Release 1.32.1 - Forward-Proxy TLS, an mcp 2.x Pin, and Collector Health
October 2026
Upgrading from 1.32.0
This section covers everything you need to know to upgrade from 1.32.0 to 1.32.1.
Breaking Changes
There are no breaking changes in this release.
New Environment Variables
No new environment variables in this release.
Upgrade Instructions
Docker Compose
cd mcp-gateway-registry
git pull origin main
git checkout 1.32.1
./build_and_run.shKubernetes / Helm (EKS)
The chart values now carry the 1.32.1 image tags, so rebuild chart dependencies before you upgrade. The packaged subcharts under charts/mcp-gateway-registry-stack/charts/ are gitignored and only repackage when you run these commands, so a plain helm upgrade would deploy the previous subcharts.
cd mcp-gateway-registry
git pull origin main
git checkout 1.32.1
cd charts/mcp-gateway-registry-stack
helm dependency build
helm dependency update
helm upgrade mcp-gateway . -f your-values.yamlTerraform / ECS
cd mcp-gateway-registry
git pull origin main
git checkout 1.32.1
cd terraform/aws-ecs
terraform plan
terraform applyWhat's New
Dependency Updates
- Refreshed the weekly lockfiles across the registry and the bundled example servers (#1850)
- Bumped the CI actions group:
github/codeql-action/upload-sarifandbridgecrewio/checkov-action(#1848)
Bug Fixes
-
Outbound requests through a plain
http://forward proxy failed wheneverEGRESS_FORWARD_PROXY_CA_BUNDLEwas set. httpcore rejectsproxy_ssl_contextfor thehttpscheme and raises while it constructs the delegate transport, so the request never left the process. The registry now attaches the context only for anhttps://proxy. The upstream leg inside the tunnel still takes the bundle fromverify, so nothing is lost for a plain proxy, which has no TLS leg of its own (#1852, closes #1849) -
Capped
mcpbelow 2.0. mcp 2.x renamesstreamable_http.streamablehttp_clienttostreamable_http_clientwith no back-compat alias, which breaksregistry/core/mcp_client.pyon import. The weekly lockfile refresh in #1850 had pulled in mcp 2.1.1. Moving to 2.x needs the 2.0 changelog reviewed for other behavior changes, so it is tracked separately. The same PR completed the server-repository test mock (#1853) -
The
otel-collectorcontainer reported a permanent falseunhealthystatus indocker ps. Its healthcheck shelled out towget, which the distroless collector image does not ship, so every probe exited-1while the collector ran normally. The healthcheck is gone, and the comment indocker-compose.ymlrecords why the service has none. Liveness stays visible through the Prometheus scrape of:8889and thehealth_checkextension on:13133(#1854)
Closed Issues
| Issue | Title | Closed By |
|---|---|---|
| #1849 | url_guard: proxy_ssl_context passed to an http:// forward proxy when EGRESS_FORWARD_PROXY_CA_BUNDLE is set (1.32.0)
| PR #1852 |
Pull Requests Included
| PR | Title |
|---|---|
| #1854 | fix(compose): drop the impossible otel-collector healthcheck |
| #1853 | fix(deps,tests): cap mcp below 2.0 and complete the server-repository mock |
| #1852 | fix(url_guard): withhold proxy_ssl_context from an http:// forward proxy |
| #1850 | chore(deps): weekly lockfile update (2026-10-05) |
| #1848 | chore(deps): bump the actions group in /.github/workflows with 2 updates |
Security Dependency Updates
| Package | Previous | Updated | Scope |
|---|---|---|---|
| github/codeql-action/upload-sarif | v4.38.1 | v4.38.2 | CI workflows |
| bridgecrewio/checkov-action | v12.3125.0 | v12.3126.0 | CI workflows |
| mcp | >=1.9.3 | >=1.9.3,<2 | Registry runtime |
Contributors
Thank you to all contributors for this release:
- Amit Arora (@aarora79)
Support
Full Changelog: 1.32.0...1.32.1