You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[v2] @modelcontextprotocol/node: optional hono peer is unmet under strict package managers, and becomes a runtime crash with @hono/node-server 2.x (#2574) #2882
@modelcontextprotocol/node declares hono as an optional peer (#1896), but its dependency @hono/node-server declares hono: ^4 as a required peer. An optional peer upstream does not satisfy a required peer downstream, so strict package managers report the same unmet peer #1504 fixed for #1425 — now against @hono/node-server.
With strictPeerDependencies: true in pnpm (reached transitively through @strapi/core@5.54.0):
Today this is install-time only: #1896's evidence holds on 1.x, where the @hono/node-server root entry (getRequestListener, the only import in packages/middleware/node/src/streamableHttp.ts) never loads hono.
It becomes a runtime failure with #2574. From @hono/node-server@2.0.5 — the floor of the ^1.19.9 || ^2.0.5 range #2574 introduces — the root entry imports hono/ws at module load in both builds:
dist/index.mjs: import { defineWebSocketHelper } from "hono/ws";
dist/index.cjs: let hono_ws = require("hono/ws");
So once a consumer resolves 2.x without hono installed (which the optional peer explicitly allows), importing @modelcontextprotocol/node throws Cannot find module 'hono/ws'. Inside this monorepo hono is present for the Hono middleware package, which would keep the workspace build and tests green.
What did you expect?
@modelcontextprotocol/node's manifest to describe what it needs at runtime, so installs are clean under strict peer checking and a @hono/node-server bump cannot break consumers at import time.
Possible fixes, smallest first:
Make hono a required peer again (revert fix(node): make hono an optional peer dependency #1896), or a direct dependency. One line; correct under every package manager and for both 1.x and 2.x. Costs a hono install for Node-middleware users.
Drop @hono/node-server altogether. The package already ships its own hono-free Node ↔ Fetch bridge: toWebRequest / toNodeHandler (same dist/index.mjs) convert the request, stream the response with drain backpressure, and abort on client disconnect. NodeStreamableHTTPServerTransport is the only remaining getRequestListener caller; moving it onto that code would remove both @hono/node-server and the hono peer from the package (in the spirit of Optional install of HTTP/SSE transport deps (express, hono) for stdio-only servers #1924), and would make fix(node): widen @hono/node-server past GHSA-frvp-7c67-39w9 #2574 unnecessary for this package. It needs a check that the transport's SSE paths behave the same through it.
(1) is the quick, safe fix and should probably land with or before #2574; (2) is the cleaner end state.
Code to reproduce
// Clean project, pnpm, no `hono` installed.// pnpm-workspace.yaml: strictPeerDependencies: true// pnpm add @modelcontextprotocol/node @modelcontextprotocol/server// -> ERR_PNPM_PEER_DEP_ISSUES: missing peer hono (wanted by @hono/node-server)//// With @hono/node-server resolved to >= 2.0.5 (e.g. via #2574, or an override):import{NodeStreamableHTTPServerTransport}from'@modelcontextprotocol/node';// -> Error: Cannot find module 'hono/ws'
SDK version
@modelcontextprotocol/node@2.0.0 (2.1.0 ships the same dependencies / peerDependencies); @hono/node-server@1.19.17 today, 2.0.5–2.1.1 checked for the hono/ws import.
What happened?
@modelcontextprotocol/nodedeclareshonoas an optional peer (#1896), but its dependency@hono/node-serverdeclareshono: ^4as a required peer. An optional peer upstream does not satisfy a required peer downstream, so strict package managers report the same unmet peer #1504 fixed for #1425 — now against@hono/node-server.With
strictPeerDependencies: truein pnpm (reached transitively through@strapi/core@5.54.0):Today this is install-time only: #1896's evidence holds on 1.x, where the
@hono/node-serverroot entry (getRequestListener, the only import inpackages/middleware/node/src/streamableHttp.ts) never loadshono.It becomes a runtime failure with #2574. From
@hono/node-server@2.0.5— the floor of the^1.19.9 || ^2.0.5range #2574 introduces — the root entry importshono/wsat module load in both builds:dist/index.mjs:import { defineWebSocketHelper } from "hono/ws";dist/index.cjs:let hono_ws = require("hono/ws");So once a consumer resolves 2.x without
honoinstalled (which the optional peer explicitly allows), importing@modelcontextprotocol/nodethrowsCannot find module 'hono/ws'. Inside this monorepohonois present for the Hono middleware package, which would keep the workspace build and tests green.What did you expect?
@modelcontextprotocol/node's manifest to describe what it needs at runtime, so installs are clean under strict peer checking and a@hono/node-serverbump cannot break consumers at import time.Possible fixes, smallest first:
honoa required peer again (revert fix(node): make hono an optional peer dependency #1896), or a direct dependency. One line; correct under every package manager and for both 1.x and 2.x. Costs ahonoinstall for Node-middleware users.@hono/node-serveraltogether. The package already ships its own hono-free Node ↔ Fetch bridge:toWebRequest/toNodeHandler(samedist/index.mjs) convert the request, stream the response withdrainbackpressure, and abort on client disconnect.NodeStreamableHTTPServerTransportis the only remaininggetRequestListenercaller; moving it onto that code would remove both@hono/node-serverand thehonopeer from the package (in the spirit of Optional install of HTTP/SSE transport deps (express, hono) for stdio-only servers #1924), and would make fix(node): widen @hono/node-server past GHSA-frvp-7c67-39w9 #2574 unnecessary for this package. It needs a check that the transport's SSE paths behave the same through it.(1) is the quick, safe fix and should probably land with or before #2574; (2) is the cleaner end state.
Code to reproduce
SDK version
@modelcontextprotocol/node@2.0.0(2.1.0 ships the samedependencies/peerDependencies);@hono/node-server@1.19.17today,2.0.5–2.1.1checked for thehono/wsimport.Related: #1425, #1504, #1896, #1924, #1964, #2531, #2548, #2574.