Skip to main content
Glama

packagetrackdev

CI License: MIT

Command-line client for PackageTrack. Reads the lock file in a project and reports which dependencies are behind, which installed versions have been withdrawn, and what the release notes in between say.

Supported lock files: package-lock.json, uv.lock, poetry.lock, Cargo.lock, composer.lock, go.mod. Falls back to requirements.txt or package.json when there is no lock file.

Install

curl -fsSL https://packagetrack.dev/install.sh | sh

Installs uv if needed, then this package and packagetrackdev-mcp as uv tools. No root required. To install only the CLI:

uv tool install --find-links https://packagetrack.dev/cli/ packagetrackdev

Requires Python 3.11+.

Related MCP server: pkg-intel-mcp

Usage

packagetrackdev check                  # report on the current directory, no account needed
packagetrackdev push --name my-app     # upload the dependency set to your dashboard
packagetrackdev login --api-key pkgt_...

Common options:

Option

Description

--project DIR

Directory to read. Default: current directory.

--ecosystem pypi|npm

Read only one lock file type.

--server URL

PackageTrack server. Default: https://packagetrack.dev.

--dry-run

Print the request payload and send nothing.

--all

check only: also list packages the archive does not hold.

push needs an API key, from packagetrackdev login, the PACKAGETRACK_API_KEY environment variable, or --api-key.

What is sent

Package names and versions, and for push, which package required which. No source code, file paths or repository name. --dry-run prints the exact payload.

Coding agents

The archive is also available to Claude Code, Cursor and other MCP clients through packagetrackdev-mcp:

claude mcp add -s user packagetrackdev -- packagetrackdev-mcp

Development

uv sync
uv run pytest

License

MIT

Related MCP Connectors

Related MCP Servers

  • F
    license
    A
    quality
    C
    maintenance
    Package intelligence for AI coding agents that checks npm and PyPI package health, deprecation, vulnerabilities, bundle size, and compares alternatives.
    5
    -
  • A
    license
    Not graded
    quality
    B
    maintenance
    Provides software supply-chain intelligence for AI agents, enabling them to query package metadata, versions, downloads, dependencies, and health signals for npm, PyPI, and crates.io packages without API keys.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables AI coding agents to identify exactly what broke between two dependency versions, with citations for every claim, and to verify package existence to catch typosquatting, all without requiring an API key.
    MIT