← Release notes

v0.2.929 Jul 2026

Check the invariants; name the silent install failure

Two releases had broken on cross-file invariants no generator owns. Separately: why npx-based servers show as not connected in GUI editors, with no error.

Both release bugs that week were cross-file invariants, not forgotten generator runs: server.json advertised 0.2.1 against npm 0.2.7, and the registry’s required mcpName did not exist at all.

CI now fails on any diff from regenerating derived files, and asserts what no generator owns — mcpName against server.json, the identifier shape, that SERVER_VERSION is still derived, and that the manifest declares exactly the tools the server registers. That last one is how the manifest sat at eight tools while the server had ten. The publish workflow checks twice, so a broken invariant fails the release instead of annotating it afterwards.

The install that fails silently

npx -y review-assist-mcp works from a terminal and fails two ways elsewhere, both silent: GUI apps on macOS inherit only /usr/bin:/bin:/usr/sbin:/sbin, so a Homebrew or nvm npx is not found; on Windows npx is a .cmd wrapper needing a TTY the VS Code panel lacks. The server just shows as not connected.

Under a bare GUI PATH, only an absolute node invoking the script directly starts — plain npx fails on lookup, the others on the shebang:

Terminal
npm install -g review-assist-mcpclaude mcp add -s user review-assist -- "$(which node)" "$(npm root -g)/review-assist-mcp/dist/index.js"

This affects every npx-based MCP server, not just this one.

Commits for this release: v0.2.8…v0.2.9