Skip to content

[finding] upgrading a consumer from 17.4.0 to 17.5.0 keeps hono@4.13.3 on the @objectstack/cli → @objectstack/mcp → @modelcontextprotocol/sdk path — the raised hono floor does not reach it #20622

Description

@hotlong

Observed on a real upgrade: HotCRM 17.4.0 → 17.5.0, 2026-09-29

After bumping every @objectstack/* to 17.5.0 and running a plain pnpm install (lockfile-preserving), pnpm why hono shows two copies:

  • hono@4.13.11 via @objectstack/plugin-hono-server, the raised floor from ca31ff6;
  • hono@4.13.3 via @objectstack/cli → @objectstack/mcp → @modelcontextprotocol/sdk@1.30.0, which declares ^4.11.4.

The monorepo's pnpm-workspace.yaml overrides do not ship to consumers. An app that upgrades therefore keeps the older hono on the MCP/CLI path. An upgrader could reasonably read the release note "floors raised to clear OSV advisories" as covering their whole tree.

Ask

Do one of the following:

  • declare a direct hono floor on @objectstack/mcp (or cli) so a consumer's install dedupes onto the patched line;
  • tell upgraders to run pnpm update hono (or the equivalent for their package manager) in the release notes.

Generated by Claude Code

Activity

  1. added theissue type on Sep 29, 2026
  2. objectstack-fleet commented on Sep 29, 2026

    @objectstack-fleet
    Contributor

    Path: the road's upgrade step — an upgrader's tree is as clean as the release note says | 缺项 (a lockfile-preserving upgrade keeps hono@4.13.3 under @modelcontextprotocol/sdk, a copy objectstack never loads) | P3

    Triage: first grade — documentation · dependencies · priority:p3 · domain:devx · area:devpath · pm:on-hold. Direction: one upgrade line, not a dependency declaration. It rides the maintainer's 17.5.0-aftercare call

    Triage seat (objectstack-wide, seat post #6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-09-29T10:05Z. ⛔ Not a claim, ⛔ not a dispatch. tooling comes off: the card names no Unblocks: target, and its deliverable is text for upgraders.

    Measured on the published 17.5.0 packages

    • The dependency path.

      • @objectstack/cli@17.5.0 depends on @objectstack/mcp@17.5.0, which declares @modelcontextprotocol/sdk ^1.30.0.
      • The SDK (1.30.0 and 1.31.0 alike) declares hono ^4.11.4.
      • @objectstack/plugin-hono-server@17.5.0 declares hono ^4.13.5.
    • The advisories (npm's bulk advisory endpoint). hono below 4.13.5 carries three moderate advisories:

      4.13.5 and 4.13.11 answer none.

    • Installed, never loaded.

      • The published @objectstack/mcp@17.5.0 dist imports only the SDK's server/mcp.js, server/stdio.js, server/webStandardStreamableHttp.js and types.js.
      • In the SDK 1.30.0 tarball, the only modules that import hono or @hono/node-server are server/streamableHttp.js and an example, and objectstack imports neither.
      • ⇒ No objectstack code path loads the stale copy, so there is no security label. The harm is a consumer's own scanner going red, plus a release note an upgrader reads as covering their whole tree.
    • Only a preserved lockfile keeps it. A fresh install resolves ^4.11.4 to 4.13.11.

    Direction

    Restart-when: the maintainer's 17.5.0-aftercare call is recorded. If the call is to annotate, this line joins that annotation. If it is 17.5.1, this line goes into that release's changeset text.

  3. added
    area:devpathThe road — create, dev, verify, publish/install, connect an agent, iterate
    dependenciesPull requests that update a dependency file
    documentationImprovements or additions to documentation
    and removed on Sep 29, 2026
  4. objectstack-fleet commented on Sep 29, 2026

    @objectstack-fleet
    Contributor

    Triage: pm:on-hold → pm:queue, regraded p3 → p2. The 17.5.0-aftercare call is made; this card now carries the next release's aftercare changeset

    Triage seat (objectstack-wide, seat post #6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-09-29T15:31Z. ⛔ Not a claim, ⛔ not a dispatch.

    Provenance. This is executed on the maintainer's call. In the triage seat's chat (session session_01AavokzJ5DndAwitDXvKy4U), asked "annotate the 17.5.0 notes, or cut 17.5.1", the maintainer replied, verbatim: 「可以发 17.5.1 ,但是你应该统一看一下有哪些遗留问题需要发版本之前解决」. So this card's Restart-when: is met: the call is a follow-up release, and the hono line goes into that release's changeset text.

    Measured: the next version is 17.6.0, not a patch. The open Version Packages PR #20639 computes 17.6.0 for the whole fixed group. main carries 44 pending changesets.

    The deliverable: one patch changeset, so it rides whichever version the maintainer ships, in two parts:

    1. An upgrade line (the original ask). In substance: the raised dependency floors cover what objectstack loads. A lockfile-preserving upgrade can keep an older hono under @modelcontextprotocol/sdk, which objectstack never loads, and pnpm update hono (or the equivalent) clears a scanner.

    2. A "shipped in 17.5.0 without notes" section. It names these 16 entries by their PRs, so a reader of the new CHANGELOG knows they were already live in 17.5.0. The 3 with breaking notes are called out first:

      PR feat(spec)!: RealtimeEventType names the emitted data.record.* / data.records.* vocabulary (#20288) #20567 carries two changesets.

    • ⛔ Don't edit or delete the 16 changesets. Their own text is correct; only their release was early. ⛔ No security detail beyond the PR titles.

    Why p2. It gates the release: the notes must be true when the version ships. It lands before the Version Packages PR merges.

  5. objectstack-fleet commented on Sep 29, 2026

    @objectstack-fleet
    Contributor

    Claim: PM loop round 17
    Session: session_01VDtqoecgES7ScQYGbFVDRv
    Branch: claude/issue-20622-release-aftercare-changeset
    Worktree: objectstack-issue-20622
    Domain: domain:devx
    Seat: domain:devx#1
    File surface:

    • one NEW patch changeset under .changeset/, holding (1) the upgrade line for hono under @modelcontextprotocol/sdk and (2) the "shipped in 17.5.0 without notes" section naming the 16 entries by PR, with the 3 breaking ones first;
    • ⛔ no edit or delete of any existing changeset, and no code.

    Stop on a breach and explain it in the report.
    Container & model: S (one new changeset file), mode:subagent, model: sonnet
    Clause-②: no (release-note text only).
    Thread-read: 5893392023
    Serial constraints cleared: board read at 2026-09-29T15:50Z. The deliverable is a new file, so it has no hunk overlap with any open PR. Ordering: it must land before the Version Packages PR #20639 merges. The dev re-measures the 16 entries against 8c87d26a5d..0f6dcac5e9 on origin/main 6bff748bbd and does not copy the list from the thread.

    Priority rule 3 reading: this is release-notes correctness, not a tooling or contract-hygiene card. Under NORTH-STAR rule 4, a published CHANGELOG that omits 3 breaking changes is a wrong sentence in published docs, so rule 3 does not hold it. Triage 5893392023 grades it p2 because it gates the release.


    Generated by Claude Code

  6. objectstack-fleet commented on Sep 29, 2026

    @objectstack-fleet
    Contributor

    os-dev-report

    {
      "issue": 20622,
      "status": "done",
      "branch": "claude/issue-20622-release-aftercare-changeset",
      "pr": "https://github.com/objectstack-ai/objectstack/pull/20667",
      "head_sha": "5a42c6234491bce0a9fe9a3d94cc6544ee86cfc8",
      "session": "session_01VDtqoecgES7ScQYGbFVDRv",
      "premise_still_valid": true,
      "summary": "One new patch changeset (@objectstack/cli, fixed group confirmed) with the hono upgrade line and a 'shipped in 17.5.0 without notes' section of 16 entries (15 PRs), breaking first. PR 20639 was still open and unmerged when checked.",
      "measured_entries": {
        "count": 16,
        "distinct_prs": 15,
        "diff_vs_triage": "Count and breaking set match the triage (16; breaking PR 20458, PR 20504, PR 20567 with two changesets). The brief's literal range 8c87d26a5d..0f6dcac5e9 yields only 8 files; the other 8 were added before the version commit and left unconsumed by it (the tree at 8c87d26a5d still holds them). The correct set is the changeset directory at 0f6dcac5e9 intersected with origin/main.",
        "breaking_prs": [20458, 20504, 20567],
        "prs": [20458, 20504, 20567, 20568, 20572, 20576, 20577, 20579, 20582, 20584, 20585, 20591, 20598, 20605, 20606]
      },
      "gates": "19 derived by dispatch-gates --commands, all exit 0; --ran reconciliation 19 derived, 19 run, 0 NOT-MEASURED, 0 UNRUN; check-changeset-fixed green. First pass exit 3 on 3 gates (node_modules missing), rerun green after pnpm install --frozen-lockfile.",
      "code_anchors": [
        "packages/mcp/package.json:29 depends on @modelcontextprotocol/sdk ^1.30.0",
        "packages/cli/package.json:74 depends on @objectstack/mcp",
        "packages/plugins/plugin-hono-server/package.json:27 hono ^4.13.5",
        "packages/mcp/src imports only server/mcp, server/stdio, server/webStandardStreamableHttp, types from the SDK; zero hits for server/streamableHttp"
      ],
      "mcp_calls": "2 read-only (pull_request_read, list_pull_requests)",
      "api_writes": "2 via fleet relay: pr_create (draft, PR 20667) and this report comment; plus git push of the branch",
      "open_questions": [],
      "out_of_scope_findings": []
    }

    Reported at 2026-09-29T16:02Z.

  7. objectstack-fleet commented on Sep 29, 2026

    @objectstack-fleet
    Contributor

    Landed: PR #20667 → bae38590a8, verified on origin/main by content at 2026-09-29T16:40Z.

    PM review anchors:

    • The set was re-measured independently: the .changeset/ tree at 0f6dcac5e9 intersected with origin/main gives the same 16 files, 15 PRs and breaking set as triage 5893392023.
    • packages/mcp/package.json:29 (SDK dependency), packages/cli/package.json:74 (@objectstack/mcp), packages/plugins/plugin-hono-server/package.json:27 (the hono floor).
    • One review round: the lead sentence's causal claim ("published from a later commit, so…") was false for the 8 changesets already in the tree at the version commit 8c87d26a5d. It was reworded before landing to a sentence true for all 16.

    pm:dispatched removed.

    Seat domain:devx#1 · session_01VDtqoecgES7ScQYGbFVDRv


    Generated by Claude Code

  8. added a commit that references this issue on Sep 29, 2026
    bae3859
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratedependenciesPull requests that update a dependency filedocumentationImprovements or additions to documentationdomain:devxpriority:p2Medium: important, M3

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions