dep-diff-mcp

Translates a lockfile diff into a human-readable upgrade plan for npm, PyPI, and GitHub Actions.

사용해야 할까요

품질 및 안전성

A
설명 품질
100%
스키마 완전성
100%
이름 품질
100%
오염 위험
100%
권한 일치
100%
프로토콜 준수
100%

도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.

컨텍스트 비용

~1,966토큰 (도구 정의)
~11.0 KB일반적인 응답 크기
중간 정도의 주의 영향 (128k 컨텍스트의 1.54%)

이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.

설치

원클릭 설치

`claude_desktop_config.json` 파일에 다음을 추가하세요:

{
  "mcpServers": {
    "dep-diff-mcp": {
      "command": "npx",
      "args": [
        "@digicatalyst/dep-diff-mcp"
      ]
    }
  }
}

실행 가능한 패키지

npm@digicatalyst/dep-diff-mcp0.3.2stdio

원격 엔드포인트

https://dep-diff.digicatalyst.ca/mcpstreamable-http

할 수 있는 일

도구 목록

도구 (2)

🟢 읽기 전용🟡 쓰기🔴 삭제⚪ 알 수 없음
🟢analyze_package_change(ecosystem, name, fromVersion, toVersion)

Given one package and two versions (from -> to), returns a structured upgrade analysis: semver classification, GitHub release notes summary, detected breaking changes, security advisories fixed in the range, migration guide links, and a clear recommendation. Use when the user asks about a specific package upgrade ('what changed between react 18 and 19', 'is it safe to bump axios from 0.27 to 1.0', 'what does upgrading lodash 4.17.20 to 4.17.21 fix'). Supports npm, pypi, and github-actions (use the action reference as the name, e.g. actions/checkout). For analyzing many packages at once or a Dependabot batch, use analyze_packages_bulk instead.

입력 스키마

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "enum": [
        "npm",
        "pypi",
        "github-actions"
      ],
      "description": "Package ecosystem"
    },
    "name": {
      "type": "string",
      "minLength": 1,
      "description": "Package name (e.g. 'react', 'requests')"
    },
    "fromVersion": {
      "type": "string",
      "minLength": 1,
      "description": "Current version (e.g. '18.2.0')"
    },
    "toVersion": {
      "type": "string",
      "minLength": 1,
      "description": "Target version (e.g. '19.0.0')"
    }
  },
  "required": [
    "ecosystem",
    "name",
    "fromVersion",
    "toVersion"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}

출력 스키마

{
  "type": "object",
  "properties": {
    "package": {
      "type": "string",
      "description": "Package name that was analyzed"
    },
    "ecosystem": {
      "type": "string",
      "enum": [
        "npm",
        "pypi",
        "github-actions"
      ],
      "description": "Package ecosystem"
    },
    "fromVersion": {
      "type": "string",
      "description": "Version being upgraded from"
    },
    "toVersion": {
      "type": "string",
      "description": "Version being upgraded to"
    },
    "semverClass": {
      "type": "string",
      "enum": [
        "major",
        "minor",
        "patch",
        "downgrade",
        "unknown"
      ],
      "description": "Semver relationship between the two versions"
    },
    "repoUrl": {
      "description": "Source repository URL, or null when none could be resolved",
      "type": [
        "string",
        "null"
      ]
    },
    "releaseCount": {
      "type": "number",
      "description": "Number of GitHub releases found strictly between the two versions"
    },
    "breakingChanges": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Breaking changes extracted from release notes; empty when none were found"
    },
    "releaseExcerpts": {
      "description": "Raw release-note excerpts, present only as a fallback when a major/minor bump yielded no breaking changes",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "tag": {
            "type": "string",
            "description": "Release tag the excerpt came from"
          },
          "excerpt": {
            "type": "string",
            "description": "Short excerpt of the release notes"
          }
        },
        "required": [
          "tag",
          "excerpt"
        ],
        "additionalProperties": false
      }
    },
    "securityFixes": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "description": "Advisory identifier (e.g. 'GHSA-29mw-wpgm-hmr9' or a CVE)"
          },
          "summary": {
            "type": "string",
            "description": "One-line description of the advisory"
          },
          "severity": {
            "type": "string",
            "description": "Severity as reported by OSV (e.g. 'LOW', 'MODERATE', 'HIGH', 'CRITICAL')"
          }
        },
        "required": [
          "id",
          "summary",
          "severity"
        ],
        "additionalProperties": false
      },
      "description": "Advisories affecting fromVersion that are resolved at toVersion"
    },
    "migrationLinks": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Migration or upgrade guide URLs found in release notes"
    },
    "recommendation": {
      "type": "string",
      "description": "Single-line verdict explaining the recommendation level"
    },
    "recommendationLevel": {
      "type": "string",
      "enum": [
        "safe",
        "likely-safe",
        "review",
        "caution",
        "security"
      ],
      "description": "Risk classification, used to rank packages in bulk results"
    }
  },
  "required": [
    "package",
    "ecosystem",
    "fromVersion",
    "toVersion",
    "semverClass",
    "repoUrl",
    "releaseCount",
    "breakingChanges",
    "securityFixes",
    "migrationLinks",
    "recommendation",
    "recommendationLevel"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#",
  "additionalProperties": false
}
🟢analyze_packages_bulk(changes)

Analyzes a list of package upgrades in parallel and returns a unified risk report with packages ranked by recommendation level (security > caution > review > likely-safe > safe). Use when the user provides many dependency changes from a Dependabot PR, npm outdated output, lockfile diff, or batch upgrade. Returns: total count, breakdown by semver class, total security fixes found, packages with breaking changes, and per-package details. Limit 50 packages per call (chunk larger lists).

입력 스키마

{
  "type": "object",
  "properties": {
    "changes": {
      "minItems": 1,
      "maxItems": 50,
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "ecosystem": {
            "type": "string",
            "enum": [
              "npm",
              "pypi",
              "github-actions"
            ],
            "description": "Package ecosystem"
          },
          "name": {
            "type": "string",
            "minLength": 1
          },
          "fromVersion": {
            "type": "string",
            "minLength": 1
          },
          "toVersion": {
            "type": "string",
            "minLength": 1
          }
        },
        "required": [
          "ecosystem",
          "name",
          "fromVersion",
          "toVersion"
        ]
      },
      "description": "List of package changes to analyze"
    }
  },
  "required": [
    "changes"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}

출력 스키마

{
  "type": "object",
  "properties": {
    "totalPackages": {
      "type": "number",
      "description": "Number of package changes submitted"
    },
    "bySemverClass": {
      "type": "object",
      "properties": {
        "major": {
          "type": "number",
          "description": "Count of major bumps"
        },
        "minor": {
          "type": "number",
          "description": "Count of minor bumps"
        },
        "patch": {
          "type": "number",
          "description": "Count of patch bumps"
        }
      },
      "required": [
        "major",
        "minor",
        "patch"
      ],
      "additionalProperties": false,
      "description": "Breakdown of the batch by semver class"
    },
    "securityFixesTotal": {
      "type": "number",
      "description": "Total security advisories resolved across the whole batch"
    },
    "packagesWithBreakingChanges": {
      "type": "number",
      "description": "How many packages had at least one breaking change"
    },
    "packages": {
      "type": "array",
      "items": {
        "anyOf": [
          {
            "type": "object",
            "properties": {
              "package": {
                "type": "string",
                "description": "Package name that was analyzed"
              },
              "ecosystem": {
                "type": "string",
                "enum": [
                  "npm",
                  "pypi",
                  "github-actions"
                ],
                "description": "Package ecosystem"
              },
              "fromVersion": {
                "type": "string",
                "description": "Version being upgraded from"
              },
              "toVersion": {
                "type": "string",
                "description": "Version being upgraded to"
              },
              "semverClass": {
                "type": "string",
                "enum": [
                  "major",
                  "minor",
                  "patch",
                  "downgrade",
                  "unknown"
                ],
                "description": "Semver relationship between the two versions"
              },
              "repoUrl": {
                "description": "Source repository URL, or null when none could be resolved",
                "type": [
                  "string",
                  "null"
                ]
              },
              "releaseCount": {
                "type": "number",
                "description": "Number of GitHub releases found strictly between the two versions"
              },
              "breakingChanges": {
                "type": "array",
                "items": {
                  "type": "string"
                },
                "description": "Breaking changes extracted from release notes; empty when none were found"
              },
              "releaseExcerpts": {
                "description": "Raw release-note excerpts, present only as a fallback when a major/minor bump yielded no breaking changes",
                "type": "array",
                "items": {
                  "type": "object",
                  "properties": {
                    "tag": {
                      "type": "string",
                      "description": "Release tag the excerpt came from"
                    },
                    "excerpt": {
                      "type": "string",
                      "description": "Short excerpt of the release notes"
                    }
                  },
                  "required": [
                    "tag",
                    "excerpt"
                  ],
                  "additionalProperties": false
                }
              },
              "securityFixes": {
                "type": "array",
                "items": {
                  "type": "object",
                  "properties": {
                    "id": {
                      "type": "string",
                      "description": "Advisory identifier (e.g. 'GHSA-29mw-wpgm-hmr9' or a CVE)"
                    },
                    "summary": {
                      "type": "string",
                      "description": "One-line description of the advisory"
                    },
                    "severity": {
                      "type": "string",
                      "description": "Severity as reported by OSV (e.g. 'LOW', 'MODERATE', 'HIGH', 'CRITICAL')"
                    }
                  },
                  "required": [
                    "id",
                    "summary",
                    "severity"
                  ],
                  "additionalProperties": false
                },
                "description": "Advisories affecting fromVersion that are resolved at toVersion"
              },
              "migrationLinks": {
                "type": "array",
                "items": {
                  "type": "string"
                },
                "description": "Migration or upgrade guide URLs found in release notes"
              },
              "recommendation": {
                "type": "string",
                "description": "Single-line verdict explaining the recommendation level"
              },
              "recommendationLevel": {
                "type": "string",
                "enum": [
                  "safe",
                  "likely-safe",
                  "review",
                  "caution",
                  "security"
                ],
                "description": "Risk classification, used to rank packages in bulk results"
              }
            },
            "required": [
              "package",
              "ecosystem",
              "fromVersion",
              "toVersion",
              "semverClass",
              "repoUrl",
              "releaseCount",
              "breakingChanges",
              "securityFixes",
              "migrationLinks",
              "recommendation",
              "recommendationLevel"
            ],
            "additionalProperties": false
          },
          {
            "type": "object",
            "properties": {
              "package": {
                "type": "string",
                "description": "Package name whose analysis failed"
              },
              "error": {
                "type": "string",
                "description": "Why the analysis could not be completed"
              },
              "recommendationLevel": {
                "type": "string",
                "const": "review",
                "description": "Always 'review' — a package that could not be analyzed cannot be cleared automatically"
              }
            },
            "required": [
              "package",
              "error",
              "recommendationLevel"
            ],
            "additionalProperties": false
          }
        ]
      },
      "description": "Per-package results, ranked security > caution > review > likely-safe > safe"
    }
  },
  "required": [
    "totalPackages",
    "bySemverClass",
    "securityFixesTotal",
    "packagesWithBreakingChanges",
    "packages"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#",
  "additionalProperties": false
}

커뮤니티

이 서버 평가하기

증거

최근 관측

검증됨버전이 기록되지 않음도구 2개
검증됨버전이 기록되지 않음도구 2개
검증됨버전이 기록되지 않음도구 2개