Skip to content

DigiCatalyst-Systems/dep-diff-mcp

MCP Security & Auth

Translates a lockfile diff (npm, PyPI) into a human-readable upgrade plan. Point it at a Dependabot PR and get back semver classification, breaking changes from GitHub release notes, CVEs fixed in range, migration links, and a per-package recommendation. Bulk tool ranks up to 50 changes by risk (security > caution > review > likely-safe > safe)

TypeScript Latest v0.1.10 · 3mo ago Security brief →

Features

  • Translates lockfile diffs into a ranked upgrade plan
  • Extracts semver class, breaking changes from GitHub release notes, and security fixes via OSV.dev
  • Provides migration guide links and clear per‑package recommendations

Recent releases

View all 11 releases →
No immediate action
v0.1.10 Bug fix

Install snippet fix

Config change
v0.1.9 Breaking risk
Auth Dependencies

Analytics Engine removal

No immediate action
v0.1.7 New feature

Tool annotations + prompts

No immediate action
v0.1.6 New feature

Server card JSON endpoint

Review required
v0.1.5 New feature
Auth

Cloudflare Worker + deploy workflow

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
2
Forks
0
Languages
TypeScript JavaScript Dockerfile
Downloads/week
81 ↓2%
NPM Maintainers
1 Single npm maintainer
Contributors
1
TypeScript
Types included ✓

Install & Platforms

Install via
npm

Beta — feedback welcome: [email protected]