fix: pin npm package versions in MCP integration templates (#25)
* fix: pin npm package versions in MCP integration templates Prevent supply chain attacks by pinning exact versions instead of using unpinned `npx -y @package` which pulls latest on every run. 23 of 25 integrations pinned. sqlite-mcp and aws skipped (packages not found on npm registry). * fix: use stable azure/mcp version instead of beta
This commit is contained in:
23 files changed
+24
-24
No files matched your search
@@ -8,7 +8,7 @@ tags = ["search", "web", "ai", "neural", "semantic", "information-retrieval"]
|
||||
[transport]
|
||||
type = "stdio"
|
||||
command = "npx"
|
||||
args = ["-y", "exa-mcp-server"]
|
||||
args = ["-y", "exa-mcp-server@3.1.9"]
|
||||
|
||||
[[required_env]]
|
||||
name = "EXA_API_KEY"
|
||||
|
||||
Reference in new issue
Block a user