Skip to content

This release includes 1 breaking change for platform teams planning a safe upgrade.

Published 1mo MCP Security & Auth
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

changelog cve dependabot dependency-management mcp model-context-protocol
+4 more
npm pypi security typescript

Affected surfaces

breaking_upgrade

Summary

AI summary

mcpName and name fields now use correct GitHub organization casing to avoid 403 errors from the MCP Registry.

Full changelog

Fixed

  • mcpName in package.json and name in server.json now use io.github.DigiCatalyst-Systems/... with the correct GitHub organization casing (was lowercase). The MCP Registry enforces case-sensitive namespace ownership derived from GitHub org identity, so the lowercase form was rejected with a 403.

Changed

  • server.json description shortened to fit the registry's 100-character limit.

Breaking Changes

  • Renamed `mcpName` in package.json and `name` in server.json from lowercase org identifier to correct casing: io.github.DigiCatalyst-Systems/...

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track DigiCatalyst-Systems/dep-diff-mcp

Get notified when new releases ship.

Sign up free

About DigiCatalyst-Systems/dep-diff-mcp

Translates a lockfile diff (npm, PyPI) into a human-readable upgrade plan. Point it at a Dependabot PR and get back semver classification, breaking changes from GitHub release notes, CVEs fixed in range, migration links, and a per-package recommendation. Bulk tool ranks up to 50 changes by risk (security > caution > review > likely-safe > safe)

All releases →

Beta — feedback welcome: [email protected]