fix: pin npm package versions in MCP integration templates (#25)
* fix: pin npm package versions in MCP integration templates Prevent supply chain attacks by pinning exact versions instead of using unpinned `npx -y @package` which pulls latest on every run. 23 of 25 integrations pinned. sqlite-mcp and aws skipped (packages not found on npm registry). * fix: use stable azure/mcp version instead of beta
This commit is contained in:
23 files changed
+24
-24
No files matched your search
@@ -1,4 +1,4 @@
|
||||
id = "teams-mcp"
|
||||
id = "teams-mcp@0.3.3"
|
||||
name = "Microsoft Teams"
|
||||
description = "Access Microsoft Teams channels, chats, and messages through the MCP server"
|
||||
category = "communication"
|
||||
@@ -8,7 +8,7 @@ tags = ["chat", "messaging", "microsoft", "enterprise", "collaboration"]
|
||||
[transport]
|
||||
type = "stdio"
|
||||
command = "npx"
|
||||
args = ["-y", "teams-mcp"]
|
||||
args = ["-y", "teams-mcp@0.3.3"]
|
||||
|
||||
[oauth]
|
||||
provider = "microsoft"
|
||||
|
||||
Reference in new issue
Block a user