Detect unpinned server specs, show the resolved version, one-click pin, drift re-check (P0) #92

Closed
opened 2026-08-12 02:34:22 -04:00 by the_og · 0 comments
Owner

Why (P0 — correctness)

npx -y ssh-mcp resolves latest on every launch. In a single working session the package went v1 → v2 and the exposed tool set changed under a running agent — exec/sudo-exec vanished, run-command/open-session/sftp-upload appeared, mid-task, with no warning. For a layperson this is "my AI tools broke today for no reason" vs. a comprehensible upgrade prompt.

What

  • Detect unpinned specs: -y, @latest, bare names.
  • Show the currently resolved version, not just the spec (read a lockfile / npx cache / npm ls where available).
  • One-click pin to current version.
  • On-demand drift re-check: "ssh-mcp moved 2.1.0 → 3.0.0 since you pinned."

Reuse

parse_version and is_newer_version already exist (bcc_core.py, from the update checker); _catalog_package_spec_version already parses a spec's version in the catalog path. This is mostly new detection/plumbing on top of existing primitives — additive, no rework.

Acceptance

Pure-core spec parsing + resolved-version lookup + pin transform, unit-tested (fixture: package bumps major between launches → detect + offer pin/rollback). Minimal GUI (a badge + "pin" button, mirroring the existing dependency-status surface). Depends on the ServerSpec spine.

Part of the ssh-mcp field-notes epic.

## Why (P0 — correctness) `npx -y ssh-mcp` resolves **latest on every launch**. In a single working session the package went v1 → v2 and the exposed tool set changed **under a running agent** — `exec`/`sudo-exec` vanished, `run-command`/`open-session`/`sftp-upload` appeared, mid-task, with no warning. For a layperson this is "my AI tools broke today for no reason" vs. a comprehensible upgrade prompt. ## What - Detect unpinned specs: `-y`, `@latest`, bare names. - Show the **currently resolved** version, not just the spec (read a lockfile / npx cache / `npm ls` where available). - One-click **pin to current version**. - On-demand drift re-check: *"ssh-mcp moved 2.1.0 → 3.0.0 since you pinned."* ## Reuse `parse_version` and `is_newer_version` already exist (`bcc_core.py`, from the update checker); `_catalog_package_spec_version` already parses a spec's version in the catalog path. This is mostly new detection/plumbing on top of existing primitives — additive, no rework. ## Acceptance Pure-core spec parsing + resolved-version lookup + pin transform, unit-tested (fixture: package bumps major between launches → detect + offer pin/rollback). Minimal GUI (a badge + "pin" button, mirroring the existing dependency-status surface). Depends on the ServerSpec spine. Part of the ssh-mcp field-notes epic.
the_og added the P0 label 2026-08-12 02:34:22 -04:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: the_og/better-claude-config#92