fix: pin npm package versions in MCP integration templates (#25)

* fix: pin npm package versions in MCP integration templates

Prevent supply chain attacks by pinning exact versions instead of
using unpinned `npx -y @package` which pulls latest on every run.

23 of 25 integrations pinned. sqlite-mcp and aws skipped (packages
not found on npm registry).

* fix: use stable azure/mcp version instead of beta
This commit is contained in:
Evan authored and GitHub committed 2026-03-25 22:27:42 +09:00
1 parent d012a4a26d
commit c25a321e88
23 files changed
+24 -24

No files matched your search

+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["cloud", "microsoft", "infrastructure", "azure", "devops", "enterprise"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "@azure/mcp@latest", "server", "start"]
args = ["-y", "@azure/mcp@1.0.4", "server", "start"]
[[required_env]]
name = "AZURE_SUBSCRIPTION_ID"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["git", "vcs", "code", "pull-requests", "ci", "atlassian"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "@atlassian-mcp-server/bitbucket"]
args = ["-y", "@atlassian-mcp-server/bitbucket@0.6.6"]
[[required_env]]
name = "BITBUCKET_USERNAME"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["search", "web", "brave", "api", "information-retrieval"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "@modelcontextprotocol/server-brave-search"]
args = ["-y", "@modelcontextprotocol/server-brave-search@0.6.2"]
[[required_env]]
name = "BRAVE_API_KEY"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["chat", "messaging", "community", "gaming", "voice"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "mcp-discord"]
args = ["-y", "mcp-discord@1.3.4"]
[[required_env]]
name = "DISCORD_BOT_TOKEN"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["files", "storage", "cloud-storage", "sync", "sharing"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "@microagents/mcp-server-dropbox"]
args = ["-y", "@microagents/mcp-server-dropbox@0.0.1"]
[[required_env]]
name = "DROPBOX_ACCESS_TOKEN"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["search", "database", "indexing", "analytics", "full-text"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "@elastic/mcp-server-elasticsearch"]
args = ["-y", "@elastic/mcp-server-elasticsearch@0.3.1"]
[[required_env]]
name = "ELASTICSEARCH_URL"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["search", "web", "ai", "neural", "semantic", "information-retrieval"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "exa-mcp-server"]
args = ["-y", "exa-mcp-server@3.1.9"]
[[required_env]]
name = "EXA_API_KEY"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["cloud", "google", "infrastructure", "gce", "gcs", "bigquery", "devops"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "@google-cloud/gcloud-mcp"]
args = ["-y", "@google-cloud/gcloud-mcp@0.5.3"]
[[required_env]]
name = "GOOGLE_APPLICATION_CREDENTIALS"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["git", "vcs", "code", "issues", "pull-requests", "ci"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "@modelcontextprotocol/server-github"]
args = ["-y", "@modelcontextprotocol/server-github@2025.4.8"]
[[required_env]]
name = "GITHUB_PERSONAL_ACCESS_TOKEN"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["git", "vcs", "code", "merge-requests", "ci", "devops"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "@modelcontextprotocol/server-gitlab"]
args = ["-y", "@modelcontextprotocol/server-gitlab@2025.4.25"]
[[required_env]]
name = "GITLAB_PERSONAL_ACCESS_TOKEN"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["email", "google", "messaging", "inbox", "communication"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "@gongrzhe/server-gmail-autoauth-mcp"]
args = ["-y", "@gongrzhe/server-gmail-autoauth-mcp@1.1.11"]
[oauth]
provider = "google"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["calendar", "scheduling", "google", "events", "meetings"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "@cocal/google-calendar-mcp"]
args = ["-y", "@cocal/google-calendar-mcp@2.6.1"]
[oauth]
provider = "google"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["files", "storage", "google", "documents", "cloud-storage"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "@modelcontextprotocol/server-gdrive"]
args = ["-y", "@modelcontextprotocol/server-gdrive@2025.1.14"]
[oauth]
provider = "google"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["project-management", "issues", "agile", "atlassian", "tracking"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "@aashari/mcp-server-atlassian-jira"]
args = ["-y", "@aashari/mcp-server-atlassian-jira@3.3.0"]
[[required_env]]
name = "JIRA_API_TOKEN"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["project-management", "issues", "agile", "tracking", "sprint"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "linear-mcp"]
args = ["-y", "linear-mcp@1.2.0"]
[[required_env]]
name = "LINEAR_API_KEY"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["database", "nosql", "document", "mongo", "queries"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "@mongodb-js/mongodb-mcp-server"]
args = ["-y", "@mongodb-js/mongodb-mcp-server@0.0.3"]
[[required_env]]
name = "MONGODB_URI"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["notes", "wiki", "knowledge-base", "documentation", "databases"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "@notionhq/notion-mcp-server"]
args = ["-y", "@notionhq/notion-mcp-server@2.2.1"]
[[required_env]]
name = "NOTION_API_KEY"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["database", "sql", "relational", "postgres", "queries"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "@modelcontextprotocol/server-postgres"]
args = ["-y", "@modelcontextprotocol/server-postgres@0.6.2"]
[[required_env]]
name = "POSTGRES_CONNECTION_STRING"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["database", "cache", "key-value", "in-memory", "nosql"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "@modelcontextprotocol/server-redis"]
args = ["-y", "@modelcontextprotocol/server-redis@2025.4.25"]
[[required_env]]
name = "REDIS_URL"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["monitoring", "errors", "debugging", "observability", "apm"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "@sentry/mcp-server"]
args = ["-y", "@sentry/mcp-server@0.30.0"]
[[required_env]]
name = "SENTRY_AUTH_TOKEN"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["chat", "messaging", "team", "channels", "collaboration"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "@modelcontextprotocol/server-slack"]
args = ["-y", "@modelcontextprotocol/server-slack@2025.4.25"]
[[required_env]]
name = "SLACK_BOT_TOKEN"
+2 -2
View File
@@ -1,4 +1,4 @@
id = "teams-mcp"
id = "teams-mcp@0.3.3"
name = "Microsoft Teams"
description = "Access Microsoft Teams channels, chats, and messages through the MCP server"
category = "communication"
@@ -8,7 +8,7 @@ tags = ["chat", "messaging", "microsoft", "enterprise", "collaboration"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "teams-mcp"]
args = ["-y", "teams-mcp@0.3.3"]
[oauth]
provider = "microsoft"
+1 -1
View File
@@ -8,7 +8,7 @@ tags = ["tasks", "todo", "project-management", "productivity", "gtd"]
[transport]
type = "stdio"
command = "npx"
args = ["-y", "todoist-mcp"]
args = ["-y", "todoist-mcp@1.3.0"]
[[required_env]]
name = "TODOIST_API_KEY"