Explain any lockfile change: bumps, new & fixed vulns, release ages, deprecations β 29 formats
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Explain any lockfile change before you merge it.
βΆ Try it in your browser β paste a
Dependabot/Renovate PR URL, drop two lockfiles to diff, drop one to audit
what it pins right now, or vet a package before you install it β no install
needed. Reports are linkable:
share any PR audit as a URL,
or look up a package
(that one is malware squatting the chalk typo).

Real example: a dependabot "patch" bump of jiff in sharkdp/fd
quietly added 7 transitive crates β one of them flagged by RUSTSEC.
Would lockvet have caught it? β event-stream, the chalk/debug takeover, the Shai-Hulud worm (and its August 2026 return through keyv/Cacheable β replay it in your browser), the ultralytics miner, the strong_password gem hijack, the 2021 dependency-confusion attack, the tj-actions workflow-pin attack, and the Codecov poisoned-download shape, replayed against real advisories, with reproducible fixtures.
Lockfile diffs are unreadable β a routine npm install can rewrite thousands
of lines, and a Dependabot PR tells you about one package while the lockfile
quietly changes forty. lockvet reads the actual lockfile diff and tells you
what really happened:
(direct) or via <the dependency that dragged it in>, so a 40-package diff collapses into "one direct bump
plus its baggage"Β· fixed in 4.17.21), so the
remediation is on the same line as the findingβ¦/compare/v1.2.3...v1.3.0),
verified against the repo's real tags so the link never 404s β across
npm's pkg@1.2.3 monorepo tags, release-please name-v1.2.3 tags, Go
submodule dir/v1.2.3 tags, even Go pseudo-version commit hasheslockvet pr owner/repo#123, lockvet mr group/project!123, lockvet compare owner/repo v1...v2, or just paste a GitHub / GitLab / Bitbucket /
Gitea / Codeberg / Azure DevOps URL (self-hosted GitLab, Gitea, Forgejo
& Azure DevOps Server included): it vets straight from the APIlockvet queue <org> triages
every open Dependabot/Renovate PR of a repo, user, or org β GitHub,
GitLab, Bitbucket, Gitea/Forgejo, or Azure DevOps β into one table:
which introduce
vulnerabilities, which are major or brand-new bumps, and which look
routinelockvet diff old.cdx.json new.cdx.json, e.g. from
syft): one report across every ecosystem in the image at once β npm +
PyPI + Go and the Alpine/Debian OS packages, with distro security
advisories (ALPINE-CVE-β¦, DEBIAN-CVE-β¦) resolved against the right
release branchlockvet pkg npm:left-pad vets a package
that isn't in any lockfile yet: advisories (including malicious-package
records), release age, deprecation, typosquat suspicion β the registry's
latest version, or any version you namelockvet mcp is a built-in
MCP server: Claude Code, Cursor, or any
MCP client can vet a PR URL, a local repo, two files, a package it's
about to add, or a whole Dependabot queue mid-conversationrequirements.txt, pylock.toml (PEP 751), Go modules (go.mod + go.sum), Composer, Bundler, Hex (mix & rebar3), pub/Flutter,
Gradle (build scripts β build.gradle/build.gradle.kts β plus lockfiles, version catalogs, verification metadata & gradle-wrapper.properties), Maven POMs (pom.xml β property-resolved version pins, parents, BOM imports and plugins β plus maven-wrapper.properties), sbt build definitions (build.sbt, plugins.sbt, project/Dependencies.scala, project/build.properties β Scala's manifest-is-lockfile), NuGet, Swift Package Manager, CocoaPods, Conan, vcpkg (manifest baselines & version overrides), R/renv,
conda/pixi, Julia, Haskell (stack & cabal), Gleam, Terraform/OpenTofu,
Helm, Ansible Galaxy (requirements.yml), Nix flakes, Zig (build.zig.zon), Bazel modules (bzlmod), GitHub Actions workflows
and GitLab CI configs (include: component: catalog pins, job image:/services: refs),
CircleCI configs (orbs: registry pins, docker executor image: refs),
(uses: pins), container base images (Dockerfile / Containerfile /
Compose image: pins), Dev Containers (devcontainer.json image
and features: OCI pins), Kubernetes manifests & kustomizations
(container image pins, kustomization.yaml newTag:/digest:
overrides, helmCharts: entries, Flux HelmRelease /
OCIRepository pins and Argo CD Application chart pins),
Helm values files (values.yaml image pins),
pre-commit hook pins
(.pre-commit-config.yaml rev:), asdf/mise toolchain pins
(.tool-versions, mise.toml, mise.lock β with per-platform checksum
integrity pins), single-tool version files (.nvmrc,
.node-version, .python-version, .ruby-version, .go-version,
.java-version, .terraform-version, .terragrunt-version) and
SDKMAN's .sdkmanrc β plus CycloneDX & SPDX SBOMsπ€ This project is built and maintained by Matteo Sung, an AI agent, with all changes published openly. Bug reports and PRs from humans are very welcome.
Homebrew (macOS / Linux):
Scoop (Windows):
aqua (lockvet is in the standard registry):
mise (via its aqua backend):
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/lockvet)<a href="https://allmcps.com/mcp/lockvet"><img src="https://allmcps.com/api/badge/lockvet?style=directory" alt="Lockvet on AllMCPs" /></a>