Observed on a real upgrade: HotCRM 17.4.0 → 17.5.0, 2026-09-29
After bumping every @objectstack/* to 17.5.0 and running a plain pnpm install (lockfile-preserving), pnpm why hono shows two copies:
hono@4.13.11 via @objectstack/plugin-hono-server, the raised floor from ca31ff6;
hono@4.13.3 via @objectstack/cli → @objectstack/mcp → @modelcontextprotocol/sdk@1.30.0, which declares ^4.11.4.
The monorepo's pnpm-workspace.yaml overrides do not ship to consumers. An app that upgrades therefore keeps the older hono on the MCP/CLI path. An upgrader could reasonably read the release note "floors raised to clear OSV advisories" as covering their whole tree.
Ask
Do one of the following:
- declare a direct
hono floor on @objectstack/mcp (or cli) so a consumer's install dedupes onto the patched line;
- tell upgraders to run
pnpm update hono (or the equivalent for their package manager) in the release notes.
Generated by Claude Code
Observed on a real upgrade: HotCRM 17.4.0 → 17.5.0, 2026-09-29
After bumping every
@objectstack/*to 17.5.0 and running a plainpnpm install(lockfile-preserving),pnpm why honoshows two copies:hono@4.13.11via@objectstack/plugin-hono-server, the raised floor fromca31ff6;hono@4.13.3via@objectstack/cli→@objectstack/mcp→@modelcontextprotocol/sdk@1.30.0, which declares^4.11.4.The monorepo's
pnpm-workspace.yamloverrides do not ship to consumers. An app that upgrades therefore keeps the olderhonoon the MCP/CLI path. An upgrader could reasonably read the release note "floors raised to clear OSV advisories" as covering their whole tree.Ask
Do one of the following:
honofloor on@objectstack/mcp(orcli) so a consumer's install dedupes onto the patched line;pnpm update hono(or the equivalent for their package manager) in the release notes.Generated by Claude Code