packagetrackdev
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@packagetrackdevwhat changed in lodash between 4.17.20 and 4.17.21?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
packagetrackdev
Command-line client for PackageTrack. Reads the lock file in a project and reports which dependencies are behind, which installed versions have been withdrawn, and what the release notes in between say.
Supported lock files: package-lock.json, uv.lock, poetry.lock,
Cargo.lock, composer.lock, go.mod. Falls back to requirements.txt or
package.json when there is no lock file.
Install
curl -fsSL https://packagetrack.dev/install.sh | shInstalls uv if needed, then this package and
packagetrackdev-mcp
as uv tools. No root required. To install only the CLI:
uv tool install --find-links https://packagetrack.dev/cli/ packagetrackdevRequires Python 3.11+.
Related MCP server: pkg-intel-mcp
Usage
packagetrackdev check # report on the current directory, no account needed
packagetrackdev push --name my-app # upload the dependency set to your dashboard
packagetrackdev login --api-key pkgt_...Common options:
Option | Description |
| Directory to read. Default: current directory. |
| Read only one lock file type. |
| PackageTrack server. Default: |
| Print the request payload and send nothing. |
|
|
push needs an API key, from packagetrackdev login, the
PACKAGETRACK_API_KEY environment variable, or --api-key.
What is sent
Package names and versions, and for push, which package required which.
No source code, file paths or repository name. --dry-run prints the exact
payload.
Coding agents
The archive is also available to Claude Code, Cursor and other MCP clients through packagetrackdev-mcp:
claude mcp add -s user packagetrackdev -- packagetrackdev-mcpDevelopment
uv sync
uv run pytestLicense
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Package intelligence for AI agents across npm, PyPI, crates.io and deps.dev. No API keys.
Package intelligence for AI agents across npm, PyPI, crates.io and deps.dev. No API keys.
Real-time Python package and vulnerability data for AI coding agents.
Provide AI-powered real-time analysis and intelligence on NPM packages, including security, depend…
Related MCP Servers
- AlicenseAqualityAmaintenanceDependency intelligence for AI agents. CVE scanning, health checks, upgrade planning.9121 npm2Apache 2.0
- FlicenseAqualityCmaintenancePackage intelligence for AI coding agents that checks npm and PyPI package health, deprecation, vulnerabilities, bundle size, and compares alternatives.5-
- AlicenseNot gradedqualityBmaintenanceProvides software supply-chain intelligence for AI agents, enabling them to query package metadata, versions, downloads, dependencies, and health signals for npm, PyPI, and crates.io packages without API keys.MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI coding agents to identify exactly what broke between two dependency versions, with citations for every claim, and to verify package existence to catch typosquatting, all without requiring an API key.MIT