Pin the tested ExMCP fork without enabling MCP #1599

Closed
sean wants to merge 1 commit from feat/mcp-bandit-dependency into trunk
Owner

Pin sean/ex_mcp commit 2bbb22baf398f05b7f1d20b03a6225f674ab3d86 from sean/ex_mcp#1. Cowboy is optional; the resolved dependency graph has no Cowboy/Cowlib/Ranch. ExMCP is packaged with load-only startup and runtime:false so its default in-memory services do not start. No endpoint is exposed.

Add exact-pin and banned-package checks to the normal contract suite. Check packaged applications in make release and both container release architectures. Record maintenance requirements and pending MCP work in docs/mcp-dependency.md.

Validation: red dependency contract before the pin; green after. Full make check passed, including 2258 existing ExUnit tests and PostgreSQL integration. make release, clean audit without exceptions, format check, and release dependency checks passed. Inspected the release boot script: Binjovi API starts, ExMCP does not.

This removes the dependency blocker. Ory sign-in, durable MCP sessions, tool projections, commands, and watches remain separate implementation work. Forgejo Actions is disabled on the fork; its weekly workflow is not yet active.

Pin sean/ex_mcp commit 2bbb22baf398f05b7f1d20b03a6225f674ab3d86 from https://code.sean.farm/sean/ex_mcp/pulls/1. Cowboy is optional; the resolved dependency graph has no Cowboy/Cowlib/Ranch. ExMCP is packaged with load-only startup and runtime:false so its default in-memory services do not start. No endpoint is exposed. Add exact-pin and banned-package checks to the normal contract suite. Check packaged applications in make release and both container release architectures. Record maintenance requirements and pending MCP work in docs/mcp-dependency.md. Validation: red dependency contract before the pin; green after. Full make check passed, including 2258 existing ExUnit tests and PostgreSQL integration. make release, clean audit without exceptions, format check, and release dependency checks passed. Inspected the release boot script: Binjovi API starts, ExMCP does not. This removes the dependency blocker. Ory sign-in, durable MCP sessions, tool projections, commands, and watches remain separate implementation work. Forgejo Actions is disabled on the fork; its weekly workflow is not yet active.
Pin the tested ExMCP fork without enabling the MCP endpoint
Some checks failed
binjovi/ci Binjovi failed the frozen plan
6261b02fd4
sean closed this pull request 2026-09-12 14:27:23 +00:00
Some checks failed
binjovi/ci Binjovi failed the frozen plan
Required
Details

Pull request closed

Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
sean/binjovi!1599
No description provided.