fix: pin npm package versions in MCP integration templates (#25)
* fix: pin npm package versions in MCP integration templates Prevent supply chain attacks by pinning exact versions instead of using unpinned `npx -y @package` which pulls latest on every run. 23 of 25 integrations pinned. sqlite-mcp and aws skipped (packages not found on npm registry). * fix: use stable azure/mcp version instead of beta
This commit is contained in:
23 files changed
+24
-24
No files matched your search
@@ -8,7 +8,7 @@ tags = ["project-management", "issues", "agile", "atlassian", "tracking"]
|
||||
[transport]
|
||||
type = "stdio"
|
||||
command = "npx"
|
||||
args = ["-y", "@aashari/mcp-server-atlassian-jira"]
|
||||
args = ["-y", "@aashari/mcp-server-atlassian-jira@3.3.0"]
|
||||
|
||||
[[required_env]]
|
||||
name = "JIRA_API_TOKEN"
|
||||
|
||||
Reference in new issue
Block a user