← Home

@paretools/security

MCP server for security scanning — structured Trivy, Semgrep, and Gitleaks findings for AI agents

28
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

dave212

Keywords

mcpmcp-servermodel-context-protocolstructured-outputaiai-agentclaudecursorcopilottoken-efficientdevtoolsclitrivysecurityvulnerabilityscannercontaineriacsemgrepstatic-analysissastgitleakssecret-detection

Versions (showing 28 of 28)

Version Deps Published
0.21.1 3 / 4
0.21.0 3 / 4
0.20.0 3 / 4
0.19.1 3 / 4
0.18.1 3 / 4
0.18.0 3 / 4
0.17.0 3 / 4
0.16.3 3 / 4
0.16.2 3 / 4
0.16.1 3 / 4
0.16.0 3 / 4
0.15.0 3 / 4
0.14.2 3 / 4
0.14.1 3 / 4
0.14.0 3 / 4
0.13.1 3 / 4
0.13.0 3 / 4
0.12.0 3 / 4
0.11.0 3 / 4
0.10.2 3 / 4
0.10.1 3 / 4
0.10.0 3 / 4
0.9.0 3 / 4
0.8.5 3 / 4
0.1.3 3 / 4
0.1.2 3 / 4
0.1.1 3 / 4
0.1.0 3 / 4

v0.21.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.21.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.