Update stacklok/toolhive to v0.44.0 - #1113
Conversation
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Claude finished @renovate[bot]'s task in 11m 52s —— View job Upstream release docs sync — toolhive v0.44.0Ran the
Content changes
Skipped PRs (rationale in
|
Add an "Accept subject tokens from external issuers" section to both the vMCP and Kubernetes embedded auth server guides, covering the new `trustedIssuers` CRD field shipped in toolhive v0.44.0 (stacklok/toolhive#6353) that lets the RFC 8693 token-exchange grant accept subject tokens minted by an external OIDC issuer. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
|
Claude finished @renovate[bot]'s task in 2m 36s —— View job Editorial review of upstream release docs
Todos
Files under review:
|

This PR contains the following updates:
v0.43.0→v0.44.0After this PR opens,
.github/workflows/upstream-release-docs.ymladds source-verified content edits for the new release. Forstacklok/toolhive, the same workflow also syncs reference assets (CLI help, Swagger) and regenerates the CRD MDX pages.Release Notes
stacklok/toolhive (stacklok/toolhive)
v0.44.0Compare Source
What's Changed
Full Changelog: stacklok/toolhive@v0.43.0...v0.44.0
Configuration
📅 Schedule: (in timezone America/New_York)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Never, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.
Docs update for
toolhivev0.44.0At a glance
stacklok/toolhivev0.43.0→v0.44.0Who does what
@jerm-dro cut this release and owns this PR: review your own changes, chase the remaining approvals, and merge once they're in. You don't need to wait on a review from anyone listed as having no docs impact below.
Everyone with a review request: the target is a review and approval within 2 business days.
Summary of changes
docs/toolhive/guides-k8s/embedded-auth-server-k8s.mdx, covering the newtrustedIssuersCRD field onMCPExternalAuthConfig.spec.embeddedAuthServer(external OIDC issuers, per-issuerallowedActors/allowedDelegateClients/actorClaim, and theallowMayActopt-in) from Harden external may_act delegation toolhive#6353.docs/toolhive/guides-vmcp/embedded-auth-server-vmcp.mdx, coveringtrustedIssuersunderVirtualMCPServer.spec.authServerConfigand linking back to the Kubernetes guide for the full field list and trust model.actor_tokenin RFC 8693 token exchange) — request-time/oauth/tokenparameter with no CLI/CRD surface; already covered by upstream's design doc, and the docs don't shadow that layer.INSECURE_DISABLE_URL_VALIDATIONbehavior is not user-facing in these docs (the env var isn't mentioned anywhere).--oidc-audienceis already recommended in thethv servedocs.thvpath in Claude Desktop shim) — bug fix;thv llm setupis only surfaced in auto-generated CLI reference.--no-sign) — internal CI workflow only.No docs impact identified
@samuv - your changes in this release didn't appear to affect the docs, so no review is requested and you're not blocking this PR. Please skim the diff anyway and comment if something of yours was missed or misjudged.
Run cost
How this PR was built
Two Claude Opus sessions run per release: a generation pass
(
upstream-release-docsskill, 6 phases) followed by a fresh-context editorial pass (
docs-review). Prettier/ESLintauto-fixes are applied after.
Auto-synced paths — do not hand-edit these in review:
static/api-specs/docs/toolhive/reference/cli/(toolhive only)docs/toolhive/reference/crds/If a "Gaps needing human context" section is present above,
each entry includes a paste-ready Helper prompt for local
Claude a reviewer can use to resolve the gap.