Dependency Management MCP server
online · 100% uptimeSonatype component intelligence: versions, security analysis, and Trust Score recommendations
74 stars
Reviews
Write oneNobody has reviewed Dependency Management yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Dependency Management tools
Tool list not cached yet. `describe` through the gateway fetches it live.
Public scan report
scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 234ms (auth required)20/20
- –Tool poisoningtools not inspected (endpoint requires auth); not countedn/a
- Auth qualityauth enforced (bearer)9/15
- Maintenancelast push 256 days ago4/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year9/10
Install Dependency Management in Claude Code, Cursor or VS Code
claude mcp add --transport http dependency-management-mcp-server https://mcp.guide.sonatype.com/mcp
What the publisher says
From the Dependency Management repository's README, as published. We do not edit it. Read it on GitHub
Sonatype MCP Server
A Model Context Protocol (MCP) server that connects AI assistants to Sonatype's dependency management and security intelligence platform. Empower your AI coding assistant with real-time insights into open source security vulnerabilities, license compliance, and dependency health.
Overview
The Sonatype MCP Server enables AI assistants to access Sonatype's comprehensive dependency intelligence directly within your development workflow. By integrating with the Model Context Protocol, your AI assistant can help you make informed decisions about dependencies, identify security risks, and maintain compliance — all without leaving your IDE.
Key Features
- Component Version Selection - Select the best version the first time, without the side quest
- Security Vulnerability Scanning - Identify known vulnerabilities in your project dependencies
- License Compliance Checking - Ensure your dependencies meet your organization's license policies
- Dependency Health Analysis - Get insights into dependency quality, maintenance status, and risk factors
- Real-time Security Advisories - Stay informed about the latest security threats affecting your dependencies
- Remediation Guidance - Receive actionable recommendations to fix vulnerabilities and compliance issues
Prerequisites
- For IDEs or tools that only support stdio MCP servers (like IntelliJ), install mcp-remote:
npm install -g mcp-remoteSetup
The Sonatype MCP Server runs as a remote MCP server. Choose the setup instructions for your IDE or AI assistant:
Gemini Code Assist
Replace with your personal API token generated at https://guide.sonatype.com/settings/tokens
{
"mcpServers": {
"discoveredServer": {
"httpUrl": "https://mcp.guide.sonatype.com/mcp",
"headers": {
"Authorization": "Bearer <your-token>"
}
}
}
}Claude Code
Add the server using the Claude CLI:
Replace with your personal API token generated at https://guide.sonatype.com/settings/tokens
claude mcp add --transport http --scope user sonatype-mcp https://mcp.guide.sonatype.com/mcp --header "Authorization: Bearer <your-token>"VS Code Copilot
Add the following configuration to your global VS Code mcp.json or create a .vscode/mcp.json file in your workspace:
Replace with your personal API token generated at https://guide.sonatype.com/settings/tokens
{
"servers": {
"sonatype-mcp": {
"url": "https://mcp.guide.sonatype.com/mcp",
"type": "http",
"headers": {
"Authorization": "Bearer <your-token>"
}
}
}
}Windsurf
Create or edit ~/.codeium/windsurf/mcp_config.json:
Replace with your personal API token generated at https://guide.sonatype.com/settings/tokens
{
"mcpServers": {
"sonatype-mcp": {
"command": "npx",
"args": [
"mcp-remote",
"https://mcp.guide.sonatype.com/mcp",
"--header",
"Authorization: Bearer <your-token>"
]
}
}
}IntelliJ with Junie
Global Scope: Go to IDE settings → Tools → Junie → MCP Settings. Click "+" and add:
Project Scope: Create .junie/mcp/.mcp.json in your project root:
Replace with your personal API token generated at https://guide.sonatype.com/settings/tokens
{
"mcpServers": {
"sonatype-mcp": {
"command": "npx",
"args": [
"mcp-remote",
"https://mcp.guide.sonatype.com/mcp",
"--header",
"Authorization: Bearer <your-token>"
]
}
}
}Kiro
Create or edit ~/.kiro/settings/mcp.json:
Replace with your personal API token generated at https://guide.sonatype.com/settings/tokens
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Dependency Management: common questions
- Is Dependency Management MCP server safe?
- Mostly: it is graded B (70/100). Read the Dependency Management safety report
- How do I install Dependency Management?
- It runs remotely at mcp.guide.sonatype.com. Add it to Claude Code, Cursor, VS Code or Claude Desktop with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does Dependency Management need an API key?
- Yes. The endpoint refuses requests without credentials; the publisher's docs say how to get them.
- Is Dependency Management maintained?
- The last commit was 256 days ago (2026-01-14). The latest release is v1.0.2.
- Is Dependency Management up?
- 100% of our last 28 checks got an answer. We check remote servers about four times a day.
- What can I use instead of Dependency Management?
- Servers from other publishers that do the same job: npm Registry MCP Server, CrowdStrike Falcon MCP Server and Wireshark MCP server. Compare all Dependency Management alternatives.
Alternatives to Dependency Management
Same job from other publishers: the closest match first, then the best rated.
- npm Registry MCP Servernpm registry MCP server — package intelligence, security audits, dependency analysisnot reviewedGrowingB
- CrowdStrike Falcon MCP ServerConnects AI agents with CrowdStrike Falcon for security analysis and automation.not reviewedEstablishedA
- WiresharkProfessional network analysis with tshark. Security audits, deep-dives, and threat detection.not reviewedEstablishedA
- Reversecore MCPSecurity-first MCP server for reverse engineering, malware analysis, forensics, and SAST.not reviewedEstablishedB
- Npm SentinelAdvanced NPM analysis: Recursive security scanning, ecosystem awareness, and deep insights.not reviewedGrowingA