npx -y ssh-mcp resolves latest on every launch. In a single working session the package went v1 → v2 and the exposed tool set changed under a running agent — exec/sudo-exec vanished, run-command/open-session/sftp-upload appeared, mid-task, with no warning. For a layperson this is "my AI tools broke today for no reason" vs. a comprehensible upgrade prompt.
What
Detect unpinned specs: -y, @latest, bare names.
Show the currently resolved version, not just the spec (read a lockfile / npx cache / npm ls where available).
One-click pin to current version.
On-demand drift re-check: "ssh-mcp moved 2.1.0 → 3.0.0 since you pinned."
Reuse
parse_version and is_newer_version already exist (bcc_core.py, from the update checker); _catalog_package_spec_version already parses a spec's version in the catalog path. This is mostly new detection/plumbing on top of existing primitives — additive, no rework.
Acceptance
Pure-core spec parsing + resolved-version lookup + pin transform, unit-tested (fixture: package bumps major between launches → detect + offer pin/rollback). Minimal GUI (a badge + "pin" button, mirroring the existing dependency-status surface). Depends on the ServerSpec spine.
Part of the ssh-mcp field-notes epic.
## Why (P0 — correctness)
`npx -y ssh-mcp` resolves **latest on every launch**. In a single working session the package went v1 → v2 and the exposed tool set changed **under a running agent** — `exec`/`sudo-exec` vanished, `run-command`/`open-session`/`sftp-upload` appeared, mid-task, with no warning. For a layperson this is "my AI tools broke today for no reason" vs. a comprehensible upgrade prompt.
## What
- Detect unpinned specs: `-y`, `@latest`, bare names.
- Show the **currently resolved** version, not just the spec (read a lockfile / npx cache / `npm ls` where available).
- One-click **pin to current version**.
- On-demand drift re-check: *"ssh-mcp moved 2.1.0 → 3.0.0 since you pinned."*
## Reuse
`parse_version` and `is_newer_version` already exist (`bcc_core.py`, from the update checker); `_catalog_package_spec_version` already parses a spec's version in the catalog path. This is mostly new detection/plumbing on top of existing primitives — additive, no rework.
## Acceptance
Pure-core spec parsing + resolved-version lookup + pin transform, unit-tested (fixture: package bumps major between launches → detect + offer pin/rollback). Minimal GUI (a badge + "pin" button, mirroring the existing dependency-status surface). Depends on the ServerSpec spine.
Part of the ssh-mcp field-notes epic.
the_og
added the P0 label 2026-08-12 02:34:22 -04:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Why (P0 — correctness)
npx -y ssh-mcpresolves latest on every launch. In a single working session the package went v1 → v2 and the exposed tool set changed under a running agent —exec/sudo-execvanished,run-command/open-session/sftp-uploadappeared, mid-task, with no warning. For a layperson this is "my AI tools broke today for no reason" vs. a comprehensible upgrade prompt.What
-y,@latest, bare names.npm lswhere available).Reuse
parse_versionandis_newer_versionalready exist (bcc_core.py, from the update checker);_catalog_package_spec_versionalready parses a spec's version in the catalog path. This is mostly new detection/plumbing on top of existing primitives — additive, no rework.Acceptance
Pure-core spec parsing + resolved-version lookup + pin transform, unit-tested (fixture: package bumps major between launches → detect + offer pin/rollback). Minimal GUI (a badge + "pin" button, mirroring the existing dependency-status surface). Depends on the ServerSpec spine.
Part of the ssh-mcp field-notes epic.