Depcheck
Known vulnerabilities for exact package versions from OSV, with fixes. Paid per call, x402.
사용해야 할까요
품질 및 안전성
도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.
컨텍스트 비용
이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.
설치
원클릭 설치
`claude_desktop_config.json` 파일에 다음을 추가하세요:
{
"mcpServers": {
"depcheck": {
"url": "https://depcheck.kaneky.dev/mcp"
}
}
}원격 엔드포인트
https://depcheck.kaneky.dev/mcpstreamable-http할 수 있는 일
도구 목록
도구 (1)
🟢check_packages(packages)
Look up the known vulnerabilities affecting exact package versions in the public OSV database (npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Pub, Hex), 1 to 50 packages per call. Per package: every OSV advisory for that version with its id, CVE/GHSA aliases, summary, severity (database label, CVSS vectors, v3 base scores), the versions that fix it or "no fix published", published/modified dates and a link. Plus a summary: packages checked, packages vulnerable, total advisories and the highest severity. Evidence, not advice: absence from OSV does not prove safety.
입력 스키마
{
"type": "object",
"properties": {
"packages": {
"items": {
"properties": {
"ecosystem": {
"description": "OSV's ecosystem name, case-sensitive.",
"enum": [
"npm",
"PyPI",
"Go",
"Maven",
"crates.io",
"RubyGems",
"NuGet",
"Packagist",
"Pub",
"Hex"
],
"type": "string"
},
"name": {
"description": "As the ecosystem names it: lodash, requests, github.com/gin-gonic/gin, org.apache.logging.log4j:log4j-core.",
"maxLength": 214,
"minLength": 1,
"type": "string"
},
"version": {
"description": "The exact version, not a range.",
"maxLength": 128,
"minLength": 1,
"type": "string"
}
},
"required": [
"ecosystem",
"name",
"version"
],
"type": "object"
},
"maxItems": 50,
"minItems": 1,
"type": "array"
}
},
"required": [
"packages"
]
}커뮤니티
증거