mcp-maven-deps
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| GITHUB_TOKEN | No | GitHub API token. Raises the GitHub API limit from 60 to 5000 requests/hour for changelogs and health. Default: unset. | |
| MAVEN_MCP_OFFLINE | No | When enabled, skip public Maven, Google, Plugin Portal, and enrichment APIs. | off |
| MAVEN_MCP_HTTP_HOST | No | Host the HTTP transport binds to (used when MAVEN_MCP_TRANSPORT=http). Default: 127.0.0.1. The HTTP transport has no authentication — bind to localhost or a trusted network only. | 127.0.0.1 |
| MAVEN_MCP_HTTP_PORT | No | Port the HTTP transport listens on (used when MAVEN_MCP_TRANSPORT=http). Default: 8765. | 8765 |
| MAVEN_MCP_TRANSPORT | No | Transport for the MCP server. `http` serves a stateless Streamable HTTP endpoint at `POST /mcp`; default is `stdio`. | stdio |
| MAVEN_MCP_CACHE_DISABLE | No | When enabled, skip the on-disk response cache. | off |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| get_latest_versionB | Get the latest version of a Maven artifact from Maven Central, Google Maven, or Gradle Plugin Portal. |
| check_version_existsA | Check if a specific version of a Maven artifact exists in any repository resolved for the project: declared repositories first, then the public Maven Central / Google Maven / Gradle Plugin Portal fallback when the project declares none (see projectPath). |
| check_multiple_dependenciesA | Batch lookup of latest versions for multiple Maven dependencies. |
| compare_dependency_versionsB | Compare current dependency versions against the latest available and determine upgrade types (major/minor/patch). |
| get_dependency_changesB | Get changelog/release notes between two versions (AndroidX/AGP developer docs when applicable, else GitHub releases). |
| scan_project_dependenciesA | Scan a local project directory to extract declared dependencies from build files (Gradle, Maven). Applies BOM/platform managed versions (effectiveVersion/managedBy) via network POM fetch when platforms are declared. |
| expand_bomA | Expand a Maven BOM (Bill of Materials) into its managed dependency versions. Recursively expands import-scope BOMs with first-wins ordering. |
| get_transitive_graphA | Fetch the resolved transitive dependency graph for a Maven GAV via deps.dev GetDependencies. Returns nodes (g/a/v) and edges (from/to indices). Partial results are flagged when deps.dev is unreachable, returns errors, or the graph is truncated by the node cap. |
| get_vulnerability_pathsA | Show the dependency path from a project root Maven GAV to each vulnerable transitive node. Fetches the deps.dev transitive graph, checks every unique node for known CVE/GHSA advisories via OSV.dev, and returns the shortest root-to-node path for each vulnerable dependency found — so a CVE deep in the tree can be traced back to which direct dependency pulls it in. An empty vulnerabilityPaths list means no known vulnerability was found in the graph; it is not a safety guarantee (same OSV coverage caveat as get_dependency_vulnerabilities). Partial results are flagged when deps.dev/OSV is unreachable, the graph is truncated by the node cap, or the unique-dependency count is truncated before querying OSV. |
| detect_dependency_conflictsA | Detect version conflicts by unioning deps.dev transitive graphs for each direct project dependency. Flags GAs appearing at ≥2 versions and reports the version Maven nearest-wins or Gradle highest-wins would pick. Approximation of a full project resolve — see notes[] for limitations. |
| check_version_compatibilityA | Check whether a set of versions is mutually compatible. Validates (1) dependency versions against the Spring Boot BOM (spring-boot-dependencies) when springBoot is set, (2) AGP↔Gradle↔JDK and Kotlin Gradle plugin↔Gradle/AGP ranges from a shipped matrix file, and (3) javax→jakarta EE coordinate migration when Spring Boot ≥ 3. Returns conflicts with suggested compatible versions and reference URLs. v1 coverage is intentionally bounded — see notes[] in the response; matrices are not scraped at runtime and must be refreshed via the documented procedure in compat-matrices.json. |
| get_dependency_vulnerabilitiesA | Check dependencies for known vulnerabilities using the OSV.dev database. Each dependency requires a pinned version — OSV lookups are version-specific and version-less coordinates are not queried. An empty vulnerabilities list means no known CVE/GHSA advisory was found for that coordinate+version in OSV.dev; it is NOT a safety guarantee (OSV coverage is incomplete and reporting lags real-world disclosure). When ≥1 vulnerability is found, a per-dependency safeUpgrade candidate is synthesized from the already-fetched fixed-version data (the highest fixed version across all known CVEs) — ADVISORY ONLY, a candidate to verify, never a guaranteed-safe pin; fixesAllKnown is false when at least one CVE has no known fix. |
| get_dependency_healthA | Get health signals for Maven dependencies: version info, GitHub activity, issue stats, license, and maintenance signals. When the GitHub repository is known, also surfaces the OpenSSF Scorecard (overallScore + per-check name/score/reason) from deps.dev when one is on file — omitted (or flagged with capabilityUnavailable) when deps.dev has no scorecard for that repo, is offline, or is unreachable. |
| get_dependency_licenseA | Resolve license intelligence for Maven dependencies: SPDX id, category (permissive / weak-copyleft / strong-copyleft / network-copyleft / proprietary / unknown), plain-English notes, and source (pom / github / spdx-normalized). Uses POM plus optional GitHub license metadata; category mapping is a static lookup (no external license API). |
| check_license_complianceA | Aggregate SPDX licenses across the transitive closure of one or more Maven GAVs (deps.dev GetDependencies + GetVersion) and flag risky/incompatible licenses against a projectLicense posture or an explicit disallow list (SPDX ids and/or categories). Verdicts: ok / review / violation. Missing license metadata degrades to review, never a false ok. Heuristic policy signal — not legal advice; see notes[]. |
| search_artifactsA | Search Maven artifacts by keyword. Uses Maven Central Solr by default; in closed/offline mode (or with repositoryType) routes to Nexus 3 REST or Artifactory AQL/GAVC against MAVEN_MCP_REPOSITORY_BASE / mirrors. |
| audit_project_dependenciesA | Orchestrates a full dependency audit: scans project build files, checks for available updates, and optionally queries OSV.dev for vulnerabilities. Optional includeLicenses adds license categorization, summary, and newLicenseCategories (categories unique in the scanned set). Optional onlyIssues narrows the returned dependencies to only those with a signal (error, available upgrade, vulnerability, or license flag); summary always covers the full scanned set. |
| catalog_entryA | Generate or validate Gradle version-catalog (libs.versions.toml) entries. mode=generate builds a rule-correct [versions]/[libraries]/[plugins] snippet with kebab alias + libs/alias(libs.plugins.) accessor; mode=validate flags reserved aliases, invalid first subgroups, undefined version.ref, accessor clashes, id(libs.plugins.) misuse, and libs usage inside subprojects/buildscript. Returns a minimal diff suggestion, not a full file rewrite. |
| verify_coordinatesA | Verify whether Maven coordinates exist (tri-state: exists / absent / unknown) and, for absent ones, suggest the closest real coordinates. Detects hallucinated / slopsquat-shaped names an LLM may invent. Existence is NOT a safety guarantee: a published typosquat reports exists and is not flagged. Suggestions are candidates to verify, not endorsements. |
| get_eol_statusA | Check end-of-life / support status for JDK, Kotlin, Gradle, and/or Spring Boot via endoflife.date. Provide one or more of kotlin/gradle/springBoot (a version string) and/or jdk ({vendor, version}) — at least one is required. endoflife.date has no generic "java" product: JDK end-of-life is vendor-specific (e.g. eclipse-temurin, amazon-corretto, oracle-jdk, redhat-build-of-openjdk), so jdk always requires an explicit vendor. Each requested version is matched to its endoflife.date release cycle (cycle granularity varies by product — Gradle/JDK vendors cycle by major version, Kotlin/Spring Boot by major.minor) and reports isEol/eolDate/isMaintained/isLts/latestInCycle for that cycle. A version with no matching cycle, or a product/vendor unknown to endoflife.date, surfaces a clear per-item error rather than failing the whole call. |
| compare_upgrade_closureA | Compare a direct upgrade's closure before and after the candidate version. graphSource defaults to auto: Gradle when the project has a Gradle build and gradlew (two sequential resolves, up to 20 substitutions); otherwise deps.dev for exactly one upgrade. Gradle does not fall back to deps.dev after a failure. deps.dev is an isolated public graph, not a project resolve. advisory is not a safety verdict; none and unknown do not mean the coordinate is safe. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 21 tools
Most tools target distinct Maven dependency analysis concerns, and the detailed descriptions help separate overlapping areas like vulnerability lookup vs. vulnerability path tracing vs. full audit. However, the boundary between orchestration tools such as audit_project_dependencies and granular tools such as scan_project_dependencies or compare_upgrade_closure can still require careful reading.
The set mostly follows a predictable snake_case verb_noun pattern (get_latest_version, check_version_exists, compare_dependency_versions, scan_project_dependencies). A few names deviate, such as catalog_entry and get_eol_status, but the overall convention is still readable and consistent.
At 21 tools, the server sits in the heavy 16–25 range. While each tool addresses a real Maven dependency subproblem, the surface is large enough that it risks feeling sprawling for users who only need basic version or vulnerability checks.
The tool set covers a remarkably complete dependency-analysis lifecycle: version lookup, existence checks, batch comparison, changelogs, BOM expansion, transitive graphs, conflict detection, vulnerability paths, license compliance, EOL status, catalog validation, and full project audits. No obvious core operation for this domain appears missing.