From c25a321e8831b89602983231a608bea0cb86c700 Mon Sep 17 00:00:00 2001 From: Evan Date: Wed, 25 Mar 2026 22:27:42 +0900 Subject: [PATCH] fix: pin npm package versions in MCP integration templates (#25) * fix: pin npm package versions in MCP integration templates Prevent supply chain attacks by pinning exact versions instead of using unpinned `npx -y @package` which pulls latest on every run. 23 of 25 integrations pinned. sqlite-mcp and aws skipped (packages not found on npm registry). * fix: use stable azure/mcp version instead of beta --- integrations/azure-mcp.toml | 2 +- integrations/bitbucket.toml | 2 +- integrations/brave-search.toml | 2 +- integrations/discord-mcp.toml | 2 +- integrations/dropbox.toml | 2 +- integrations/elasticsearch.toml | 2 +- integrations/exa-search.toml | 2 +- integrations/gcp-mcp.toml | 2 +- integrations/github.toml | 2 +- integrations/gitlab.toml | 2 +- integrations/gmail.toml | 2 +- integrations/google-calendar.toml | 2 +- integrations/google-drive.toml | 2 +- integrations/jira.toml | 2 +- integrations/linear.toml | 2 +- integrations/mongodb.toml | 2 +- integrations/notion.toml | 2 +- integrations/postgresql.toml | 2 +- integrations/redis.toml | 2 +- integrations/sentry.toml | 2 +- integrations/slack.toml | 2 +- integrations/teams-mcp.toml | 4 ++-- integrations/todoist.toml | 2 +- 23 files changed, 24 insertions(+), 24 deletions(-) diff --git a/integrations/azure-mcp.toml b/integrations/azure-mcp.toml index b7959e2..7fbbdc8 100644 --- a/integrations/azure-mcp.toml +++ b/integrations/azure-mcp.toml @@ -8,7 +8,7 @@ tags = ["cloud", "microsoft", "infrastructure", "azure", "devops", "enterprise"] [transport] type = "stdio" command = "npx" -args = ["-y", "@azure/mcp@latest", "server", "start"] +args = ["-y", "@azure/mcp@1.0.4", "server", "start"] [[required_env]] name = "AZURE_SUBSCRIPTION_ID" diff --git a/integrations/bitbucket.toml b/integrations/bitbucket.toml index 3ba3952..e4bbf6f 100644 --- a/integrations/bitbucket.toml +++ b/integrations/bitbucket.toml @@ -8,7 +8,7 @@ tags = ["git", "vcs", "code", "pull-requests", "ci", "atlassian"] [transport] type = "stdio" command = "npx" -args = ["-y", "@atlassian-mcp-server/bitbucket"] +args = ["-y", "@atlassian-mcp-server/bitbucket@0.6.6"] [[required_env]] name = "BITBUCKET_USERNAME" diff --git a/integrations/brave-search.toml b/integrations/brave-search.toml index d5da51a..6aaaf5d 100644 --- a/integrations/brave-search.toml +++ b/integrations/brave-search.toml @@ -8,7 +8,7 @@ tags = ["search", "web", "brave", "api", "information-retrieval"] [transport] type = "stdio" command = "npx" -args = ["-y", "@modelcontextprotocol/server-brave-search"] +args = ["-y", "@modelcontextprotocol/server-brave-search@0.6.2"] [[required_env]] name = "BRAVE_API_KEY" diff --git a/integrations/discord-mcp.toml b/integrations/discord-mcp.toml index 2cdf773..1d88f41 100644 --- a/integrations/discord-mcp.toml +++ b/integrations/discord-mcp.toml @@ -8,7 +8,7 @@ tags = ["chat", "messaging", "community", "gaming", "voice"] [transport] type = "stdio" command = "npx" -args = ["-y", "mcp-discord"] +args = ["-y", "mcp-discord@1.3.4"] [[required_env]] name = "DISCORD_BOT_TOKEN" diff --git a/integrations/dropbox.toml b/integrations/dropbox.toml index 8b219b9..0ea3dd7 100644 --- a/integrations/dropbox.toml +++ b/integrations/dropbox.toml @@ -8,7 +8,7 @@ tags = ["files", "storage", "cloud-storage", "sync", "sharing"] [transport] type = "stdio" command = "npx" -args = ["-y", "@microagents/mcp-server-dropbox"] +args = ["-y", "@microagents/mcp-server-dropbox@0.0.1"] [[required_env]] name = "DROPBOX_ACCESS_TOKEN" diff --git a/integrations/elasticsearch.toml b/integrations/elasticsearch.toml index fea180f..62f08df 100644 --- a/integrations/elasticsearch.toml +++ b/integrations/elasticsearch.toml @@ -8,7 +8,7 @@ tags = ["search", "database", "indexing", "analytics", "full-text"] [transport] type = "stdio" command = "npx" -args = ["-y", "@elastic/mcp-server-elasticsearch"] +args = ["-y", "@elastic/mcp-server-elasticsearch@0.3.1"] [[required_env]] name = "ELASTICSEARCH_URL" diff --git a/integrations/exa-search.toml b/integrations/exa-search.toml index 737b597..edf21df 100644 --- a/integrations/exa-search.toml +++ b/integrations/exa-search.toml @@ -8,7 +8,7 @@ tags = ["search", "web", "ai", "neural", "semantic", "information-retrieval"] [transport] type = "stdio" command = "npx" -args = ["-y", "exa-mcp-server"] +args = ["-y", "exa-mcp-server@3.1.9"] [[required_env]] name = "EXA_API_KEY" diff --git a/integrations/gcp-mcp.toml b/integrations/gcp-mcp.toml index 43b923f..d6f6a0a 100644 --- a/integrations/gcp-mcp.toml +++ b/integrations/gcp-mcp.toml @@ -8,7 +8,7 @@ tags = ["cloud", "google", "infrastructure", "gce", "gcs", "bigquery", "devops"] [transport] type = "stdio" command = "npx" -args = ["-y", "@google-cloud/gcloud-mcp"] +args = ["-y", "@google-cloud/gcloud-mcp@0.5.3"] [[required_env]] name = "GOOGLE_APPLICATION_CREDENTIALS" diff --git a/integrations/github.toml b/integrations/github.toml index c9fb6c7..86fffeb 100644 --- a/integrations/github.toml +++ b/integrations/github.toml @@ -8,7 +8,7 @@ tags = ["git", "vcs", "code", "issues", "pull-requests", "ci"] [transport] type = "stdio" command = "npx" -args = ["-y", "@modelcontextprotocol/server-github"] +args = ["-y", "@modelcontextprotocol/server-github@2025.4.8"] [[required_env]] name = "GITHUB_PERSONAL_ACCESS_TOKEN" diff --git a/integrations/gitlab.toml b/integrations/gitlab.toml index 1df602a..ac19937 100644 --- a/integrations/gitlab.toml +++ b/integrations/gitlab.toml @@ -8,7 +8,7 @@ tags = ["git", "vcs", "code", "merge-requests", "ci", "devops"] [transport] type = "stdio" command = "npx" -args = ["-y", "@modelcontextprotocol/server-gitlab"] +args = ["-y", "@modelcontextprotocol/server-gitlab@2025.4.25"] [[required_env]] name = "GITLAB_PERSONAL_ACCESS_TOKEN" diff --git a/integrations/gmail.toml b/integrations/gmail.toml index 61f27f9..853c17f 100644 --- a/integrations/gmail.toml +++ b/integrations/gmail.toml @@ -8,7 +8,7 @@ tags = ["email", "google", "messaging", "inbox", "communication"] [transport] type = "stdio" command = "npx" -args = ["-y", "@gongrzhe/server-gmail-autoauth-mcp"] +args = ["-y", "@gongrzhe/server-gmail-autoauth-mcp@1.1.11"] [oauth] provider = "google" diff --git a/integrations/google-calendar.toml b/integrations/google-calendar.toml index 08925ba..cf4dd31 100644 --- a/integrations/google-calendar.toml +++ b/integrations/google-calendar.toml @@ -8,7 +8,7 @@ tags = ["calendar", "scheduling", "google", "events", "meetings"] [transport] type = "stdio" command = "npx" -args = ["-y", "@cocal/google-calendar-mcp"] +args = ["-y", "@cocal/google-calendar-mcp@2.6.1"] [oauth] provider = "google" diff --git a/integrations/google-drive.toml b/integrations/google-drive.toml index b2fd9d8..cd64ef5 100644 --- a/integrations/google-drive.toml +++ b/integrations/google-drive.toml @@ -8,7 +8,7 @@ tags = ["files", "storage", "google", "documents", "cloud-storage"] [transport] type = "stdio" command = "npx" -args = ["-y", "@modelcontextprotocol/server-gdrive"] +args = ["-y", "@modelcontextprotocol/server-gdrive@2025.1.14"] [oauth] provider = "google" diff --git a/integrations/jira.toml b/integrations/jira.toml index 2afecb0..e7e10d6 100644 --- a/integrations/jira.toml +++ b/integrations/jira.toml @@ -8,7 +8,7 @@ tags = ["project-management", "issues", "agile", "atlassian", "tracking"] [transport] type = "stdio" command = "npx" -args = ["-y", "@aashari/mcp-server-atlassian-jira"] +args = ["-y", "@aashari/mcp-server-atlassian-jira@3.3.0"] [[required_env]] name = "JIRA_API_TOKEN" diff --git a/integrations/linear.toml b/integrations/linear.toml index 1faca17..a11836b 100644 --- a/integrations/linear.toml +++ b/integrations/linear.toml @@ -8,7 +8,7 @@ tags = ["project-management", "issues", "agile", "tracking", "sprint"] [transport] type = "stdio" command = "npx" -args = ["-y", "linear-mcp"] +args = ["-y", "linear-mcp@1.2.0"] [[required_env]] name = "LINEAR_API_KEY" diff --git a/integrations/mongodb.toml b/integrations/mongodb.toml index aef760a..97a8e4b 100644 --- a/integrations/mongodb.toml +++ b/integrations/mongodb.toml @@ -8,7 +8,7 @@ tags = ["database", "nosql", "document", "mongo", "queries"] [transport] type = "stdio" command = "npx" -args = ["-y", "@mongodb-js/mongodb-mcp-server"] +args = ["-y", "@mongodb-js/mongodb-mcp-server@0.0.3"] [[required_env]] name = "MONGODB_URI" diff --git a/integrations/notion.toml b/integrations/notion.toml index 8561b72..ec2b0d3 100644 --- a/integrations/notion.toml +++ b/integrations/notion.toml @@ -8,7 +8,7 @@ tags = ["notes", "wiki", "knowledge-base", "documentation", "databases"] [transport] type = "stdio" command = "npx" -args = ["-y", "@notionhq/notion-mcp-server"] +args = ["-y", "@notionhq/notion-mcp-server@2.2.1"] [[required_env]] name = "NOTION_API_KEY" diff --git a/integrations/postgresql.toml b/integrations/postgresql.toml index 225da8f..15e037a 100644 --- a/integrations/postgresql.toml +++ b/integrations/postgresql.toml @@ -8,7 +8,7 @@ tags = ["database", "sql", "relational", "postgres", "queries"] [transport] type = "stdio" command = "npx" -args = ["-y", "@modelcontextprotocol/server-postgres"] +args = ["-y", "@modelcontextprotocol/server-postgres@0.6.2"] [[required_env]] name = "POSTGRES_CONNECTION_STRING" diff --git a/integrations/redis.toml b/integrations/redis.toml index e3ad7ad..143a1f6 100644 --- a/integrations/redis.toml +++ b/integrations/redis.toml @@ -8,7 +8,7 @@ tags = ["database", "cache", "key-value", "in-memory", "nosql"] [transport] type = "stdio" command = "npx" -args = ["-y", "@modelcontextprotocol/server-redis"] +args = ["-y", "@modelcontextprotocol/server-redis@2025.4.25"] [[required_env]] name = "REDIS_URL" diff --git a/integrations/sentry.toml b/integrations/sentry.toml index b8c9b7c..fc067e7 100644 --- a/integrations/sentry.toml +++ b/integrations/sentry.toml @@ -8,7 +8,7 @@ tags = ["monitoring", "errors", "debugging", "observability", "apm"] [transport] type = "stdio" command = "npx" -args = ["-y", "@sentry/mcp-server"] +args = ["-y", "@sentry/mcp-server@0.30.0"] [[required_env]] name = "SENTRY_AUTH_TOKEN" diff --git a/integrations/slack.toml b/integrations/slack.toml index ad95627..f4b6b9d 100644 --- a/integrations/slack.toml +++ b/integrations/slack.toml @@ -8,7 +8,7 @@ tags = ["chat", "messaging", "team", "channels", "collaboration"] [transport] type = "stdio" command = "npx" -args = ["-y", "@modelcontextprotocol/server-slack"] +args = ["-y", "@modelcontextprotocol/server-slack@2025.4.25"] [[required_env]] name = "SLACK_BOT_TOKEN" diff --git a/integrations/teams-mcp.toml b/integrations/teams-mcp.toml index 587c94e..91ee9aa 100644 --- a/integrations/teams-mcp.toml +++ b/integrations/teams-mcp.toml @@ -1,4 +1,4 @@ -id = "teams-mcp" +id = "teams-mcp@0.3.3" name = "Microsoft Teams" description = "Access Microsoft Teams channels, chats, and messages through the MCP server" category = "communication" @@ -8,7 +8,7 @@ tags = ["chat", "messaging", "microsoft", "enterprise", "collaboration"] [transport] type = "stdio" command = "npx" -args = ["-y", "teams-mcp"] +args = ["-y", "teams-mcp@0.3.3"] [oauth] provider = "microsoft" diff --git a/integrations/todoist.toml b/integrations/todoist.toml index 3785975..a8529e6 100644 --- a/integrations/todoist.toml +++ b/integrations/todoist.toml @@ -8,7 +8,7 @@ tags = ["tasks", "todo", "project-management", "productivity", "gtd"] [transport] type = "stdio" command = "npx" -args = ["-y", "todoist-mcp"] +args = ["-y", "todoist-mcp@1.3.0"] [[required_env]] name = "TODOIST_API_KEY"