Skip to content

Update MCP SDK and Zod with matching release checks - #36

Draft
StoneHub wants to merge 1 commit into
mainfrom
codex/mcp-dependency-compat
Draft

StoneHub wants to merge 1 commit into
mainfrom
codex/mcp-dependency-compat

Conversation

@StoneHub

@StoneHub StoneHub commented Oct 2, 2026

Copy link
Copy Markdown
Owner

The open MCP SDK and Zod updates pass protocol tests but fail the release gate because it still asserts the previous versions. Update the two exact pins together and retain strict release-version checks.

This combines #26 and #31 on main 3804b33d710ccc200153e85b6fcf125829a40c6b, preserving the merged inspector window-close fix (#35). Only package.json, package-lock.json, and the two release expectations change. Existing transitive versions and CI triggers are preserved. The shipped MCP companion uses stdio; this is a compatibility update.

Validation at head 131870626ebc93bbbd01a7cf0973e4f566f95e06 on an arm64 Mac, Node 24.20.0:

  • Full local suite: 54 tests pass, plus release assertions and Electron build.
  • Supplemental stdio check: schema requirements/bounds/enums survive conversion; six invalid requests leave the stored record unchanged; a valid update and resource read still work.
  • Release check, production npm audit (0 vulnerabilities), package verification, and git diff --check pass.
  • Exact-ZIP browser acceptance: all 9 checks pass in cached Chrome for Testing 153.0.8010.12 with a disposable profile, trusted browser input, actual clipboard readback, export bytes and unchanged ZIP/extracted-file checks.
  • Tested ZIP SHA-256: b984d41fac6e540f1c942e4dc419548f3b3fc2139ed74119a27f03e728c526c9.
  • Independent Standards review: 0 findings. Independent Spec review: 0 implementation findings.

The browser ZIP excludes the separately tested MCP companion. PR34 file-access work and its native disabled-toggle acceptance remain separate. This draft leaves integration to the coordinating task.

Test when you sit down: use the local MCP companion to import a synthetic capture, read its resource, and update its status. Failed schema validation should leave the record unchanged; successful calls should keep clean MCP output on stdout.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant