Skip to content

fix(deps): pin mcp>=1.28,<2 to prevent MCP SDK 2.0 breaking installs - #16

Open
zxkjack123 wants to merge 7 commits into
SecurityRonin:mainfrom
zxkjack123:fix/mcp-2-pin-upper-bound
Open

zxkjack123 wants to merge 7 commits into
SecurityRonin:mainfrom
zxkjack123:fix/mcp-2-pin-upper-bound

Conversation

@zxkjack123

Copy link
Copy Markdown
Contributor

Problem

docx-mcp-server declares mcp>=1.0.0 with no upper bound. MCP Python SDK 2.0.0 (released 2026-07-28) removed mcp.server.fastmcp (renamed FastMCP → MCPServer), so any fresh install resolves to mcp==2.0.0 and the server dies on import:

ModuleNotFoundError: No module named 'mcp.server.fastmcp'

This is exactly issue #14, which was closed without a fix commit.

Fix

Pin to the v1 maintenance line — the official SDK migration guide recommends exactly this for packages not yet migrated:

"If your package depends on mcp, keep a <2 upper bound until you've migrated."
— MCP Python SDK Migration Guide

-    "mcp>=1.0.0",
+    "mcp>=1.28,<2",

uv.lock re-resolved: mcp 1.26.0 → 1.29.0 (latest v1).

Why not migrate to v2 yet?

Migration surface is small (~5 lines: import + class rename; all 228 @mcp.tool() decorators are v2-compatible), but it requires a thread-safety audit — v2 runs sync handlers on worker threads, and docx-mcp's 228 tools share the global _docs dict. That is a follow-up, tracked separately.

Test results

1108 passed, 3 skipped, 0 failures

Closes #14

…resolve()

When para_id is explicitly provided, _resolve() no longer rejects
the operation because the same text appears in other paragraphs.
The paragraph-level dedup (multiple matches within one paragraph
without context) is preserved.

Closes SecurityRonin#6
This merges the fix for SecurityRonin#6 (remove document-global uniqueness guard
from _resolve()) into our local main so we can use the patched version
immediately. The feature branch remains available for the upstream PR.

PR: SecurityRonin#11
When tracked=True, wraps existing w:r elements in w:del and appends
new text in w:ins, producing proper revision markup.
tracked=False preserves the existing silent-update behavior.

Closes SecurityRonin#9
Adds tracked=True support to update_paragraph (Closes SecurityRonin#9).
Branch retained for upstream PR.
…e_image

Both tools now accept document_handle: str = '' for concurrent
session isolation. Empty string continues to use __default__ slot.

Closes SecurityRonin#8
Adds document_handle to copy_document and update_image (Closes SecurityRonin#8).
Branch retained for upstream PR.
MCP SDK 2.0.0 removed mcp.server.fastmcp (FastMCP renamed to MCPServer).
Unpinned mcp>=1.0.0 lets fresh installs resolve to 2.0.0 and die on
import. Pin to the v1 maintenance line until migration to MCPServer
API is done (see issue SecurityRonin#14).

Closes SecurityRonin#14
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedmcp@​1.26.0 ⏵ 1.29.099 +1100 +31100100100

View full report

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Unpinned mcp>=1.0.0 breaks all fresh installs since MCP SDK 2.0.0 removed mcp.server.fastmcp

1 participant