Share watchdog timeout assessments for the MCP foundation #1598
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/mcp-timeout-watches"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
This is the timeout foundation only. It does not implement or enable the MCP endpoint.
Validation
MCP dependency blocker
The ExMCP 1.3.0 dependency probe selected Cowlib 2.20.0 through mandatory Plug.Cowboy. The audit failed on EEF-CVE-2026-43966, EEF-CVE-2026-43969, and EEF-CVE-2026-43971. The probe was removed: mix.lock is unchanged and no audit exceptions were added.
The MCP transport, OAuth service, sessions, tools, command receipts, and watches remain pending a dependency decision. A possible solution is a pinned ExMCP fork that makes the unused Cowboy transport optional. This PR does not introduce that fork or change production configuration.
Pull request closed