Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
GITHUB_TOKENNoGitHub API token. Raises the GitHub API limit from 60 to 5000 requests/hour for changelogs and health. Default: unset.
MAVEN_MCP_OFFLINENoWhen enabled, skip public Maven, Google, Plugin Portal, and enrichment APIs.off
MAVEN_MCP_HTTP_HOSTNoHost the HTTP transport binds to (used when MAVEN_MCP_TRANSPORT=http). Default: 127.0.0.1. The HTTP transport has no authentication — bind to localhost or a trusted network only.127.0.0.1
MAVEN_MCP_HTTP_PORTNoPort the HTTP transport listens on (used when MAVEN_MCP_TRANSPORT=http). Default: 8765.8765
MAVEN_MCP_TRANSPORTNoTransport for the MCP server. `http` serves a stateless Streamable HTTP endpoint at `POST /mcp`; default is `stdio`.stdio
MAVEN_MCP_CACHE_DISABLENoWhen enabled, skip the on-disk response cache.off

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
get_latest_versionB

Get the latest version of a Maven artifact from Maven Central, Google Maven, or Gradle Plugin Portal.

check_version_existsA

Check if a specific version of a Maven artifact exists in any repository resolved for the project: declared repositories first, then the public Maven Central / Google Maven / Gradle Plugin Portal fallback when the project declares none (see projectPath).

check_multiple_dependenciesA

Batch lookup of latest versions for multiple Maven dependencies.

compare_dependency_versionsB

Compare current dependency versions against the latest available and determine upgrade types (major/minor/patch).

get_dependency_changesB

Get changelog/release notes between two versions (AndroidX/AGP developer docs when applicable, else GitHub releases).

scan_project_dependenciesA

Scan a local project directory to extract declared dependencies from build files (Gradle, Maven). Applies BOM/platform managed versions (effectiveVersion/managedBy) via network POM fetch when platforms are declared.

expand_bomA

Expand a Maven BOM (Bill of Materials) into its managed dependency versions. Recursively expands import-scope BOMs with first-wins ordering.

get_transitive_graphA

Fetch the resolved transitive dependency graph for a Maven GAV via deps.dev GetDependencies. Returns nodes (g/a/v) and edges (from/to indices). Partial results are flagged when deps.dev is unreachable, returns errors, or the graph is truncated by the node cap.

get_vulnerability_pathsA

Show the dependency path from a project root Maven GAV to each vulnerable transitive node. Fetches the deps.dev transitive graph, checks every unique node for known CVE/GHSA advisories via OSV.dev, and returns the shortest root-to-node path for each vulnerable dependency found — so a CVE deep in the tree can be traced back to which direct dependency pulls it in. An empty vulnerabilityPaths list means no known vulnerability was found in the graph; it is not a safety guarantee (same OSV coverage caveat as get_dependency_vulnerabilities). Partial results are flagged when deps.dev/OSV is unreachable, the graph is truncated by the node cap, or the unique-dependency count is truncated before querying OSV.

detect_dependency_conflictsA

Detect version conflicts by unioning deps.dev transitive graphs for each direct project dependency. Flags GAs appearing at ≥2 versions and reports the version Maven nearest-wins or Gradle highest-wins would pick. Approximation of a full project resolve — see notes[] for limitations.

check_version_compatibilityA

Check whether a set of versions is mutually compatible. Validates (1) dependency versions against the Spring Boot BOM (spring-boot-dependencies) when springBoot is set, (2) AGP↔Gradle↔JDK and Kotlin Gradle plugin↔Gradle/AGP ranges from a shipped matrix file, and (3) javax→jakarta EE coordinate migration when Spring Boot ≥ 3. Returns conflicts with suggested compatible versions and reference URLs. v1 coverage is intentionally bounded — see notes[] in the response; matrices are not scraped at runtime and must be refreshed via the documented procedure in compat-matrices.json.

get_dependency_vulnerabilitiesA

Check dependencies for known vulnerabilities using the OSV.dev database. Each dependency requires a pinned version — OSV lookups are version-specific and version-less coordinates are not queried. An empty vulnerabilities list means no known CVE/GHSA advisory was found for that coordinate+version in OSV.dev; it is NOT a safety guarantee (OSV coverage is incomplete and reporting lags real-world disclosure). When ≥1 vulnerability is found, a per-dependency safeUpgrade candidate is synthesized from the already-fetched fixed-version data (the highest fixed version across all known CVEs) — ADVISORY ONLY, a candidate to verify, never a guaranteed-safe pin; fixesAllKnown is false when at least one CVE has no known fix.

get_dependency_healthA

Get health signals for Maven dependencies: version info, GitHub activity, issue stats, license, and maintenance signals. When the GitHub repository is known, also surfaces the OpenSSF Scorecard (overallScore + per-check name/score/reason) from deps.dev when one is on file — omitted (or flagged with capabilityUnavailable) when deps.dev has no scorecard for that repo, is offline, or is unreachable.

get_dependency_licenseA

Resolve license intelligence for Maven dependencies: SPDX id, category (permissive / weak-copyleft / strong-copyleft / network-copyleft / proprietary / unknown), plain-English notes, and source (pom / github / spdx-normalized). Uses POM plus optional GitHub license metadata; category mapping is a static lookup (no external license API).

check_license_complianceA

Aggregate SPDX licenses across the transitive closure of one or more Maven GAVs (deps.dev GetDependencies + GetVersion) and flag risky/incompatible licenses against a projectLicense posture or an explicit disallow list (SPDX ids and/or categories). Verdicts: ok / review / violation. Missing license metadata degrades to review, never a false ok. Heuristic policy signal — not legal advice; see notes[].

search_artifactsA

Search Maven artifacts by keyword. Uses Maven Central Solr by default; in closed/offline mode (or with repositoryType) routes to Nexus 3 REST or Artifactory AQL/GAVC against MAVEN_MCP_REPOSITORY_BASE / mirrors.

audit_project_dependenciesA

Orchestrates a full dependency audit: scans project build files, checks for available updates, and optionally queries OSV.dev for vulnerabilities. Optional includeLicenses adds license categorization, summary, and newLicenseCategories (categories unique in the scanned set). Optional onlyIssues narrows the returned dependencies to only those with a signal (error, available upgrade, vulnerability, or license flag); summary always covers the full scanned set.

catalog_entryA

Generate or validate Gradle version-catalog (libs.versions.toml) entries. mode=generate builds a rule-correct [versions]/[libraries]/[plugins] snippet with kebab alias + libs/alias(libs.plugins.) accessor; mode=validate flags reserved aliases, invalid first subgroups, undefined version.ref, accessor clashes, id(libs.plugins.) misuse, and libs usage inside subprojects/buildscript. Returns a minimal diff suggestion, not a full file rewrite.

verify_coordinatesA

Verify whether Maven coordinates exist (tri-state: exists / absent / unknown) and, for absent ones, suggest the closest real coordinates. Detects hallucinated / slopsquat-shaped names an LLM may invent. Existence is NOT a safety guarantee: a published typosquat reports exists and is not flagged. Suggestions are candidates to verify, not endorsements.

get_eol_statusA

Check end-of-life / support status for JDK, Kotlin, Gradle, and/or Spring Boot via endoflife.date. Provide one or more of kotlin/gradle/springBoot (a version string) and/or jdk ({vendor, version}) — at least one is required. endoflife.date has no generic "java" product: JDK end-of-life is vendor-specific (e.g. eclipse-temurin, amazon-corretto, oracle-jdk, redhat-build-of-openjdk), so jdk always requires an explicit vendor. Each requested version is matched to its endoflife.date release cycle (cycle granularity varies by product — Gradle/JDK vendors cycle by major version, Kotlin/Spring Boot by major.minor) and reports isEol/eolDate/isMaintained/isLts/latestInCycle for that cycle. A version with no matching cycle, or a product/vendor unknown to endoflife.date, surfaces a clear per-item error rather than failing the whole call.

compare_upgrade_closureA

Compare a direct upgrade's closure before and after the candidate version. graphSource defaults to auto: Gradle when the project has a Gradle build and gradlew (two sequential resolves, up to 20 substitutions); otherwise deps.dev for exactly one upgrade. Gradle does not fall back to deps.dev after a failure. deps.dev is an isolated public graph, not a project resolve. advisory is not a safety verdict; none and unknown do not mean the coordinate is safe.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.7/5.0

Scored across 21 tools

Disambiguation4/5

Most tools target distinct Maven dependency analysis concerns, and the detailed descriptions help separate overlapping areas like vulnerability lookup vs. vulnerability path tracing vs. full audit. However, the boundary between orchestration tools such as audit_project_dependencies and granular tools such as scan_project_dependencies or compare_upgrade_closure can still require careful reading.

Naming Consistency4/5

The set mostly follows a predictable snake_case verb_noun pattern (get_latest_version, check_version_exists, compare_dependency_versions, scan_project_dependencies). A few names deviate, such as catalog_entry and get_eol_status, but the overall convention is still readable and consistent.

Tool Count3/5

At 21 tools, the server sits in the heavy 16–25 range. While each tool addresses a real Maven dependency subproblem, the surface is large enough that it risks feeling sprawling for users who only need basic version or vulnerability checks.

Completeness5/5

The tool set covers a remarkably complete dependency-analysis lifecycle: version lookup, existence checks, batch comparison, changelogs, BOM expansion, transitive graphs, conflict detection, vulnerability paths, license compliance, EOL status, catalog validation, and full project audits. No obvious core operation for this domain appears missing.

Maintenance

ActivityMaintained
ResponsivenessResponsive