Lockvet

Explain any lockfile or workflow-pin change: bumps, vulns, ages, deprecations — 61 formats

LLM Mart 3 views 8 listing impressions
Transport
Not stated
Package
—
Registry id
io.github.matteo-sung/lockvet

No install snippet on purpose. A working MCP config is a command, its arguments and an environment block — the last two are where API keys live, so this catalogue never stores them and cannot publish them. Follow the link above for the authors' own instructions.

Lockvet explains any lockfile change: what bumped, what's breaking, what's newly vulnerable, how old every incoming version is — before you merge. It runs entirely in your browser via WebAssembly, so pasted or dropped data stays local except for queries to public APIs. The tool supports 61 formats including GitHub Actions, GitLab CI, CircleCI, Dockerfiles, and Kubernetes manifests.

It can report known advisories, versions missing from registry indexes, deprecated or yanked packages, license oddities, and days-old releases for every pinned package during an audit. The vet-package feature checks a package before it is in any lockfile, covering advisories, release age, deprecation, yank, missing index versions, and typosquat suspects.

Summary drafted from the project's own website. Every sentence is backed by text on that page and was reviewed before publishing.