Repository navigation
[finding] upgrading a consumer from 17.4.0 to 17.5.0 keeps hono@4.13.3 on the @objectstack/cli → @objectstack/mcp → @modelcontextprotocol/sdk path — the raised hono floor does not reach it #20622
Description
Activity
objectstack-fleet commented
on Sep 29, 2026 ContributorMore actionsPath: the road's upgrade step — an upgrader's tree is as clean as the release note says | 缺项 (a lockfile-preserving upgrade keeps
hono@4.13.3under@modelcontextprotocol/sdk, a copy objectstack never loads) | P3Triage: first grade —
documentation·dependencies·priority:p3·domain:devx·area:devpath·pm:on-hold. Direction: one upgrade line, not a dependency declaration. It rides the maintainer's 17.5.0-aftercare callTriage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-09-29T10:05Z. ⛔ Not a claim, ⛔ not a dispatch.toolingcomes off: the card names noUnblocks:target, and its deliverable is text for upgraders.Measured on the published 17.5.0 packages
-
The dependency path.
@objectstack/cli@17.5.0depends on@objectstack/mcp@17.5.0, which declares@modelcontextprotocol/sdk ^1.30.0.- The SDK (1.30.0 and 1.31.0 alike) declares
hono ^4.11.4. @objectstack/plugin-hono-server@17.5.0declareshono ^4.13.5.
-
The advisories (npm's bulk advisory endpoint).
honobelow 4.13.5 carries three moderate advisories:- GHSA-gqvv-2mrq-wpjv (
toSSG()path traversal); - GHSA-g6gw-c38x-mqfc (
parseBody()nesting); - GHSA-crvj-82cr-hjcx (the query parser reading past the fragment).
4.13.5 and 4.13.11 answer none.
- GHSA-gqvv-2mrq-wpjv (
-
Installed, never loaded.
- The published
@objectstack/mcp@17.5.0distimports only the SDK'sserver/mcp.js,server/stdio.js,server/webStandardStreamableHttp.jsandtypes.js. - In the SDK 1.30.0 tarball, the only modules that import
honoor@hono/node-serverareserver/streamableHttp.jsand an example, and objectstack imports neither. - ⇒ No objectstack code path loads the stale copy, so there is no
securitylabel. The harm is a consumer's own scanner going red, plus a release note an upgrader reads as covering their whole tree.
- The published
-
Only a preserved lockfile keeps it. A fresh install resolves
^4.11.4to 4.13.11.
Direction
- ⛔ Not the first ask.
- A direct
honofloor on@objectstack/mcpwould declare a dependency the package never imports. - pnpm resolves the SDK's own
honorange for the SDK. So under a preserved lockfile, the SDK's entry is not expected to move.
- A direct
- Take the second ask, as one line for upgraders. In substance: the raised floors cover what objectstack loads. A lockfile-preserving upgrade can keep an older
honounder@modelcontextprotocol/sdk, which objectstack never loads.pnpm update hono, or the equivalent for your package manager, clears a scanner. - The vehicle is the maintainer's open 17.5.0-aftercare call ([finding] release.yml: every main landing between the version-PR merge and the approval queues a new publish deployment, evicts the waiting one, and ships main's head instead of the version commit — ADR-0125 D1's premise does not hold #20613): annotate the 17.5.0 notes, or cut 17.5.1 with the unconsumed changesets. Both are one line, and this card must not pick between them.
Restart-when: the maintainer's 17.5.0-aftercare call is recorded. If the call is to annotate, this line joins that annotation. If it is 17.5.1, this line goes into that release's changeset text.
-
- addedarea:devpathThe road — create, dev, verify, publish/install, connect an agent, iterateThe road — create, dev, verify, publish/install, connect an agent, iteratedependenciesPull requests that update a dependency filePull requests that update a dependency filedocumentationImprovements or additions to documentationImprovements or additions to documentationand removed
on Sep 29, 2026 objectstack-fleet commented
on Sep 29, 2026 ContributorMore actionsTriage:
pm:on-hold→pm:queue, regraded p3 → p2. The 17.5.0-aftercare call is made; this card now carries the next release's aftercare changesetTriage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-09-29T15:31Z. ⛔ Not a claim, ⛔ not a dispatch.Provenance. This is executed on the maintainer's call. In the triage seat's chat (session
session_01AavokzJ5DndAwitDXvKy4U), asked "annotate the 17.5.0 notes, or cut 17.5.1", the maintainer replied, verbatim: 「可以发 17.5.1 ,但是你应该统一看一下有哪些遗留问题需要发版本之前解决」. So this card'sRestart-when:is met: the call is a follow-up release, and the hono line goes into that release's changeset text.Measured: the next version is 17.6.0, not a patch. The open Version Packages PR #20639 computes
17.6.0for the whole fixed group.maincarries 44 pending changesets.- 16 of them already shipped inside 17.5.0, unannounced. They were added between the version commit
8c87d26a5dand the published head0f6dcac5e9([finding] release.yml: every main landing between the version-PR merge and the approval queues a new publish deployment, evicts the waiting one, and ships main's head instead of the version commit — ADR-0125 D1's premise does not hold #20613's defect, fixed by PR fix(release): queue the publish only on the push that carries the version commit, and publish that commit (ADR-0125 D1 amended) #20625). 6 areminor, and 3 carry breaking notes (PR feat(spec)!: retire the inner name on cube measures and dimensions — the record key is the member's name (#20300) #20458, PR fix(spec,driver-turso)!: refuse a forced mode replica with no syncUrl at authoring and at construction (#20437) #20504, PR feat(spec)!: RealtimeEventType names the emitted data.record.* / data.records.* vocabulary (#20288) #20567). - 28 are new. 8 of them are
minor, which is why the computed version is17.6.0. The maintainer is being told the number in chat; ⛔ this card does not pick it.
The deliverable: one
patchchangeset, so it rides whichever version the maintainer ships, in two parts:-
An upgrade line (the original ask). In substance: the raised dependency floors cover what objectstack loads. A lockfile-preserving upgrade can keep an older
honounder@modelcontextprotocol/sdk, which objectstack never loads, andpnpm update hono(or the equivalent) clears a scanner. -
A "shipped in 17.5.0 without notes" section. It names these 16 entries by their PRs, so a reader of the new CHANGELOG knows they were already live in 17.5.0. The 3 with breaking notes are called out first:
- PR feat(spec)!: retire the inner name on cube measures and dimensions — the record key is the member's name (#20300) #20458, PR fix(spec,driver-turso)!: refuse a forced mode replica with no syncUrl at authoring and at construction (#20437) #20504, PR feat(spec)!: RealtimeEventType names the emitted data.record.* / data.records.* vocabulary (#20288) #20567 (breaking);
- PR fix(spec,cli): os validate / os build read the ADR-0087 conversions defineStack applied — --json conversions and --strict see the producer's record #20579, PR feat(sdui-parser): the manifest marks the html tier's intrinsic tags
tier: 'html', ported from objectui's lockstep copy #20582, PR fix(service-automation,metadata-protocol,metadata,runtime): withhold a flow's inbound-hook secret from every served definition, and keep it on a round trip (#20552) #20585; - PR fix(spec): os migrate meta guidance for fourteen more migration-entry families states each lesson in words, not tracker numbers (stage 7) #20568, PR refactor(spec): step 18 rationale as key-sorted fragments, conversionIds derived, so two retirements merge clean #20572, PR docs(spec): re-anchor the dead tracker citations in ui/ and two freed sites to the commits that decided them (stage 5) #20576, PR fix(spec,objectql): name the aggregated column at
having, PostgreSQL only atwhere#20577, PR fix(plugin-security): an organization-less permission-set read resolves organization-less rows only #20584, PR fix(spec): nextUtcCalendarDay and utcInstantMs read years 0001..0099 as written, not as 1900..1999 (#20550) #20591, PR fix(plugin-security): security/explain answers enforcement's refusal for a row-level policy comparing two fields of no shared comparison class #20598, PR fix(plugin-audit): describe sys_comment reactions and mentions by the shape they store (#20558) #20605, PR docs(spec): re-anchor the dead tracker citations in the packages/spec/src remainder to the commits and ADRs that decided them (stage 6) #20606.
PR feat(spec)!: RealtimeEventType names the emitted data.record.* / data.records.* vocabulary (#20288) #20567 carries two changesets.
- ⛔ Don't edit or delete the 16 changesets. Their own text is correct; only their release was early. ⛔ No security detail beyond the PR titles.
Why p2. It gates the release: the notes must be true when the version ships. It lands before the Version Packages PR merges.
- 16 of them already shipped inside 17.5.0, unannounced. They were added between the version commit
- addedpriority:p2Medium: important, M3Medium: important, M3and removed
on Sep 29, 2026 objectstack-fleet commented
on Sep 29, 2026 ContributorMore actionsClaim: PM loop round 17
Session:session_01VDtqoecgES7ScQYGbFVDRv
Branch:claude/issue-20622-release-aftercare-changeset
Worktree:objectstack-issue-20622
Domain:domain:devx
Seat:domain:devx#1
File surface:- one NEW
patchchangeset under.changeset/, holding (1) the upgrade line forhonounder@modelcontextprotocol/sdkand (2) the "shipped in 17.5.0 without notes" section naming the 16 entries by PR, with the 3 breaking ones first; - ⛔ no edit or delete of any existing changeset, and no code.
Stop on a breach and explain it in the report.
Container & model:S(one new changeset file),mode:subagent,model: sonnet
Clause-②: no (release-note text only).
Thread-read: 5893392023
Serial constraints cleared: board read at 2026-09-29T15:50Z. The deliverable is a new file, so it has no hunk overlap with any open PR. Ordering: it must land before the Version Packages PR #20639 merges. The dev re-measures the 16 entries against8c87d26a5d..0f6dcac5e9onorigin/main6bff748bbdand does not copy the list from the thread.Priority rule 3 reading: this is release-notes correctness, not a tooling or contract-hygiene card. Under NORTH-STAR rule 4, a published CHANGELOG that omits 3 breaking changes is a wrong sentence in published docs, so rule 3 does not hold it. Triage
5893392023grades it p2 because it gates the release.
Generated by Claude Code
- one NEW
objectstack-fleet commented
on Sep 29, 2026 ContributorMore actionsos-dev-report
{ "issue": 20622, "status": "done", "branch": "claude/issue-20622-release-aftercare-changeset", "pr": "https://github.com/objectstack-ai/objectstack/pull/20667", "head_sha": "5a42c6234491bce0a9fe9a3d94cc6544ee86cfc8", "session": "session_01VDtqoecgES7ScQYGbFVDRv", "premise_still_valid": true, "summary": "One new patch changeset (@objectstack/cli, fixed group confirmed) with the hono upgrade line and a 'shipped in 17.5.0 without notes' section of 16 entries (15 PRs), breaking first. PR 20639 was still open and unmerged when checked.", "measured_entries": { "count": 16, "distinct_prs": 15, "diff_vs_triage": "Count and breaking set match the triage (16; breaking PR 20458, PR 20504, PR 20567 with two changesets). The brief's literal range 8c87d26a5d..0f6dcac5e9 yields only 8 files; the other 8 were added before the version commit and left unconsumed by it (the tree at 8c87d26a5d still holds them). The correct set is the changeset directory at 0f6dcac5e9 intersected with origin/main.", "breaking_prs": [20458, 20504, 20567], "prs": [20458, 20504, 20567, 20568, 20572, 20576, 20577, 20579, 20582, 20584, 20585, 20591, 20598, 20605, 20606] }, "gates": "19 derived by dispatch-gates --commands, all exit 0; --ran reconciliation 19 derived, 19 run, 0 NOT-MEASURED, 0 UNRUN; check-changeset-fixed green. First pass exit 3 on 3 gates (node_modules missing), rerun green after pnpm install --frozen-lockfile.", "code_anchors": [ "packages/mcp/package.json:29 depends on @modelcontextprotocol/sdk ^1.30.0", "packages/cli/package.json:74 depends on @objectstack/mcp", "packages/plugins/plugin-hono-server/package.json:27 hono ^4.13.5", "packages/mcp/src imports only server/mcp, server/stdio, server/webStandardStreamableHttp, types from the SDK; zero hits for server/streamableHttp" ], "mcp_calls": "2 read-only (pull_request_read, list_pull_requests)", "api_writes": "2 via fleet relay: pr_create (draft, PR 20667) and this report comment; plus git push of the branch", "open_questions": [], "out_of_scope_findings": [] }Reported at 2026-09-29T16:02Z.
- added a commit that references this issue
on Sep 29, 2026 objectstack-fleet commented
on Sep 29, 2026 ContributorMore actionsLanded: PR #20667 →
bae38590a8, verified onorigin/mainby content at 2026-09-29T16:40Z..changeset/20622-release-aftercare-upgrade-and-unannounced-notes.md('@objectstack/cli': patch) is onmainand still pending, so the Version Packages PR chore: version packages #20639 will consume it into the next release's notes.- Part 1, the upgrade line: the raised
hono ^4.13.5floor covers what objectstack loads. A lockfile-preserving upgrade can keep an olderhonounder@modelcontextprotocol/sdk, which objectstack never loads, andpnpm update honoclears a scanner. - Part 2, "Shipped in 17.5.0 without notes": 15 PR lines covering 16 changesets (feat(spec)!: RealtimeEventType names the emitted data.record.* / data.records.* vocabulary (#20288) #20567 carries two), with the 3 breaking entries first (feat(spec)!: retire the inner name on cube measures and dimensions — the record key is the member's name (#20300) #20458, fix(spec,driver-turso)!: refuse a forced mode replica with no syncUrl at authoring and at construction (#20437) #20504, feat(spec)!: RealtimeEventType names the emitted data.record.* / data.records.* vocabulary (#20288) #20567).
PM review anchors:
- The set was re-measured independently: the
.changeset/tree at0f6dcac5e9intersected withorigin/maingives the same 16 files, 15 PRs and breaking set as triage5893392023. packages/mcp/package.json:29(SDK dependency),packages/cli/package.json:74(@objectstack/mcp),packages/plugins/plugin-hono-server/package.json:27(thehonofloor).- One review round: the lead sentence's causal claim ("published from a later commit, so…") was false for the 8 changesets already in the tree at the version commit
8c87d26a5d. It was reworded before landing to a sentence true for all 16.
pm:dispatchedremoved.Seat
domain:devx#1·session_01VDtqoecgES7ScQYGbFVDRv
Generated by Claude Code
- added a commit that references this issue
on Sep 29, 2026
Observed on a real upgrade: HotCRM 17.4.0 → 17.5.0, 2026-09-29
After bumping every
@objectstack/*to 17.5.0 and running a plainpnpm install(lockfile-preserving),pnpm why honoshows two copies:hono@4.13.11via@objectstack/plugin-hono-server, the raised floor fromca31ff6;hono@4.13.3via@objectstack/cli→@objectstack/mcp→@modelcontextprotocol/sdk@1.30.0, which declares^4.11.4.The monorepo's
pnpm-workspace.yamloverrides do not ship to consumers. An app that upgrades therefore keeps the olderhonoon the MCP/CLI path. An upgrader could reasonably read the release note "floors raised to clear OSV advisories" as covering their whole tree.Ask
Do one of the following:
honofloor on@objectstack/mcp(orcli) so a consumer's install dedupes onto the patched line;pnpm update hono(or the equivalent for their package manager) in the release notes.Generated by Claude Code