MCP server that reads dependency changelogs and tells you what's risky in an upgrade.
- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
claude mcp add dep-diff-mcp -- npx -y @digicatalyst/dep-diff-mcp{
"mcpServers": {
"dep-diff-mcp": {
"command": "npx",
"args": ["-y", "@digicatalyst/dep-diff-mcp"],
"env": {
"GITHUB_TOKEN": "<github_token>"
}
}
}
}GITHUB_TOKENResumen de MCP Servers
# dep-diff-mcp
MCP server that translates a lockfile diff into a human-readable upgrade plan.
Point your AI assistant (Cursor, Claude Desktop, Claude Code) at a Dependabot PR, `npm outdated` output, or any pair of package versions, and get back a ranked upgrade plan: semver class, breaking changes pulled from GitHub release notes, CVEs fixed in the range, migration guide links, and a clear recommendation per package.
## Install
### Claude Code
One command, user scope (available in every project):
```bash
claude mcp add -s user dep-diff -- npx -y @digicatalyst/dep-diff-mcp
```
Project scope (writes `.mcp.json` at repo root, team-shared):
```bash
claude mcp add -s project dep-diff -- npx -y @digicatalyst/dep-diff-mcp
```
With an explicit token (skip this if you have the `gh` CLI authenticated — see [GitHub token](#github-token-optional-but-recommended) below):
```bash
claude mcp add -s user --env GITHUB_TOKEN=ghp_xxx dep-diff -- npx -y @digicatalyst/dep-diff-mcp
```
Verify:
```bash
claude mcp list
```
Restart the Claude Code session to pick up the server.
### Cursor and Claude Desktop
Add to your MCP client config:
- Cursor: `~/.cursor/mcp.json`
- Claude Desktop: `~/Library/Application Support/Claude/claude_desktop_config.json` (macOS) or `%APPDATA%\Claude\claude_desktop_config.json` (Windows)
```json
{
"mcpServers": {
"dep-diff": {
"command": "npx",
"args": ["-y", "@digicatalyst/dep-diff-mcp"]
}
}
}
```
Restart your MCP client. Ask something like "what's risky in this Dependabot PR?" and the tools are invoked automatically.
### Hosted remote (no install)
A hosted instance runs at `https://dep-diff.digicatalyst.ca/mcp` over streamable HTTP, so you can skip the npm package entirely:
```bash
claude mcp add -s user -t http dep-diff https://dep-diff.digicatalyst.ca/mcp
```
Or in a client config:
```json
{
"mcpServers": {
"dep-diff": {
"type": "http",
"url": "https://dep-diff.digicatalyst.ca/mcp"
}
}
}
```
Pass a GitHub token with `?githubToken=ghp_xxx` on the URL if you want higher rate limits. The hosted instance is stateless and keeps no logs of your queries — see [PRIVACY.md](PRIVACY.md). Run the npm package locally instead if you would rather your token never leave your machine.
## GitHub token (optional but recommended)
The server hits the GitHub API to read release notes. Without a token you get 60 requests per hour (GitHub's anonymous limit) — enough for occasional single-package queries, not enough for bulk lockfile analysis.
The server resolves a token in this order:
1. `GITHUB_TOKEN` environment variable, if set.
2. `gh auth token` — if the [GitHub CLI](https://cli.github.com) is installed and authenticated, the server uses that token automatically. No config change needed.
3. Anonymous (60 req/hr).
### Recommended: use the `gh` CLI
If you already have `gh` installed (`brew install gh && gh auth login`), stop here — the server picks up your existing auth. No plaintext token anywhere.
### Alternative: environment variable
Create a **fine-grained** token at <https://github.com/settings/tokens>:
- **Token name:** `dep-diff-mcp`
- **Expiration:** 90 days (rotate periodically)
- **Repository access:** `Public Repositories (read-only)` — no private repo access
- **Permissions:** none beyond the default public read — do **not** grant `repo`, `workflow`, `user`, or any write scope
Then reference it in the MCP config:
```json
{
"mcpServers": {
"dep-diff": {
"command": "npx",
"args": ["-y", "@digicatalyst/dep-diff-mcp"],
"env": { "GITHUB_TOKEN": "github_pat_xxx" }
}
}
}
```
### Security notes
- This config file lives on your disk in plaintext. Keep perms tight (`chmod 600`) and **do not paste the token into AI chats, issues, or shared screens** — transcripts are often retained.
- The token in this config should be least-privilege (public repo read only). Even leaked, it can only read public data you could already read.
- Rotate tokens periodically. Revoke any token that may have been exposed at <https://github.com/settings/tokens>.
- The server never writes the token to stdout/stderr or the response payload.
## Tools
### `analyze_package_change`
Analyze one package upgrade. Inputs: `ecosystem` (`npm` or `pypi`), `name`, `fromVersion`, `toVersion`.
### `analyze_packages_bulk`
Analyze up to 50 package upgrades in parallel. Returns packages ranked by risk (`security` > `caution` > `review` > `likely-safe` > `safe`), plus summary counts.
## What you get back
- **Semver classification** — major / minor / patch / downgrade / unknown
- **Breaking changes** — extracted from GitHub release notes headers
- **Security fixes** — CVEs present at `fromVersion` but resolved at `toVersion` (via OSV.dev)
- **Migration links** — upgrade guide URLs found in release notes
- **Recommendation** — single-line verdict + level
## Supported ecosystems
- npm
- PyPI
## Development
```bash
npm install
npm run build
GITHUB_TOKEN=ghp_xxx npm run inspect # MCP Inspector
```
## License
MIT
Lo que la gente pregunta sobre dep-diff-mcp
¿Qué es DigiCatalyst-Systems/dep-diff-mcp?
+
DigiCatalyst-Systems/dep-diff-mcp es mcp servers para el ecosistema de Claude AI. MCP server that reads dependency changelogs and tells you what's risky in an upgrade. Tiene 2 estrellas en GitHub y su última actualización registrada es del 2026-08-24.
¿Cómo se instala dep-diff-mcp?
+
Puedes instalar dep-diff-mcp clonando el repositorio (https://github.com/DigiCatalyst-Systems/dep-diff-mcp) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar DigiCatalyst-Systems/dep-diff-mcp?
+
Nuestro agente de seguridad ha analizado DigiCatalyst-Systems/dep-diff-mcp y le ha asignado un Trust Score de 95/100 (tier: Verified). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene DigiCatalyst-Systems/dep-diff-mcp?
+
DigiCatalyst-Systems/dep-diff-mcp es mantenido por DigiCatalyst-Systems. La última actividad registrada en GitHub es del 2026-08-24, con 0 issues abiertos.
¿Hay alternativas a dep-diff-mcp?
+
Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.
Despliega dep-diff-mcp en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/digicatalyst-systems-dep-diff-mcp)<a href="https://claudewave.com/repo/digicatalyst-systems-dep-diff-mcp"><img src="https://claudewave.com/api/badge/digicatalyst-systems-dep-diff-mcp" alt="Featured on ClaudeWave: DigiCatalyst-Systems/dep-diff-mcp" width="320" height="64" /></a>Más MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
The fastest path to AI-powered full stack observability, even for lean teams.
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!