Skip to content

[finding] upgrading a consumer from 17.4.0 to 17.5.0 keeps hono@4.13.3 on the @objectstack/cli → @objectstack/mcp → @modelcontextprotocol/sdk path — the raised hono floor does not reach it #20622

Description

@hotlong

Observed on a real upgrade: HotCRM 17.4.0 → 17.5.0, 2026-09-29

After bumping every @objectstack/* to 17.5.0 and running a plain pnpm install (lockfile-preserving), pnpm why hono shows two copies:

  • hono@4.13.11 via @objectstack/plugin-hono-server, the raised floor from ca31ff6;
  • hono@4.13.3 via @objectstack/cli → @objectstack/mcp → @modelcontextprotocol/sdk@1.30.0, which declares ^4.11.4.

The monorepo's pnpm-workspace.yaml overrides do not ship to consumers. An app that upgrades therefore keeps the older hono on the MCP/CLI path. An upgrader could reasonably read the release note "floors raised to clear OSV advisories" as covering their whole tree.

Ask

Do one of the following:

  • declare a direct hono floor on @objectstack/mcp (or cli) so a consumer's install dedupes onto the patched line;
  • tell upgraders to run pnpm update hono (or the equivalent for their package manager) in the release notes.

Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratedependenciesPull requests that update a dependency filedocumentationImprovements or additions to documentationdomain:devxpriority:p2Medium: important, M3

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions