For a whole project's outdated report — npm/pnpm outdated --json (current → from, wanted, latest), ncu --format installedVersion, pip or uv pip list --outdated --format json (version → from, latest_version → latest), go list -m -u -json all (Version → from, Update.Version → latest), cargo outdated, dotnet list package --outdated, a Gradle versions report — pass each package with the version installed and, where the tool gives them, wanted and latest. Answers what the project is missing, most exposed first: per package, the security releases, CVE ids and fixes it does not have, split into toWanted (from → wanted: reachable by an update within the declared range, no manifest edit) and toLatest (→ latest: needs the range changed), with the cost of moving beside them (major bump, breaking mentions, removed/deprecated) and a few of the fixes themselves. Counts are deterministic over every tracked release; no model judged anything. Up to 100 packages a call. Pass repository (from the package's own package.json) for scoped or renamed packages; a Maven, Go or NuGet package goes by its purl. For the vendor's own breaking-change and migration sections, call upgrade_notes on the packages worth moving. A Maven, Go or NuGet package this server does not track is checked against deps.dev after the answer and counted; pass recordMisses: false for private packages.