Release script skips version bump for packages with only lockfile changes
Maintainers usually reply within 1 day
@haosenwang1018 is already working on this.
Since Apr 11, 2026.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 75/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Quiet
- Tech stack
- python
- Domain
- build-system, release
Research direction
Start in scripts/release.py at has_changes() and inspect how changed files are filtered for package version bumps. Reproduce the 2026.1.14 to 2026.1.26 case with src/git/uv.lock, then verify that the release process updates src/git/pyproject.toml to version 2026.1.26 when the package directory has only lockfile changes.
Written by the indexing model from the issue text.
Description
Describe the bug
has_changes() in scripts/release.py only considers .py and .ts files when deciding which packages to version-bump at release time:
relevant_files = [f for f in changed_files if f.suffix in [".py", ".ts"]]
return len(relevant_files) >= 1
If a sub-package only has lockfile changes between tags (e.g. uv.lock from dependabot), the function returns False and the package's pyproject.toml version is never bumped to the CalVer tag. It keeps whatever stale version is on main.
To Reproduce
Between tags 2026.1.14 and 2026.1.26, the only change in src/git/ was uv.lock:
git diff --name-only 2026.1.14 2026.1.26 -- src/git/
# src/git/uv.lock
The release script skipped src/git/, so pyproject.toml stayed at 0.6.2:
git show 2026.1.26:src/git/pyproject.toml | grep '^version'
# version = "0.6.2"
git show 2026.1.14:src/git/pyproject.toml | grep '^version'
# version = "2026.1.14"
Expected behavior
src/git/pyproject.toml should read version = "2026.1.26" on the 2026.1.26 tag, since the package directory had changes included in that release.
Logs
N/A this is in the release automation, not a runtime issue.
Additional context
Downstream consumers (SBOM generators, CVE scanners) key off the version in pyproject.toml. When it says 0.6.2, advisories with CalVer "fixed in" thresholds never match, so scanners flag the package as vulnerable even though the source is identical to a patched release.
- Dominant language
- TypeScript
- Stars
- 90.6k
- Forks
- 11.7k
- Avg merge
- 8h 36m
- Merged PRs (30d)
- 23
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from modelcontextprotocol/servers
-
agent guidance documentation v2
Difficulty 1/5 1-3 hours Newbie friendliness 92/100
modelcontextprotocol/servers#4924 · 1 comment ·
Maintainers usually reply within 1 day
-
mcp-server-fetch: `fetch` prompt returns JSON-RPC error code 0 with the raw exception text for an invalid URLPossibly taken @DawnofGenX claimed this 3 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
modelcontextprotocol/servers#4914 ·
Maintainers usually reply within 1 day
-
CLAUDE.md: tool-naming rule (kebab-case) disagrees with filesystem and memory serversPossibly taken @liang0417 claimed this 5 days ago. Open
Difficulty 1/5 Under an hour Newbie friendliness 92/100
modelcontextprotocol/servers#4892 · 1 comment ·
Maintainers usually reply within 1 day
-
Filesystem README recommends deprecated MCP Roots protocol for restricting directory accessPossibly taken @its-amann claimed this 10 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
modelcontextprotocol/servers#4844 ·
Maintainers usually reply within 1 day
-
Docs: `fetch` installs npm packages during a tool call, which is worth stating for deploymentsPossibly taken @teddiesloco claimed this 13 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
modelcontextprotocol/servers#4830 · 1 comment ·
Maintainers usually reply within 1 day
All issues in modelcontextprotocol/servers
Similar issues
-
check:passed streams:add
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
Maintainers usually reply within 1 day
-
[Bug] The shared instance selector's placeholder and no-match text ignore the display languagePossibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
apache/rocketmq-dashboard#5561 ·
Maintainers usually reply within 3 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
CopilotKit/OpenDots#69 ·
Maintainers usually reply within 1 day
-
sendDefaultPii is reported as deprecated on ReactNativeOptions although dataCollection is hiddenOpenBug React-Native Waiting for: Product Owner
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
getsentry/sentry-react-native#6830 · 1 comment ·
Maintainers usually reply within 1 day
-
OSCI'26
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
GauravKarakoti/SecureFlow#1215 ·
Maintainers usually reply within 1 day