Repository navigation
fix(deps): pin mcp>=1.28,<2 to prevent MCP SDK 2.0 breaking installs - #16
Open
zxkjack123 wants to merge 7 commits into
Open
zxkjack123 wants to merge 7 commits into
zxkjack123 wants to merge 7 commits into
Conversation
…resolve() When para_id is explicitly provided, _resolve() no longer rejects the operation because the same text appears in other paragraphs. The paragraph-level dedup (multiple matches within one paragraph without context) is preserved. Closes SecurityRonin#6
This merges the fix for SecurityRonin#6 (remove document-global uniqueness guard from _resolve()) into our local main so we can use the patched version immediately. The feature branch remains available for the upstream PR. PR: SecurityRonin#11
When tracked=True, wraps existing w:r elements in w:del and appends new text in w:ins, producing proper revision markup. tracked=False preserves the existing silent-update behavior. Closes SecurityRonin#9
Adds tracked=True support to update_paragraph (Closes SecurityRonin#9). Branch retained for upstream PR.
…e_image Both tools now accept document_handle: str = '' for concurrent session isolation. Empty string continues to use __default__ slot. Closes SecurityRonin#8
Adds document_handle to copy_document and update_image (Closes SecurityRonin#8). Branch retained for upstream PR.
MCP SDK 2.0.0 removed mcp.server.fastmcp (FastMCP renamed to MCPServer). Unpinned mcp>=1.0.0 lets fresh installs resolve to 2.0.0 and die on import. Pin to the v1 maintenance line until migration to MCPServer API is done (see issue SecurityRonin#14). Closes SecurityRonin#14
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
docx-mcp-serverdeclaresmcp>=1.0.0with no upper bound. MCP Python SDK 2.0.0 (released 2026-07-28) removedmcp.server.fastmcp(renamedFastMCP→MCPServer), so any fresh install resolves tomcp==2.0.0and the server dies on import:This is exactly issue #14, which was closed without a fix commit.
Fix
Pin to the v1 maintenance line — the official SDK migration guide recommends exactly this for packages not yet migrated:
uv.lockre-resolved:mcp 1.26.0 → 1.29.0(latest v1).Why not migrate to v2 yet?
Migration surface is small (~5 lines: import + class rename; all 228
@mcp.tool()decorators are v2-compatible), but it requires a thread-safety audit — v2 runs sync handlers on worker threads, and docx-mcp's 228 tools share the global_docsdict. That is a follow-up, tracked separately.Test results
Closes #14