Cap mcp dependency below 2.0 to fix pipx install breakage - #363
Merged
Conversation
The `mcp>=1.27.2` requirement had no upper bound, so fresh installs (pipx) resolved mcp 2.0.0, which removed `mcp.server.fastmcp` and the `mcp.server.transport_security` import path that taskservice/mcp.py uses — crashing on import. Cap at `<2` to hold the 1.x API panopticon depends on, and bump to 0.0.4 so the fix reaches users via upgrade. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
tildesrc
marked this pull request as ready for review
August 5, 2026 20:21
tildesrc
added a commit
that referenced
this pull request
Aug 6, 2026
Advance the patch version to 0.0.5 and resync the version strings that drifted: #363 bumped pyproject.toml + uv.lock to 0.0.4 but left __init__.py and the FastAPI app version at 0.0.3. Co-authored-by: panopticon-agent <agent@panopticon.local> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
A pipx install of
panopticon-appcrashes on startup:pyproject.tomldeclaredmcp>=1.27.2with no upper bound. The MCP SDK's2.0.0release removed the module paths panopticon imports intaskservice/mcp.py—mcp.server.fastmcp.FastMCPandmcp.server.transport_security.TransportSecuritySettings(the server surface moved tomcp.server.mcpserver). pipx resolves from the wheel's unbounded metadata, pulls2.0.0, and fails on import. Dev was insulated only becauseuv.lockalready pinned1.27.2.Change
mcp>=1.27.2→mcp>=1.27.2,<2, holding the 1.x API panopticon uses.version0.0.3→0.0.4so the fix reaches users viapipx upgrade.uv lockrecords the new specifier; the lockedmcpversion stays1.27.2(no dev change).Migrating to the MCP 2.0 API is intentionally out of scope — the priority is making the shipped package installable again.
See the
plan.mdartifact for full detail.