-jo | +35 -35 | 0 | 52d |
| #717 | Relax double sandboxed iframe architecture requirements | domfarolino | +67 -24 | 1 | 47d |
| #718 | Move basic-host and infra, to single sandboxed iframe architecture | domfarolino | +26 -144 | 0 | 46d |
| #720 (draft) | Migrate to SDK v2 with official Protocol and isolated role peers | tonxxd | +2415 -1867 | 1 | 43d |
| #719 (draft) | Migrate to SDK v2 with a core-only Apps protocol | tonxxd | +3277 -1492 | 0 | 43d |
| #722 | feat: MCP App validator (library + CLI) — reference implementation for #673 | RyanAlberts | +1663 -0 | 0 | 42d |
| #726 | Add conformance-server + importable conformance runner (addresses #674) | qchuchu | +2840 -5 | 0 | 40d |
| #728 | fix: include portal content in auto-resize | federgilad | +132 -6 | 5 | 39d |
| #733 | Support MCP Apps-rendered Elicitations | krubenok | +862 -31 | 5 | 34d |
| #736 (draft) | docs: add contextual launch pattern | Chipagosfinest | +125 -0 | 1 | 32d |
| #735 | docs(csp-cors): note that a rejected ui.domain stops the app rendering | Booyaka101 | +5 -0 | 0 | 32d |
| #739 | spec(draft): add split display mode | caseprince | +301 -23 | 0 | 28d |
| #749 | fix: prefer tool title in app view chrome | Chipagosfinest | +8 -2 | 0 | 15d |
| #748 | feat: add app homepage resource metadata | Chipagosfinest | +64 -2 | 0 | 15d |
| #751 | feat: add UI preload and result-driven close controls | sunnymitramsft | +262 -3 | 0 | 11d |
| #752 | docs: update client capabilities for MCP 2026-07-28 | dawNotPoi | +92 -42 | 0 | 9d |
| #763 | Update SKILL.md | PAJO2018 | +1 -1 | 0 | 2d |
PR Size Distribution
Open PRs by lines changed