lock-project-stack
Bind a project to its declared dependency versions so every
search(action="docs_query") call from inside that project surfaces
docs for the exact versions you pinned, instead of "latest". Mirrors
the Cabinets workflow from spec section 4.3.
Steps
Resolve the project root:
- If the user gave an absolute path, use it.
- Otherwise infer the root from the current workspace context
(e.g.
git rev-parse --show-topleveloutput). - Confirm at least one supported manifest exists:
pyproject.toml,package.json,go.mod, orCargo.toml.
Lock the project:
- Call
search(action="docs_lock_project", project_path=<abs_path>). - The response includes
totaldetected libraries +indexedcount (how many already have docs in Tier 1 or Tier 2). Surface both numbers to the user so they know how much coverage they have today.
- Call
Trigger Tier 2 ingestion for missing libraries (optional):
- Iterate the
locked_librarieslist; for entries withindexed == false, callsearch(action="docs_query", library=<name>, project_path=<abs_path>, query="<library> overview")once. The first call kicks off background Tier 2 ingestion; subsequent calls return real chunks.
- Iterate the
Verify lock reuse:
- Re-call
search(action="docs_query", library=<name>, project_path=<abs_path>, query=...)WITHOUT specifyingversion. The response should include a non-nulllock_pinfield matching the version from the manifest, confirming Cabinets is honoring the pin.
- Re-call
Surface the pin to the user:
- Summarize "Locked N libraries against versions X.Y.Z (M already indexed, K queued for Tier 2 ingestion)."
Best practices
- Re-run after every dependency bump so the lock stays in sync with what is actually installed.
- For monorepos, lock each workspace project separately — wet-mcp keys
on absolute path so
apps/webandapps/apiget distinct locks. - The lock is a hint, not a hard constraint — callers can always
override the version by passing it explicitly to
docs_query.