Skip to content

Cap mcp dependency below 2.0 to fix pipx install breakage - #363

Merged
tildesrc merged 1 commit into
mainfrom
panopticon/cap-mcp-below-v2
Aug 5, 2026
Merged

Cap mcp dependency below 2.0 to fix pipx install breakage#363
tildesrc merged 1 commit into
mainfrom
panopticon/cap-mcp-below-v2

Conversation

@tildesrc

@tildesrc tildesrc commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Problem

A pipx install of panopticon-app crashes on startup:

ModuleNotFoundError: No module named 'mcp.server.fastmcp'

pyproject.toml declared mcp>=1.27.2 with no upper bound. The MCP SDK's 2.0.0 release removed the module paths panopticon imports in taskservice/mcp.pymcp.server.fastmcp.FastMCP and mcp.server.transport_security.TransportSecuritySettings (the server surface moved to mcp.server.mcpserver). pipx resolves from the wheel's unbounded metadata, pulls 2.0.0, and fails on import. Dev was insulated only because uv.lock already pinned 1.27.2.

Change

  • Cap the dependency: mcp>=1.27.2mcp>=1.27.2,<2, holding the 1.x API panopticon uses.
  • Bump version 0.0.30.0.4 so the fix reaches users via pipx upgrade.
  • uv lock records the new specifier; the locked mcp version stays 1.27.2 (no dev change).

Migrating to the MCP 2.0 API is intentionally out of scope — the priority is making the shipped package installable again.

See the plan.md artifact for full detail.

The `mcp>=1.27.2` requirement had no upper bound, so fresh installs
(pipx) resolved mcp 2.0.0, which removed `mcp.server.fastmcp` and the
`mcp.server.transport_security` import path that taskservice/mcp.py
uses — crashing on import. Cap at `<2` to hold the 1.x API panopticon
depends on, and bump to 0.0.4 so the fix reaches users via upgrade.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@tildesrc
tildesrc marked this pull request as ready for review August 5, 2026 20:21
@tildesrc
tildesrc merged commit 61c97cd into main Aug 5, 2026
3 checks passed
tildesrc added a commit that referenced this pull request Aug 6, 2026
Advance the patch version to 0.0.5 and resync the version strings that
drifted: #363 bumped pyproject.toml + uv.lock to 0.0.4 but left
__init__.py and the FastAPI app version at 0.0.3.

Co-authored-by: panopticon-agent <agent@panopticon.local>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant