MCP 服务器

dep-diff-mcp

io.github.DigiCatalyst-Systems/dep-diff-mcp
开发者工具 公开且可连接 MCP 2025-11-25

此 MCP 可以做什么

Analyzes npm, PyPI, and GitHub Actions dependency upgrades for semver changes, breaking changes, security fixes, and migration guidance.

analyze_package_change
Analyze a single dependency version change
Given one package and two versions (from -> to), returns a structured upgrade analysis: semver classification, GitHub release notes summary, detected breaking changes, security advisories fixed in the range, migration guide links, and a clear recommendation. Use when the user asks about a specific package upgrade ('what changed between react 18 and 19', 'is it safe to bump axios from 0.27 to 1.0', 'what does upgrading lodash 4.17.20 to 4.17.21 fix'). Supports npm, pypi, and github-actions (use the action reference as the name, e.g. actions/checkout). For analyzing many packages at once or a Dependabot batch, use analyze_packages_bulk instead.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['ecosystem', 'name', 'fromVersion', 'toVersion'], 'properties': {'name': {'type': 'string', 'minLength': 1, 'description': "Package name (e.g. 'react', 'requests')"}, 'ecosystem': {'enum': ['npm', 'pypi', 'github-actions'], 'type': 'string', 'description': 'Package ecosystem'}, 'toVersion': {'type': 'string', 'minLength': 1, 'description': "Target version (e.g. '19.0.0')"}, 'fromVersion': {'type': 'string', 'minLength': 1, 'description': "Current version (e.g. '18.2.0')"}}}
输出模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['package', 'ecosystem', 'fromVersion', 'toVersion', 'semverClass', 'repoUrl', 'releaseCount', 'breakingChanges', 'securityFixes', 'migrationLinks', 'recommendation', 'recommendationLevel'], 'properties': {'package': {'type': 'string', 'description': 'Package name that was analyzed'}, 'repoUrl': {'type': ['string', 'null'], 'description': 'Source repository URL, or null when none could be resolved'}, 'ecosystem': {'enum': ['npm', 'pypi', 'github-actions'], 'type': 'string', 'description': 'Package ecosystem'}, 'toVersion': {'type': 'string', 'description': 'Version being upgraded to'}, 'fromVersion': {'type': 'string', 'description': 'Version being upgraded from'}, 'semverClass': {'enum': ['major', 'minor', 'patch', 'downgrade', 'unknown'], 'type': 'string', 'description': 'Semver relationship between the two versions'}, 'releaseCount': {'type': 'number', 'description': 'Number of GitHub releases found strictly between the two versions'}, 'securityFixes': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'summary', 'severity'], 'properties': {'id': {'type': 'string', 'description': "Advisory identifier (e.g. 'GHSA-29mw-wpgm-hmr9' or a CVE)"}, 'summary': {'type': 'string', 'description': 'One-line description of the advisory'}, 'severity': {'type': 'string', 'description': "Severity as reported by OSV (e.g. 'LOW', 'MODERATE', 'HIGH', 'CRITICAL')"}}, 'additionalProperties': False}, 'description': 'Advisories affecting fromVersion that are resolved at toVersion'}, 'migrationLinks': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Migration or upgrade guide URLs found in release notes'}, 'recommendation': {'type': 'string', 'description': 'Single-line verdict explaining the recommendation level'}, 'breakingChanges': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Breaking changes extracted from release notes; empty when none were found'}, 'releaseExcerpts': {'type': 'array', 'items': {'type': 'object', 'required': ['tag', 'excerpt'], 'properties': {'tag': {'type': 'string', 'description': 'Release tag the excerpt came from'}, 'excerpt': {'type': 'string', 'description': 'Short excerpt of the release notes'}}, 'additionalProperties': False}, 'description': 'Raw release-note excerpts, present only as a fallback when a major/minor bump yielded no breaking changes'}, 'recommendationLevel': {'enum': ['safe', 'likely-safe', 'review', 'caution', 'security'], 'type': 'string', 'description': 'Risk classification, used to rank packages in bulk results'}}, 'additionalProperties': False}
analyze_packages_bulk
Analyze multiple dependency changes in parallel
Analyzes a list of package upgrades in parallel and returns a unified risk report with packages ranked by recommendation level (security > caution > review > likely-safe > safe). Use when the user provides many dependency changes from a Dependabot PR, npm outdated output, lockfile diff, or batch upgrade. Returns: total count, breakdown by semver class, total security fixes found, packages with breaking changes, and per-package details. Limit 50 packages per call (chunk larger lists).
只读 可访问外部资源 幂等
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['changes'], 'properties': {'changes': {'type': 'array', 'items': {'type': 'object', 'required': ['ecosystem', 'name', 'fromVersion', 'toVersion'], 'properties': {'name': {'type': 'string', 'minLength': 1}, 'ecosystem': {'enum': ['npm', 'pypi', 'github-actions'], 'type': 'string', 'description': 'Package ecosystem'}, 'toVersion': {'type': 'string', 'minLength': 1}, 'fromVersion': {'type': 'string', 'minLength': 1}}}, 'maxItems': 50, 'minItems': 1, 'description': 'List of package changes to analyze'}}}
输出模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['totalPackages', 'bySemverClass', 'securityFixesTotal', 'packagesWithBreakingChanges', 'packages'], 'properties': {'packages': {'type': 'array', 'items': {'anyOf': [{'type': 'object', 'required': ['package', 'ecosystem', 'fromVersion', 'toVersion', 'semverClass', 'repoUrl', 'releaseCount', 'breakingChanges', 'securityFixes', 'migrationLinks', 'recommendation', 'recommendationLevel'], 'properties': {'package': {'type': 'string', 'description': 'Package name that was analyzed'}, 'repoUrl': {'type': ['string', 'null'], 'description': 'Source repository URL, or null when none could be resolved'}, 'ecosystem': {'enum': ['npm', 'pypi', 'github-actions'], 'type': 'string', 'description': 'Package ecosystem'}, 'toVersion': {'type': 'string', 'description': 'Version being upgraded to'}, 'fromVersion': {'type': 'string', 'description': 'Version being upgraded from'}, 'semverClass': {'enum': ['major', 'minor', 'patch', 'downgrade', 'unknown'], 'type': 'string', 'description': 'Semver relationship between the two versions'}, 'releaseCount': {'type': 'number', 'description': 'Number of GitHub releases found strictly between the two versions'}, 'securityFixes': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'summary', 'severity'], 'properties': {'id': {'type': 'string', 'description': "Advisory identifier (e.g. 'GHSA-29mw-wpgm-hmr9' or a CVE)"}, 'summary': {'type': 'string', 'description': 'One-line description of the advisory'}, 'severity': {'type': 'string', 'description': "Severity as reported by OSV (e.g. 'LOW', 'MODERATE', 'HIGH', 'CRITICAL')"}}, 'additionalProperties': False}, 'description': 'Advisories affecting fromVersion that are resolved at toVersion'}, 'migrationLinks': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Migration or upgrade guide URLs found in release notes'}, 'recommendation': {'type': 'string', 'description': 'Single-line verdict explaining the recommendation level'}, 'breakingChanges': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Breaking changes extracted from release notes; empty when none were found'}, 'releaseExcerpts': {'type': 'array', 'items': {'type': 'object', 'required': ['tag', 'excerpt'], 'properties': {'tag': {'type': 'string', 'description': 'Release tag the excerpt came from'}, 'excerpt': {'type': 'string', 'description': 'Short excerpt of the release notes'}}, 'additionalProperties': False}, 'description': 'Raw release-note excerpts, present only as a fallback when a major/minor bump yielded no breaking changes'}, 'recommendationLevel': {'enum': ['safe', 'likely-safe', 'review', 'caution', 'security'], 'type': 'string', 'description': 'Risk classification, used to rank packages in bulk results'}}, 'additionalProperties': False}, {'type': 'object', 'required': ['package', 'error', 'recommendationLevel'], 'properties': {'error': {'type': 'string', 'description': 'Why the analysis could not be completed'}, 'package': {'type': 'string', 'description': 'Package name whose analysis failed'}, 'recommendationLevel': {'type': 'string', 'const': 'review', 'description': "Always 'review' â\x80\x94 a package that could not be analyzed cannot be cleared automatically"}}, 'additionalProperties': False}]}, 'description': 'Per-package results, ranked security > caution > review > likely-safe > safe'}, 'bySemverClass': {'type': 'object', 'required': ['major', 'minor', 'patch'], 'properties': {'major': {'type': 'number', 'description': 'Count of major bumps'}, 'minor': {'type': 'number', 'description': 'Count of minor bumps'}, 'patch': {'type': 'number', 'description': 'Count of patch bumps'}}, 'description': 'Breakdown of the batch by semver class', 'additionalProperties': False}, 'totalPackages': {'type': 'number', 'description': 'Number of package changes submitted'}, 'securityFixesTotal': {'type': 'number', 'description': 'Total security advisories resolved across the whole batch'}, 'packagesWithBreakingChanges': {'type': 'number', 'description': 'How many packages had at least one breaking change'}}, 'additionalProperties': False}
已添加
analyze_packages_bulk
2026年9月17日 12:41
已添加
analyze_package_change
2026年9月17日 12:41