Skip to content

chore: pin MCP package versions - #3309

Open
tomelias10 wants to merge 1 commit into
commercetools:mainfrom
tomelias10:fix/mcp-version-pins
Open

tomelias10 wants to merge 1 commit into
commercetools:mainfrom
tomelias10:fix/mcp-version-pins

Conversation

@tomelias10

Copy link
Copy Markdown

Summary

Pins the npm-backed MCP entries in .mcp.json to exact versions so the committed configuration resolves deterministically instead of changing as package tags move.

This addresses #3307.

Pinned versions:

  • @upstash/context7-mcp@4.1.1
  • @playwright/mcp@0.0.82
  • @modelcontextprotocol/server-sequential-thinking@2026.8.31

These were the current registry versions observed when preparing this patch. If the project has internally reviewed versions it prefers, I am happy to update the pins accordingly.

Validation

  • Parsed .mcp.json successfully as JSON.
  • No MCP servers or package code were executed as part of this change.

This is a reproducibility/review-boundary change only; it does not claim any of these packages are malicious or compromised.

@tomelias10
tomelias10 requested a review from a team as a code owner September 25, 2026 08:27
@vercel

vercel Bot commented Sep 25, 2026

Copy link
Copy Markdown

@tomelias10 is attempting to deploy a commit to the commercetools Team on Vercel.

A member of the Team first needs to authorize it.

@changeset-bot

changeset-bot Bot commented Sep 25, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: c13f596

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@tomelias10

Copy link
Copy Markdown
Author

@misama-ct — you introduced this .mcp.json in #3227, so you may have the best context on the intended update policy. I pinned the three npm-backed MCP refs here for deterministic resolution. If automatic updates via @latest/bare refs were intentional, I’d appreciate that context; otherwise I can adjust the exact versions to whatever the team has reviewed.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant