Release script skips version bump for packages with only lockfile changes
Maintainer thường phản hồi trong vòng 1 ngày
@haosenwang1018 đang làm issue này rồi.
Từ ngày 11/4/2026.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 75/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- python
- Lĩnh vực
- build-system, release
Hướng nghiên cứu
Bắt đầu trong scripts/release.py tại has_changes() và kiểm tra cách các tệp đã thay đổi được lọc để tăng phiên bản gói. Tái hiện trường hợp từ 2026.1.14 đến 2026.1.26 với src/git/uv.lock, sau đó xác minh rằng quy trình release cập nhật src/git/pyproject.toml lên phiên bản 2026.1.26 khi thư mục gói chỉ có các thay đổi đối với tệp lock.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Describe the bug
has_changes() in scripts/release.py only considers .py and .ts files when deciding which packages to version-bump at release time:
relevant_files = [f for f in changed_files if f.suffix in [".py", ".ts"]]
return len(relevant_files) >= 1
If a sub-package only has lockfile changes between tags (e.g. uv.lock from dependabot), the function returns False and the package's pyproject.toml version is never bumped to the CalVer tag. It keeps whatever stale version is on main.
To Reproduce
Between tags 2026.1.14 and 2026.1.26, the only change in src/git/ was uv.lock:
git diff --name-only 2026.1.14 2026.1.26 -- src/git/
# src/git/uv.lock
The release script skipped src/git/, so pyproject.toml stayed at 0.6.2:
git show 2026.1.26:src/git/pyproject.toml | grep '^version'
# version = "0.6.2"
git show 2026.1.14:src/git/pyproject.toml | grep '^version'
# version = "2026.1.14"
Expected behavior
src/git/pyproject.toml should read version = "2026.1.26" on the 2026.1.26 tag, since the package directory had changes included in that release.
Logs
N/A this is in the release automation, not a runtime issue.
Additional context
Downstream consumers (SBOM generators, CVE scanners) key off the version in pyproject.toml. When it says 0.6.2, advisories with CalVer "fixed in" thresholds never match, so scanners flag the package as vulnerable even though the source is identical to a patched release.
- Ngôn ngữ chính
- TypeScript
- Star
- 91k
- Fork
- 11.8k
- Merge trung bình
- 8 giờ 24 phút
- Pull request đã merge (30 ngày)
- 48
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của modelcontextprotocol/servers
-
bug server-git v2
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
modelcontextprotocol/servers#5012 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent guidance documentation v2
Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 92/100
modelcontextprotocol/servers#4924 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
mcp-server-fetch: `fetch` prompt returns JSON-RPC error code 0 with the raw exception text for an invalid URLCó thể đã có người làm @DawnofGenX đã nhận 5 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
modelcontextprotocol/servers#4914 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
CLAUDE.md: tool-naming rule (kebab-case) disagrees with filesystem and memory serversCó thể đã có người làm @liang0417 đã nhận 6 ngày trước. Đang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
modelcontextprotocol/servers#4892 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Filesystem README recommends deprecated MCP Roots protocol for restricting directory accessCó thể đã có người làm @its-amann đã nhận 11 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
modelcontextprotocol/servers#4844 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của modelcontextprotocol/servers
Issue tương tự
-
Link Checker ReportĐang mởautomated issue report
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 66/100
databendlabs/databend-docs#3511 ·
-
area/dashboard kind/bug QA/dev-automation
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
rancher/dashboard#19379 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 5 ngày
-
perf(core): getComments() runs the approved count and the comment list as two sequential queriesĐang mởarea/core bot:bug bot:working
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
emdash-cms/emdash#3905 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
lingdojo/kana-dojo#31728 · 1 bình luận · 5 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
selective-claw: freshTailTurns=0 keeps ALL turns verbatim and summarizes none (slice(-0) === slice(0))Có thể đã có người làm @zjncs đã nhận hôm nay. Đang mởcomponent:tokenless
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 80/100
agentic-os-org/ANOLISA#6112 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày