
Translates a lockfile diff into a human-readable upgrade plan for npm, PyPI, and GitHub Actions.
Listed on
- Official MCP Registry
- Smithery
- Glamavia MCP Toplist
- PulseMCPvia MCP Toplist
First seen 2 Oct 2026. One server, whatever directories list it: each directory listing keeps its own page and history.
4
Directories
2 via MCP Toplist
2
Tools
From an anonymous probe
C
ToolBench grade
Arcade’s grade, not ours
1
GitHub stars
From MCP Toplist
Tools
| Tool | Description | Behaviour |
|---|---|---|
| analyze_package_change | Given one package and two versions (from -> to), returns a structured upgrade analysis: semver classification, GitHub release notes summary, detected breaking changes, security advisories fixed in the range, migration guide links, and a clear recommendation. Use when the user asks about a specific package upgrade ('what changed between react 18 and 19', 'is it safe to bump axios from 0.27 to 1.0', 'what does upgrading lodash 4.17.20 to 4.17.21 fix'). Supports npm, pypi, and github-actions (use the action reference as the name, e.g. actions/checkout). For analyzing many packages at once or a Dependabot batch, use analyze_packages_bulk instead. | Read-only |
| analyze_packages_bulk | Analyzes a list of package upgrades in parallel and returns a unified risk report with packages ranked by recommendation level (security > caution > review > likely-safe > safe). Use when the user provides many dependency changes from a Dependabot PR, npm outdated output, lockfile diff, or batch upgrade. Returns: total count, breakdown by semver class, total security fixes found, packages with breaking changes, and per-package details. Limit 50 packages per call (chunk larger lists). | Read-only |
| Directory | Listing | Tier | First seen |
|---|---|---|---|
| Official MCP Registry | io.github.DigiCatalyst-Systems/dep-diff-mcp | - | 2 Oct 2026 |
| Smithery | dep-diff-mcp | - | 2 Oct 2026 |
| Glama | Listed there according to MCP Toplist’s dataset; not collected by InvokeRank. | ||
| PulseMCP | Listed there according to MCP Toplist’s dataset; not collected by InvokeRank. | ||