← Home

@umbraco-cms/mcp-dev

A model context protocol (MCP) server for Umbraco CMS

12
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

ijacobumbraco-publish

Keywords

UmbracoMCPModel Context ProtocolCMSMCP-ServerAI

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): New dep is first-party sibling package from same org, not an external risky lib. ai
phantom-deps phantom-dep:form-data AI (phantom-deps): form-data is a transitive runtime dep used via axios/orval-generated clients; stable false positive for this package. ai
dependencies unvetted-dep:@umbraco-cms/mcp-hosted AI (dependencies): Same-org scoped package from official Umbraco publisher; consistent with package family. ai
dependencies unvetted-dep:@umbraco-cms/mcp-server-sdk AI (dependencies): Same-org scoped package from official Umbraco publisher; consistent with package family. ai
provenance no-provenance AI (provenance): Official Umbraco org package; provenance absence is a process gap, not a security risk for this publisher. ai
phantom-deps phantom-dep:@types/yargs AI (phantom-deps): Type-only package loaded by convention; stable FP. ai
phantom-deps phantom-dep:qs AI (phantom-deps): Referenced in orval/axios config files, not direct imports; stable FP for this build-tool package. ai
phantom-deps phantom-dep:@umbraco-cms/mcp-hosted AI (phantom-deps): Same-org scoped package; phantom-dep heuristic unreliable for peer/optional usage patterns. ai
phantom-deps phantom-dep:axios AI (phantom-deps): Used via generated API client config, not direct import; stable FP. ai
phantom-deps phantom-dep:yargs AI (phantom-deps): CLI tooling dependency loaded via config; stable FP. ai
phantom-deps phantom-dep:dotenv AI (phantom-deps): Env config loaded at runtime, not statically imported; stable FP. ai
phantom-deps phantom-dep:@types/uuid AI (phantom-deps): Type-only package loaded by convention; stable FP. ai

Versions (showing 12 of 12)

Version Deps Published
17.4.1 13 / 21
17.3.7 13 / 21
17.3.3 13 / 21
17.3.2 13 / 21
17.2.1 13 / 21
17.2.0 12 / 22
17.1.2 12 / 17
17.1.1 12 / 17
17.1.0 12 / 17
17.0.0 11 / 15
16.0.1 11 / 15
16.0.0 11 / 15

v17.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.1.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.