Skip to content

go-live 3/9: lock the v1 dist-tag and deprecate all four packages on npm #1816

Description

@cliffhall

Phase 3 of 9 in the v2 go-live runbook — see #1804 (§1, §3). Depends on phase 2. Mostly reversible.

Close the two npm-side traps left open by the 1.0.1 publish.

Status: complete. See the corrections note below — the runbook's v1 tag name and <=1.0.0 range were both wrong.

Tasks

⚠️ Two corrections found while executing this phase.

  1. The tag is v1-latest, not v1. npm rejects any dist-tag that parses
    as a SemVer range, and v1 parses as 1.x
    (npm error Tag name must not be a valid SemVer range: v1). This bit
    twice — npm dist-tag add failed, and the --tag v1 merged in chore: pin v1 publishes to the v1 dist-tag #1828 would
    have made the next v1 security release fail to publish outright, at
    release time. Fixed in fix: v1 dist-tag must be v1-latest — npm rejects v1 #1829.
  2. The sub-package range is <2.0.0, not <=1.0.0. That range was
    written before phase 2 published 1.0.1 to all three sub-packages, so it
    would have left the version latest resolves to — the one everyone
    installs — un-deprecated.

Why --tag v1 is the one to not forget

publish-all has no --tag, so npm assigns latest to whatever it publishes. Once 2.0.0 is out, a 1.0.2 security fix from v1/main would move latest back to 1.0.2 — every npx @modelcontextprotocol/inspector in the world silently reverts to deprecated v1. Nothing enforces this flag, and the cost of forgetting surfaces months later.

The three sub-packages (inspector-client, inspector-server, inspector-cli) are permanently orphaned at 1.0.0 with a live latest tag — v2 publishes only the root package. Without deprecation, people keep installing packages that will never update again.

npm deprecate is retroactive-but-mutable (liftable with an empty message), so it is the reversible step here.

Activity

  1. self-assigned this
    on Jul 27, 2026
  2. changed the title [-]go-live 2/9: v1 deprecation notice + publish 1.0.1 from v1/main (OIDC rehearsal)[/-] [+]go-live 3/9: lock the v1 dist-tag and deprecate all four packages on npm[/+] on Jul 27, 2026
  3. cliffhall commented on Jul 28, 2026

    @cliffhall
    MemberAuthor

    Phase 3 complete. Verified against the live registry:

    Check Result
    publish-all pins --tag v1-latest ✅ on v1/main (#1828, corrected by #1829)
    v1-latest → 1.0.1 ✅ all four packages
    npm i …@v1-latest resolves ✅ 1.0.1
    npm deprecate @<2.0.0 ✅ all four; confirmed on 1.0.1, 1.0.0, and back through 0.x
    Warning on a real install ✅ all four, full message, in a clean throwaway consumer

    Two runbook errors found and fixed — both would have surfaced later and worse:

    1. v1 is not a legal dist-tag. npm rejects any tag parsing as a SemVer range. Beyond failing dist-tag add, the --tag v1 merged in chore: pin v1 publishes to the v1 dist-tag #1828 would have made the next v1 security release fail to publish at release time, mid-incident. Now v1-latest (fix: v1 dist-tag must be v1-latest — npm rejects v1 #1829), with the workflow comment recording both failure modes so neither the flag nor the specific name gets "cleaned up" later.
    2. <=1.0.0 for the sub-packages was stale — written before phase 2 shipped 1.0.1 to all three, so it would have left the version latest points at un-deprecated. Now <2.0.0 everywhere.

    Also worth recording: the deprecation message had to be applied from a script file, not a pasted command. A long pasted line gets hard-wrapped by the terminal and the embedded newline is stored verbatim — npm then truncates its warning at the break, hiding the upgrade pointer. Took two attempts to spot; the tell was the break moving with message length. Anyone re-running npm deprecate should build the string in a file.

    The latest → v1 trap (#1804 §1) is now closed ahead of 2.0.0.

  4. added this to the v2.0.0 milestone on Jul 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

v2Issues and PRs for v2

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions