Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Release script skips version bump for packages with only lockfile changes

Đang mở Phù hợp với người mới
#3,870 1 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

@haosenwang1018 đang làm issue này rồi.

Từ ngày 11/4/2026.

  • #3892 của @JosephDoUrden — đã đóng, không merge
  • #3905 của @haosenwang1018 — đang mở
  • #3969 của @Christian-Sidak — đã đóng, không merge
  • #4020 của @Will-hxw — đã đóng, không merge

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
75/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
python
Lĩnh vực
build-system, release

Hướng nghiên cứu

Bắt đầu trong scripts/release.py tại has_changes() và kiểm tra cách các tệp đã thay đổi được lọc để tăng phiên bản gói. Tái hiện trường hợp từ 2026.1.14 đến 2026.1.26 với src/git/uv.lock, sau đó xác minh rằng quy trình release cập nhật src/git/pyproject.toml lên phiên bản 2026.1.26 khi thư mục gói chỉ có các thay đổi đối với tệp lock.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

bug

Describe the bug

has_changes() in scripts/release.py only considers .py and .ts files when deciding which packages to version-bump at release time:

relevant_files = [f for f in changed_files if f.suffix in [".py", ".ts"]]
return len(relevant_files) >= 1

If a sub-package only has lockfile changes between tags (e.g. uv.lock from dependabot), the function returns False and the package's pyproject.toml version is never bumped to the CalVer tag. It keeps whatever stale version is on main.

To Reproduce

Between tags 2026.1.14 and 2026.1.26, the only change in src/git/ was uv.lock:

git diff --name-only 2026.1.14 2026.1.26 -- src/git/
# src/git/uv.lock

The release script skipped src/git/, so pyproject.toml stayed at 0.6.2:

git show 2026.1.26:src/git/pyproject.toml | grep '^version'
# version = "0.6.2"

git show 2026.1.14:src/git/pyproject.toml | grep '^version'
# version = "2026.1.14"

Expected behavior

src/git/pyproject.toml should read version = "2026.1.26" on the 2026.1.26 tag, since the package directory had changes included in that release.

Logs

N/A this is in the release automation, not a runtime issue.

Additional context

Downstream consumers (SBOM generators, CVE scanners) key off the version in pyproject.toml. When it says 0.6.2, advisories with CalVer "fixed in" thresholds never match, so scanners flag the package as vulnerable even though the source is identical to a patched release.

Ngôn ngữ chính
TypeScript
Star
91k
Fork
11.8k
Merge trung bình
8 giờ 24 phút
Pull request đã merge (30 ngày)
48

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của modelcontextprotocol/servers

Tất cả issue của modelcontextprotocol/servers

Issue tương tự

Thêm issue về TypeScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.