This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+4 more
Summary
AI summaryAdded mcpName field for MCP Registry listing and enabled npm provenance attestations on tarballs.
Full changelog
Added
mcpNamefield inpackage.jsonand a root-levelserver.jsonso the package can be listed on the official MCP Registry (io.github.digicatalyst-systems/dep-diff-mcp).
Changed
- First release published through CI via the
publishGitHub Actions workflow using npm Trusted Publisher / OIDC. Tarballs now carry an npm provenance attestation.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About DigiCatalyst-Systems/dep-diff-mcp
Translates a lockfile diff (npm, PyPI) into a human-readable upgrade plan. Point it at a Dependabot PR and get back semver classification, breaking changes from GitHub release notes, CVEs fixed in range, migration links, and a per-package recommendation. Bulk tool ranks up to 50 changes by risk (security > caution > review > likely-safe > safe)
Related context
Beta — feedback welcome: [email protected]