fix: pin npm package versions in MCP integration templates (#25)

* fix: pin npm package versions in MCP integration templates

Prevent supply chain attacks by pinning exact versions instead of
using unpinned `npx -y @package` which pulls latest on every run.

23 of 25 integrations pinned. sqlite-mcp and aws skipped (packages
not found on npm registry).

* fix: use stable azure/mcp version instead of beta
This commit is contained in:
Evan authored and GitHub committed 2026-03-25 22:27:42 +09:00
1 parent d012a4a26d
commit c25a321e88
23 files changed
+24 -24

No files matched your search

+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["search", "web", "ai", "neural", "semantic", "information-retrieval"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "exa-mcp-server"]
args = ["-y", "exa-mcp-server@3.1.9"]
[[required_env]]
name = "EXA_API_KEY"