dependency-provenance
Establish where an installed package version comes from and what pulls it in, from registry metadata rather than recollection. Use when a vulnerable package is not imported directly and the question is whether it arrives transitively, or when a version pin or compatibility range decides the verdict.
Pinned to revision 9f52dbffa85b, so it is the text this page describes rather than whatever the author pushed since.
Pre-approved tools experimental
Experimental field. Support varies between clients, so this list is what the author declared, not what your client will enforce.
- mcp__deps__depsdev_find_dependency_path
- mcp__deps__depsdev_get_requirements
- mcp__deps__depsdev_get_dependencies
- mcp__deps__depsdev_get_version
- mcp__seizu__github_security__repo_dependencies
Files
Every link opens the file at its source, pinned to the revision this page describes.