fix: pin npm package versions in MCP integration templates (#25)

* fix: pin npm package versions in MCP integration templates

Prevent supply chain attacks by pinning exact versions instead of
using unpinned `npx -y @package` which pulls latest on every run.

23 of 25 integrations pinned. sqlite-mcp and aws skipped (packages
not found on npm registry).

* fix: use stable azure/mcp version instead of beta
This commit is contained in:
Evan authored and GitHub committed 2026-03-25 22:27:42 +09:00
1 parent d012a4a26d
commit c25a321e88
23 files changed
+24 -24

No files matched your search

+2 -2
View File
@@ -1,4 +1,4 @@
id = "teams-mcp"
id = "teams-mcp@0.3.3"
name = "Microsoft Teams"
description = "Access Microsoft Teams channels, chats, and messages through the MCP server"
category = "communication"
@@ -8,7 +8,7 @@ tags = ["chat", "messaging", "microsoft", "enterprise", "collaboration"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "teams-mcp"]
args = ["-y", "teams-mcp@0.3.3"]
[oauth]
provider = "microsoft"