← Home

@umbraco-cms/mcp-dev

A model context protocol (MCP) server for Umbraco CMS

8
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

ijacobumbraco-publish

Keywords

UmbracoMCPModel Context ProtocolCMSMCP-ServerAI

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:form-data AI (phantom-deps): form-data is a transitive runtime dep used via axios/orval-generated clients; stable false positive for this package. ai
dependencies unvetted-dep:@umbraco-cms/mcp-hosted AI (dependencies): Same-org scoped package from official Umbraco publisher; consistent with package family. ai
dependencies unvetted-dep:@umbraco-cms/mcp-server-sdk AI (dependencies): Same-org scoped package from official Umbraco publisher; consistent with package family. ai
provenance no-provenance AI (provenance): Official Umbraco org package; provenance absence is a process gap, not a security risk for this publisher. ai
phantom-deps phantom-dep:@types/uuid AI (phantom-deps): Type-only package loaded by convention; stable FP. ai
phantom-deps phantom-dep:qs AI (phantom-deps): Referenced in orval/axios config files, not direct imports; stable FP for this build-tool package. ai
phantom-deps phantom-dep:@umbraco-cms/mcp-hosted AI (phantom-deps): Same-org scoped package; phantom-dep heuristic unreliable for peer/optional usage patterns. ai
phantom-deps phantom-dep:@types/yargs AI (phantom-deps): Type-only package loaded by convention; stable FP. ai
phantom-deps phantom-dep:axios AI (phantom-deps): Used via generated API client config, not direct import; stable FP. ai
phantom-deps phantom-dep:yargs AI (phantom-deps): CLI tooling dependency loaded via config; stable FP. ai
phantom-deps phantom-dep:dotenv AI (phantom-deps): Env config loaded at runtime, not statically imported; stable FP. ai

Versions (showing 8 of 8)

Version Deps Published
17.4.1 13 / 21
17.3.7 13 / 21
17.3.3 13 / 21
17.3.2 13 / 21
17.2.1 13 / 21
17.0.0 11 / 15
16.0.1 11 / 15
16.0.0 11 / 15

v17.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.3.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.3.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v17.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v16.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v16.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.