Depcheck
Known vulnerabilities for exact package versions from OSV, with fixes. Paid per call, x402.
我該用這個嗎
品質與安全性
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"depcheck": {
"url": "https://depcheck.kaneky.dev/mcp"
}
}
}遠端端點
https://depcheck.kaneky.dev/mcpstreamable-http它能做什麼
工具清單
工具(1)
🟢check_packages(packages)
Look up the known vulnerabilities affecting exact package versions in the public OSV database (npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Pub, Hex), 1 to 50 packages per call. Per package: every OSV advisory for that version with its id, CVE/GHSA aliases, summary, severity (database label, CVSS vectors, v3 base scores), the versions that fix it or "no fix published", published/modified dates and a link. Plus a summary: packages checked, packages vulnerable, total advisories and the highest severity. Evidence, not advice: absence from OSV does not prove safety.
輸入結構描述
{
"type": "object",
"properties": {
"packages": {
"items": {
"properties": {
"ecosystem": {
"description": "OSV's ecosystem name, case-sensitive.",
"enum": [
"npm",
"PyPI",
"Go",
"Maven",
"crates.io",
"RubyGems",
"NuGet",
"Packagist",
"Pub",
"Hex"
],
"type": "string"
},
"name": {
"description": "As the ecosystem names it: lodash, requests, github.com/gin-gonic/gin, org.apache.logging.log4j:log4j-core.",
"maxLength": 214,
"minLength": 1,
"type": "string"
},
"version": {
"description": "The exact version, not a range.",
"maxLength": 128,
"minLength": 1,
"type": "string"
}
},
"required": [
"ecosystem",
"name",
"version"
],
"type": "object"
},
"maxItems": 50,
"minItems": 1,
"type": "array"
}
},
"required": [
"packages"
]
}社群
證據