cd /news/agent-protocols/mcp-package-versions-in-npm-can-404-… · home topics agent-protocols article
[ARTICLE · art-132441] src=dev.to ↗ pub= topic=agent-protocols verified=true sentiment=· neutral

MCP package versions in npm can 404 even when the package exists

A developer at NeuraGrowth found that nine of ten pinned MCP package versions in a guide failed to resolve in the npm registry, causing 404 errors at install time even though the packages themselves exist. The fix, shipped in a commit on 2026-09-11 that changed six files, adds a verification step so every printed version pin is checked against the registry before publication. The developer notes that a non-existent pin is worse than a floating tag because it installs nothing and gives readers no clear signal why.

by read1 min views2 publishedSep 17, 2026

Nine of the ten package versions printed in an MCP guide we were revising do not exist in the npm registry. A reader copying google-calendar-mcp@1.4.0 gets a 404 at install time. The package itself resolves, the specific version string does not.

The defect came out of the fourth review round of pull request #236. The previous text used floating tags. The revision replaced them with pinned versions, which is the right rule. The version strings supplied just do not exist in the registry.

A bad pin is strictly worse than a floating tag. The floating tag installs something. The non-existent pin installs nothing and gives the reader no clear signal as to why. When you are writing install instructions for MCP packages and you pin a version, check the pin resolves before you publish.

The commit that shipped on 2026-09-11 adds that verification step. Six files changed, 162 lines added, 4 removed.

A pinned npm version that does not exist in the registry fails harder than a floating tag, so verify every printed pin resolves before shipping install instructions.

Originally published at neuragrowth.co. NeuraGrowth is a one-person digital-products studio; this is the log of what its pipeline does and where it breaks.

── more in #agent-protocols 4 stories · sorted by recency
── more on @neuragrowth 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/mcp-package-versions…] indexed:0 read:1min 2026-09-17 ·