Mmcp.market

Dependency Management MCP server

online · 100% uptime
by sonatype.com·com.sonatype/dependency-management-mcp-server·v1.0.2·74 stars

Sonatype component intelligence: versions, security analysis, and Trust Score recommendations

B70/100grade B
What users say
No reviews yet
Be the first
Safety scan
B70/100

full report

Adoption
Growing

74 stars

Reviews

Write one

Nobody has reviewed Dependency Management yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Dependency Management tools

Tool list not cached yet. `describe` through the gateway fetches it live.

Public scan report

scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it

no findings
  • –Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 234ms (auth required)20/20
  • –Tool poisoningtools not inspected (endpoint requires auth); not countedn/a
  • Auth qualityauth enforced (bearer)9/15
  • Maintenancelast push 256 days ago4/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year9/10
Overall 70/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install Dependency Management in Claude Code, Cursor or VS Code

claude mcp add --transport http dependency-management-mcp-server https://mcp.guide.sonatype.com/mcp
Add to Cursor

What the publisher says

From the Dependency Management repository's README, as published. We do not edit it. Read it on GitHub

Sonatype MCP Server

A Model Context Protocol (MCP) server that connects AI assistants to Sonatype's dependency management and security intelligence platform. Empower your AI coding assistant with real-time insights into open source security vulnerabilities, license compliance, and dependency health.

Overview

The Sonatype MCP Server enables AI assistants to access Sonatype's comprehensive dependency intelligence directly within your development workflow. By integrating with the Model Context Protocol, your AI assistant can help you make informed decisions about dependencies, identify security risks, and maintain compliance — all without leaving your IDE.

Key Features

  • Component Version Selection - Select the best version the first time, without the side quest
  • Security Vulnerability Scanning - Identify known vulnerabilities in your project dependencies
  • License Compliance Checking - Ensure your dependencies meet your organization's license policies
  • Dependency Health Analysis - Get insights into dependency quality, maintenance status, and risk factors
  • Real-time Security Advisories - Stay informed about the latest security threats affecting your dependencies
  • Remediation Guidance - Receive actionable recommendations to fix vulnerabilities and compliance issues

Prerequisites

  • For IDEs or tools that only support stdio MCP servers (like IntelliJ), install mcp-remote:
npm install -g mcp-remote

Setup

The Sonatype MCP Server runs as a remote MCP server. Choose the setup instructions for your IDE or AI assistant:

Gemini Code Assist

Replace with your personal API token generated at https://guide.sonatype.com/settings/tokens

{
  "mcpServers": {
    "discoveredServer": {
      "httpUrl": "https://mcp.guide.sonatype.com/mcp",
      "headers": {
        "Authorization": "Bearer <your-token>"
      }
    }
  }
}

Claude Code

Add the server using the Claude CLI:

Replace with your personal API token generated at https://guide.sonatype.com/settings/tokens

claude mcp add --transport http --scope user sonatype-mcp https://mcp.guide.sonatype.com/mcp --header "Authorization: Bearer <your-token>"

VS Code Copilot

Add the following configuration to your global VS Code mcp.json or create a .vscode/mcp.json file in your workspace:

Replace with your personal API token generated at https://guide.sonatype.com/settings/tokens

{
  "servers": {
		"sonatype-mcp": {
			"url": "https://mcp.guide.sonatype.com/mcp",
			"type": "http",
			"headers": {
				"Authorization": "Bearer <your-token>"
			}
		}
	}
}

Windsurf

Create or edit ~/.codeium/windsurf/mcp_config.json:

Replace with your personal API token generated at https://guide.sonatype.com/settings/tokens

{
  "mcpServers": {
    "sonatype-mcp": {
      "command": "npx",
      "args": [
        "mcp-remote",
        "https://mcp.guide.sonatype.com/mcp",
        "--header",
        "Authorization: Bearer <your-token>"
      ]
    }
  }
}

IntelliJ with Junie

Global Scope: Go to IDE settings → Tools → Junie → MCP Settings. Click "+" and add:

Project Scope: Create .junie/mcp/.mcp.json in your project root:

Replace with your personal API token generated at https://guide.sonatype.com/settings/tokens

{
  "mcpServers": {
    "sonatype-mcp": {
      "command": "npx",
      "args": [
        "mcp-remote",
        "https://mcp.guide.sonatype.com/mcp",
        "--header",
        "Authorization: Bearer <your-token>"
      ]
    }
  }
}

Kiro

Create or edit ~/.kiro/settings/mcp.json:

Replace with your personal API token generated at https://guide.sonatype.com/settings/tokens

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

Dependency Management: common questions

Is Dependency Management MCP server safe?
Mostly: it is graded B (70/100). Read the Dependency Management safety report
How do I install Dependency Management?
It runs remotely at mcp.guide.sonatype.com. Add it to Claude Code, Cursor, VS Code or Claude Desktop with the snippets above, or call it through the mcp.market gateway without installing anything.
Does Dependency Management need an API key?
Yes. The endpoint refuses requests without credentials; the publisher's docs say how to get them.
Is Dependency Management maintained?
The last commit was 256 days ago (2026-01-14). The latest release is v1.0.2.
Is Dependency Management up?
100% of our last 28 checks got an answer. We check remote servers about four times a day.
What can I use instead of Dependency Management?
Servers from other publishers that do the same job: npm Registry MCP Server, CrowdStrike Falcon MCP Server and Wireshark MCP server. Compare all Dependency Management alternatives.

Alternatives to Dependency Management

Same job from other publishers: the closest match first, then the best rated.

All Dependency Management alternatives →
  • npm Registry MCP Server
    npm registry MCP server — package intelligence, security audits, dependency analysis
    B
  • CrowdStrike Falcon MCP Server
    Connects AI agents with CrowdStrike Falcon for security analysis and automation.
    A
  • Wireshark
    Professional network analysis with tshark. Security audits, deep-dives, and threat detection.
    A
  • Reversecore MCP
    Security-first MCP server for reverse engineering, malware analysis, forensics, and SAST.
    B
  • Npm Sentinel
    Advanced NPM analysis: Recursive security scanning, ecosystem awareness, and deep insights.
    A

More from sonatype.com →