{"_id":"@black-duck/mcp-server","_rev":"12-524f429728d9b25c3d50b99bff62503c","name":"@black-duck/mcp-server","dist-tags":{"latest":"1.1.8"},"versions":{"1.1.1":{"name":"@black-duck/mcp-server","version":"1.1.1","keywords":["mcp","model-context-protocol","black-duck","security","vulnerability","scanning","ai","sarif","static-analysis"],"author":{"name":"Black Duck Inc."},"license":"SEE LICENSE IN LICENSE","_id":"@black-duck/mcp-server@1.1.1","maintainers":[{"name":"blackduck-admin","email":"luisp@blackduck.com"}],"os":["darwin","linux","win32"],"bin":{"mcp-server":"dist/index.js"},"dist":{"shasum":"b5896ce178dd23b57e689829db2f833aaeaab778","tarball":"https://registry.npmjs.org/@black-duck/mcp-server/-/mcp-server-1.1.1.tgz","fileCount":296,"integrity":"sha512-sqKA/4F0Ya8TA/DJ4c94utuUrYYoqe6bxro+6fbLNRBGl4IAQyCVJUgJI1hnQQXCBb9V3EG6TWYDXXCXcVIwQA==","signatures":[{"sig":"MEYCIQCd0us/1ON2Z4pbmgxzfwlOQyU9FRNPzzzU3FTy9uyhTAIhAMs/lsIAPd3GMIbtsqp0gyms4hHrN/xAsBieo+WgnX8q","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":604267},"main":"dist/index.js","types":"./dist/index.d.ts","engines":{"node":">=24.0.0"},"gitHead":"16c8eeaa029ff6fd0009a190db8c1f41f170ccca","scripts":{"dev":"npm run build && node dist/index.js","lint":"eslint src/**/*.ts","build":"tsc","start":"node dist/index.js","format":"prettier --write src/**/*.ts","inspect":"npm run build && npx @modelcontextprotocol/inspector node dist/index.js","prepare":"husky install","lint:fix":"eslint src/**/*.ts --fix","type-check":"tsc --noEmit","format:check":"prettier --check src/**/*.ts","publish:jfrog":"npm publish","quality-check":"npm run type-check && npm run lint && npm run format:check","version:major":"npm version major","version:minor":"npm version minor","version:patch":"npm version patch","prepublishOnly":"npm run build && node scripts/copy-licenses.mjs","licenses:extract":"node scripts/extract-licenses.mjs","licenses:validate":"node scripts/validate-licenses.mjs"},"_npmUser":{"name":"blackduck-admin","email":"luisp@blackduck.com"},"_npmVersion":"11.6.2","description":"Black Duck MCP brings Signal's AI-powered security analysis directly into your development environment. Provides vulnerability detection through the Model Context Protocol.","directories":{},"lint-staged":{"src/**/*.{ts,tsx}":["eslint --fix","prettier --write"]},"_nodeVersion":"24.13.0","dependencies":{"axios":"^1.13.1","dotenv":"^17.2.3","winston":"^3.11.0","inversify":"^6.0.2","simple-git":"^3.30.0","reflect-metadata":"^0.2.2","rotating-file-stream":"^3.2.5","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"husky":"^9.1.7","eslint":"^8.57.0","prettier":"^3.6.2","typescript":"^5.5.3","@types/node":"^24.0.0","lint-staged":"^15.5.2","eslint-config-prettier":"^10.1.8","eslint-plugin-prettier":"^5.5.4","@typescript-eslint/parser":"^6.21.0","license-checker-rseidelsohn":"^4.4.2","@typescript-eslint/eslint-plugin":"^6.21.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server_1.1.1_1771542675544_0.9225206782166624","host":"s3://npm-registry-packages-npm-production"}},"1.1.2":{"name":"@black-duck/mcp-server","version":"1.1.2","keywords":["mcp","model-context-protocol","black-duck","security","vulnerability","scanning","ai","sarif","static-analysis"],"author":{"name":"Black Duck Inc."},"license":"SEE LICENSE IN LICENSE","_id":"@black-duck/mcp-server@1.1.2","maintainers":[{"name":"blackduck-admin","email":"luisp@blackduck.com"}],"os":["darwin","linux","win32"],"bin":{"mcp-server":"dist/index.js"},"dist":{"shasum":"2dc5f70c886c47d0d4f257836f11a2c158afdd24","tarball":"https://registry.npmjs.org/@black-duck/mcp-server/-/mcp-server-1.1.2.tgz","fileCount":298,"integrity":"sha512-cCHjFW+2qPCNxSBC0Vk3vucfmu4mda7oczQkquXQeRXjIqaD71WUgaWTT9rsxGTl/y2NBANTLFfyfJLV17Qe4A==","signatures":[{"sig":"MEQCIDzsIHDwqaMWQcYTNLJVlv5Vrb5B3P35nVCA57wZ3jYsAiBo4dZ1n6kTmZNcz+SEfWsy/+PbPPJ8OMIBlxEeftx76A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":606903},"main":"dist/index.js","types":"./dist/index.d.ts","engines":{"node":">=24.0.0"},"gitHead":"0306d4ab124c46d83bf81ba1194bc375ea53d920","scripts":{"dev":"npm run build && node dist/index.js","lint":"eslint src/**/*.ts","build":"tsc","start":"node dist/index.js","format":"prettier --write src/**/*.ts","inspect":"npm run build && npx @modelcontextprotocol/inspector node dist/index.js","prepare":"husky install","lint:fix":"eslint src/**/*.ts --fix","type-check":"tsc --noEmit","format:check":"prettier --check src/**/*.ts","publish:jfrog":"npm publish","quality-check":"npm run type-check && npm run lint && npm run format:check","version:major":"npm version major","version:minor":"npm version minor","version:patch":"npm version patch","prepublishOnly":"npm run build && node scripts/copy-licenses.mjs","licenses:extract":"node scripts/extract-licenses.mjs","licenses:validate":"node scripts/validate-licenses.mjs"},"_npmUser":{"name":"blackduck-admin","email":"luisp@blackduck.com"},"overrides":{"js-yaml":"4.1.1","minimatch":"10.2.2"},"_npmVersion":"11.6.2","description":"Black Duck MCP brings Signal's AI-powered security analysis directly into your development environment. Provides vulnerability detection through the Model Context Protocol.","directories":{},"lint-staged":{"src/**/*.{ts,tsx}":["eslint --fix","prettier --write"]},"_nodeVersion":"24.13.0","dependencies":{"axios":"^1.13.5","dotenv":"^17.2.3","winston":"^3.11.0","inversify":"^6.0.2","simple-git":"^3.30.0","reflect-metadata":"^0.2.2","rotating-file-stream":"^3.2.5","@modelcontextprotocol/sdk":"^1.27.0"},"_hasShrinkwrap":false,"devDependencies":{"husky":"^9.1.7","eslint":"^8.57.1","prettier":"^3.6.2","typescript":"^5.5.3","@types/node":"^24.0.0","lint-staged":"^15.5.2","eslint-config-prettier":"^10.1.8","eslint-plugin-prettier":"^5.5.4","@typescript-eslint/parser":"^6.21.0","license-checker-rseidelsohn":"^4.4.2","@typescript-eslint/eslint-plugin":"^6.21.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server_1.1.2_1771614645390_0.327561861351753","host":"s3://npm-registry-packages-npm-production"}},"1.1.3":{"name":"@black-duck/mcp-server","version":"1.1.3","keywords":["mcp","model-context-protocol","black-duck","security","vulnerability","scanning","ai","sarif","static-analysis"],"author":{"name":"Black Duck Inc."},"license":"SEE LICENSE IN LICENSE","_id":"@black-duck/mcp-server@1.1.3","maintainers":[{"name":"blackduck-admin","email":"luisp@blackduck.com"}],"os":["darwin","linux","win32"],"bin":{"mcp-server":"dist/index.js"},"dist":{"shasum":"6e22fb5a6f199d34bfd1540317b38bc56dc6e7de","tarball":"https://registry.npmjs.org/@black-duck/mcp-server/-/mcp-server-1.1.3.tgz","fileCount":384,"integrity":"sha512-5LISZfQDvJbl1Z0TW70ppxKDaLcFUwMVmarNM90u67UuK7ab+cGn/E/FMG5f8BbUIDBJBByI0koz48x8UolAHA==","signatures":[{"sig":"MEYCIQC8+GjJ1tcHfqMFKrheT4ouCcG/fBkEMHsoVA27Pq4BZQIhANxntsXQY2fRt8Xmol3CznymS7CJbKgot4OvuTP2/TSg","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":781003},"main":"dist/index.js","types":"./dist/index.d.ts","engines":{"node":">=24.0.0"},"gitHead":"859035f2bca5d6bc7b10845f563702b8ce7891d7","scripts":{"dev":"npm run build && node dist/index.js","lint":"eslint src/**/*.ts","build":"tsc","start":"node dist/index.js","format":"prettier --write src/**/*.ts","inspect":"npm run build && npx @modelcontextprotocol/inspector node dist/index.js","prepare":"husky install","lint:fix":"eslint src/**/*.ts --fix","type-check":"tsc --noEmit","format:check":"prettier --check src/**/*.ts","publish:jfrog":"npm publish","quality-check":"npm run type-check && npm run lint && npm run format:check","version:major":"npm version major","version:minor":"npm version minor","version:patch":"npm version patch","prepublishOnly":"npm run build && node scripts/copy-licenses.mjs","licenses:extract":"node scripts/extract-licenses.mjs","licenses:validate":"node scripts/validate-licenses.mjs"},"_npmUser":{"name":"blackduck-admin","email":"luisp@blackduck.com"},"overrides":{"js-yaml":"4.1.1","minimatch":"10.2.2"},"_npmVersion":"11.6.2","description":"Black Duck MCP brings Signal's AI-powered security analysis directly into your development environment. Provides vulnerability detection through the Model Context Protocol.","directories":{},"lint-staged":{"src/**/*.{ts,tsx}":["eslint --fix","prettier --write"]},"_nodeVersion":"24.13.0","dependencies":{"axios":"^1.13.5","dotenv":"^17.2.3","winston":"^3.11.0","inversify":"^6.0.2","simple-git":"^3.30.0","reflect-metadata":"^0.2.2","rotating-file-stream":"^3.2.5","@modelcontextprotocol/sdk":"^1.27.1"},"_hasShrinkwrap":false,"devDependencies":{"husky":"^9.1.7","eslint":"^8.57.1","prettier":"^3.6.2","typescript":"^5.5.3","@types/node":"^24.0.0","lint-staged":"^15.5.2","eslint-config-prettier":"^10.1.8","eslint-plugin-prettier":"^5.5.4","@typescript-eslint/parser":"^6.21.0","license-checker-rseidelsohn":"^4.4.2","@typescript-eslint/eslint-plugin":"^6.21.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server_1.1.3_1773238730671_0.9926102911364099","host":"s3://npm-registry-packages-npm-production"}},"1.1.4":{"name":"@black-duck/mcp-server","version":"1.1.4","keywords":["mcp","model-context-protocol","black-duck","security","vulnerability","scanning","ai","sarif","static-analysis"],"author":{"name":"Black Duck Inc."},"license":"SEE LICENSE IN LICENSE","_id":"@black-duck/mcp-server@1.1.4","maintainers":[{"name":"blackduck-admin","email":"luisp@blackduck.com"}],"os":["darwin","linux","win32"],"bin":{"mcp-server":"dist/index.js"},"dist":{"shasum":"42586da3a09e3c942de2564122d13aa8d2a5463b","tarball":"https://registry.npmjs.org/@black-duck/mcp-server/-/mcp-server-1.1.4.tgz","fileCount":384,"integrity":"sha512-QH1NYkgbK+PgzWYSuY+83soOyUeRLCfOtt0UjvA66FA7SxunBtZm+0fsYJacyy7pmM2EOtFgvggaG5vdwBgSvw==","signatures":[{"sig":"MEUCIQDcMO/ipEs2vljVc8I+f+7bgdtb9HfggzT/dRWMb6UYOgIgSKvIbW40RBewqQYRuLK7B5At4U5cgzivt7yhZGDMc+M=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":780988},"main":"dist/index.js","types":"./dist/index.d.ts","engines":{"node":">=24.0.0"},"gitHead":"1fd9fc1d60d0a3949f6f288d738c95ae6c2edcba","scripts":{"dev":"npm run build && node dist/index.js","lint":"eslint src/**/*.ts","build":"tsc","start":"node dist/index.js","format":"prettier --write src/**/*.ts","inspect":"npm run build && npx @modelcontextprotocol/inspector node dist/index.js","prepare":"husky install","lint:fix":"eslint src/**/*.ts --fix","type-check":"tsc --noEmit","format:check":"prettier --check src/**/*.ts","publish:jfrog":"npm publish","quality-check":"npm run type-check && npm run lint && npm run format:check","version:major":"npm version major","version:minor":"npm version minor","version:patch":"npm version patch","prepublishOnly":"npm run build && node scripts/copy-licenses.mjs","licenses:extract":"node scripts/extract-licenses.mjs","licenses:validate":"node scripts/validate-licenses.mjs"},"_npmUser":{"name":"blackduck-admin","email":"luisp@blackduck.com"},"overrides":{"js-yaml":"4.1.1","minimatch":"10.2.2"},"_npmVersion":"11.6.2","description":"Black Duck MCP brings Signal's AI-powered security analysis directly into your development environment. Provides vulnerability detection through the Model Context Protocol.","directories":{},"lint-staged":{"src/**/*.{ts,tsx}":["eslint --fix","prettier --write"]},"_nodeVersion":"24.13.0","dependencies":{"axios":"^1.13.5","dotenv":"^17.2.3","winston":"^3.11.0","inversify":"^6.0.2","simple-git":"^3.30.0","reflect-metadata":"^0.2.2","rotating-file-stream":"^3.2.5","@modelcontextprotocol/sdk":"^1.27.1"},"_hasShrinkwrap":false,"devDependencies":{"husky":"^9.1.7","eslint":"^8.57.1","prettier":"^3.6.2","typescript":"^5.5.3","@types/node":"^24.0.0","lint-staged":"^15.5.2","eslint-config-prettier":"^10.1.8","eslint-plugin-prettier":"^5.5.4","@typescript-eslint/parser":"^6.21.0","license-checker-rseidelsohn":"^4.4.2","@typescript-eslint/eslint-plugin":"^6.21.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server_1.1.4_1773255140823_0.6758365427572472","host":"s3://npm-registry-packages-npm-production"}},"1.1.5":{"name":"@black-duck/mcp-server","version":"1.1.5","keywords":["mcp","model-context-protocol","black-duck","security","vulnerability","scanning","ai","sarif","static-analysis"],"author":{"name":"Black Duck Inc."},"license":"SEE LICENSE IN LICENSE","_id":"@black-duck/mcp-server@1.1.5","maintainers":[{"name":"blackduck-admin","email":"luisp@blackduck.com"},{"name":"jfitzpat-bd","email":"jfitzpat@blackduck.com"}],"os":["darwin","linux","win32"],"bin":{"mcp-server":"dist/index.js"},"dist":{"shasum":"df14904533423682c79ecf0ca50f877f17363c60","tarball":"https://registry.npmjs.org/@black-duck/mcp-server/-/mcp-server-1.1.5.tgz","fileCount":304,"integrity":"sha512-UKcL3bKFDnxUqQzkoY+hg5RmhZmDlCmINzY1XiMnGlKuFTlZwB2qMpyds7SxAyhyq+jY3EJGubRmhTjr4s1AuA==","signatures":[{"sig":"MEUCIFOqjxJVJKnuBWMvKwobM3BywRe1q2f4pYYeTWmhNOcXAiEAuxqAc0IrXQ8ExtkcPpWh6nANVQk7Hh9nxrrs/iBsEkY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":641843},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=24.0.0"},"gitHead":"053b1b86e4a9c0731eb01ed110c5980860bd527e","mcpName":"com.blackduck/mcp-server","scripts":{"dev":"npm run build && node dist/index.js","lint":"eslint src/**/*.ts","test":"vitest run","build":"tsc","start":"node dist/index.js","format":"prettier --write src/**/*.ts","inspect":"npm run build && npx @modelcontextprotocol/inspector node dist/index.js","prepare":"husky install","lint:fix":"eslint src/**/*.ts --fix","type-check":"tsc --noEmit","format:check":"prettier --check src/**/*.ts","publish:jfrog":"npm publish","quality-check":"npm run type-check && npm run lint && npm run format:check","test:coverage":"vitest run --coverage","version:major":"npm version major","version:minor":"npm version minor","version:patch":"npm version patch","prepublishOnly":"npm run build && node scripts/copy-licenses.mjs","licenses:extract":"node scripts/extract-licenses.mjs","licenses:validate":"node scripts/validate-licenses.mjs"},"_npmUser":{"name":"blackduck-admin","email":"luisp@blackduck.com"},"overrides":{"js-yaml":"4.1.1","minimatch":"10.2.2"},"_npmVersion":"10.9.2","description":"Black Duck MCP brings Signal's AI-powered security analysis directly into your development environment. Provides vulnerability detection through the Model Context Protocol.","directories":{},"lint-staged":{"src/**/*.{ts,tsx}":["eslint --fix","prettier --write"]},"_nodeVersion":"23.10.0","dependencies":{"axios":"1.16.1","dotenv":"17.4.2","winston":"3.19.0","inversify":"8.1.0","simple-git":"3.36.0","reflect-metadata":"0.2.2","rotating-file-stream":"3.2.9","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"husky":"9.1.7","eslint":"10.4.0","vitest":"4.1.5","prettier":"3.8.3","@eslint/js":"10.0.1","typescript":"5.9.3","@types/node":"25.6.0","lint-staged":"16.4.0","typescript-eslint":"8.59.1","@vitest/coverage-v8":"4.1.5","eslint-config-prettier":"10.1.8","eslint-plugin-prettier":"5.5.5","license-checker-rseidelsohn":"4.4.2"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server_1.1.5_1780543842494_0.4338169936797702","host":"s3://npm-registry-packages-npm-production"}},"1.1.6":{"name":"@black-duck/mcp-server","version":"1.1.6","keywords":["mcp","model-context-protocol","black-duck","security","vulnerability","scanning","ai","sarif","static-analysis"],"author":{"name":"Black Duck Inc."},"license":"SEE LICENSE IN LICENSE","_id":"@black-duck/mcp-server@1.1.6","maintainers":[{"name":"blackduck-admin","email":"luisp@blackduck.com"},{"name":"jfitzpat-bd","email":"jfitzpat@blackduck.com"}],"os":["darwin","linux","win32"],"bin":{"mcp-server":"dist/index.js"},"dist":{"shasum":"c1e6788e39fcc94b602cda006b0f5b231b648fda","tarball":"https://registry.npmjs.org/@black-duck/mcp-server/-/mcp-server-1.1.6.tgz","fileCount":304,"integrity":"sha512-1G9clb7uD9ODS2C/E2e5mOiVOuPqwwrIvJXo6G++ryvwEhPYDb/Nt7FvUkdzT47vcl8mxOvJnJrmy8G5eRsFXw==","signatures":[{"sig":"MEYCIQCeLIInaKAcewoXrffevoQtaOl4p+/exLpw+1GBFr4xuQIhAIABai+iCFgoVvQvHLX39OnN8R7FaCNudXEA4xSmL8D7","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":641843},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=24.0.0"},"gitHead":"b10433eff873f499d0eef45fba76c14c965c8815","mcpName":"com.blackduck/mcp-server","scripts":{"dev":"npm run build && node dist/index.js","lint":"eslint src/**/*.ts","test":"vitest run","build":"tsc","start":"node dist/index.js","format":"prettier --write src/**/*.ts","inspect":"npm run build && npx @modelcontextprotocol/inspector node dist/index.js","prepare":"husky install","lint:fix":"eslint src/**/*.ts --fix","type-check":"tsc --noEmit","format:check":"prettier --check src/**/*.ts","publish:jfrog":"npm publish","quality-check":"npm run type-check && npm run lint && npm run format:check","test:coverage":"vitest run --coverage","version:major":"npm version major","version:minor":"npm version minor","version:patch":"npm version patch","prepublishOnly":"npm run build && node scripts/copy-licenses.mjs","licenses:extract":"node scripts/extract-licenses.mjs","licenses:validate":"node scripts/validate-licenses.mjs"},"_npmUser":{"name":"blackduck-admin","email":"luisp@blackduck.com"},"overrides":{"js-yaml":"4.1.1","minimatch":"10.2.2"},"_npmVersion":"10.9.2","description":"Black Duck MCP brings Signal's AI-powered security analysis directly into your development environment. Provides vulnerability detection through the Model Context Protocol.","directories":{},"lint-staged":{"src/**/*.{ts,tsx}":["eslint --fix","prettier --write"]},"_nodeVersion":"23.10.0","dependencies":{"axios":"1.16.1","dotenv":"17.4.2","winston":"3.19.0","inversify":"8.1.0","simple-git":"3.36.0","reflect-metadata":"0.2.2","rotating-file-stream":"3.2.9","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"husky":"9.1.7","eslint":"10.4.0","vitest":"4.1.5","prettier":"3.8.3","@eslint/js":"10.0.1","typescript":"5.9.3","@types/node":"25.6.0","lint-staged":"16.4.0","typescript-eslint":"8.59.1","@vitest/coverage-v8":"4.1.5","eslint-config-prettier":"10.1.8","eslint-plugin-prettier":"5.5.5","license-checker-rseidelsohn":"4.4.2"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server_1.1.6_1780607953258_0.07445380931331314","host":"s3://npm-registry-packages-npm-production"}},"1.1.7":{"name":"@black-duck/mcp-server","version":"1.1.7","keywords":["mcp","model-context-protocol","black-duck","security","vulnerability","scanning","ai","sarif","static-analysis"],"author":{"name":"Black Duck Inc."},"license":"SEE LICENSE IN LICENSE","_id":"@black-duck/mcp-server@1.1.7","maintainers":[{"name":"blackduck-admin","email":"luisp@blackduck.com"},{"name":"jfitzpat-bd","email":"jfitzpat@blackduck.com"}],"os":["darwin","linux","win32"],"bin":{"mcp-server":"dist/index.js"},"dist":{"shasum":"89c2a6bca8b436fc8f662da29a23bd2f6350ef4a","tarball":"https://registry.npmjs.org/@black-duck/mcp-server/-/mcp-server-1.1.7.tgz","fileCount":304,"integrity":"sha512-NGouMyetu00yWtxoWoWXOyykDzNifjznCLyTazsiMwkgoc+MM91KMTJkmwYYF4GS3j7dl07AajFQpZlBDPoHHA==","signatures":[{"sig":"MEYCIQDD288GXIknOqr8lqklRX6TnPy7mg1bHPPtNPtqg6qc8QIhAM5tQdwWLHyOsSd0D26ZS8NSmS0I4xXJYmF+0PrXsKe3","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":642509},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=24.0.0"},"gitHead":"177e0b457390670ebb78659485dd6e0d3e7ef299","mcpName":"com.blackduck/mcp-server","scripts":{"dev":"npm run build && node dist/index.js","lint":"eslint src/**/*.ts","test":"vitest run","build":"tsc","start":"node dist/index.js","format":"prettier --write src/**/*.ts","inspect":"npm run build && npx @modelcontextprotocol/inspector node dist/index.js","prepare":"husky install || exit 0","version":"node scripts/sync-manifest-version.mjs && git add manifest.json","lint:fix":"eslint src/**/*.ts --fix","mcpb:pack":"npm run mcpb:build && npm run mcpb:clean && npm run mcpb:install-prod && npm run mcpb:validate && mcpb pack . black-duck-mcp.mcpb && npm install","mcpb:build":"npm run build && node scripts/copy-licenses.mjs && node scripts/sync-manifest-version.mjs","mcpb:clean":"node -e \"require('fs').rmSync('node_modules',{recursive:true,force:true})\"","type-check":"tsc --noEmit","format:check":"prettier --check src/**/*.ts","mcpb:pack:ci":"npm run mcpb:build && npm run mcpb:validate && mcpb pack . black-duck-mcp.mcpb","mcpb:validate":"mcpb validate manifest.json","publish:jfrog":"npm publish","quality-check":"npm run type-check && npm run lint && npm run format:check","test:coverage":"vitest run --coverage","version:major":"npm version major","version:minor":"npm version minor","version:patch":"npm version patch","prepublishOnly":"npm run build && node scripts/copy-licenses.mjs","licenses:extract":"node scripts/extract-licenses.mjs","licenses:validate":"node scripts/validate-licenses.mjs","mcpb:install-prod":"npm ci --omit=dev"},"_npmUser":{"name":"blackduck-admin","email":"luisp@blackduck.com"},"overrides":{"js-yaml":"4.1.1","minimatch":"10.2.2"},"_npmVersion":"11.13.0","description":"Black Duck MCP brings Signal's AI-powered security analysis directly into your development environment. Provides vulnerability detection through the Model Context Protocol.","directories":{},"lint-staged":{"src/**/*.{ts,tsx}":["eslint --fix","prettier --write"]},"_nodeVersion":"24.16.0","dependencies":{"axios":"1.16.1","dotenv":"17.4.2","winston":"3.19.0","inversify":"8.1.0","simple-git":"3.36.0","reflect-metadata":"0.2.2","rotating-file-stream":"3.2.9","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"husky":"9.1.7","eslint":"10.4.0","vitest":"4.1.5","prettier":"3.8.3","@eslint/js":"10.0.1","typescript":"5.9.3","@types/node":"25.6.0","lint-staged":"16.4.0","typescript-eslint":"8.59.1","@vitest/coverage-v8":"4.1.5","eslint-config-prettier":"10.1.8","eslint-plugin-prettier":"5.5.5","license-checker-rseidelsohn":"4.4.2"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server_1.1.7_1781197618579_0.17197877602157474","host":"s3://npm-registry-packages-npm-production"}},"1.1.8":{"name":"@black-duck/mcp-server","version":"1.1.8","mcpName":"com.blackduck/mcp-server","description":"Black Duck MCP brings Signal's AI-powered security analysis directly into your development environment. Provides vulnerability detection through the Model Context Protocol.","type":"module","main":"dist/index.js","bin":{"mcp-server":"dist/index.js"},"scripts":{"build":"tsc","dev":"npm run build && node dist/index.js","start":"node dist/index.js","inspect":"npm run build && npx @modelcontextprotocol/inspector node dist/index.js","prepublishOnly":"npm run build && node scripts/copy-licenses.mjs","publish:jfrog":"npm publish","version:patch":"npm version patch","version:minor":"npm version minor","version:major":"npm version major","lint":"eslint src/**/*.ts","lint:fix":"eslint src/**/*.ts --fix","format":"prettier --write src/**/*.ts","format:check":"prettier --check src/**/*.ts","type-check":"tsc --noEmit","test":"vitest run","test:coverage":"vitest run --coverage","quality-check":"npm run type-check && npm run lint && npm run format:check && npm run compatibility:validate","prepare":"husky install || exit 0","licenses:extract":"node scripts/extract-licenses.mjs","licenses:validate":"node scripts/validate-licenses.mjs","compatibility:validate":"node scripts/validate-compatibility.mjs","mcpb:clean":"node -e \"require('fs').rmSync('node_modules',{recursive:true,force:true})\"","mcpb:install-prod":"npm ci --omit=dev","mcpb:build":"npm run build && node scripts/copy-licenses.mjs && node scripts/sync-manifest-version.mjs","mcpb:validate":"mcpb validate manifest.json","mcpb:pack":"npm run mcpb:build && npm run mcpb:clean && npm run mcpb:install-prod && npm run mcpb:validate && mcpb pack . black-duck-mcp.mcpb && npm install","mcpb:pack:ci":"npm run mcpb:build && npm run mcpb:validate && mcpb pack . black-duck-mcp.mcpb","version":"node scripts/sync-manifest-version.mjs && git add manifest.json","version:check-sync":"node scripts/check-version-sync.mjs"},"keywords":["mcp","model-context-protocol","black-duck","security","vulnerability","scanning","ai","sarif","static-analysis"],"author":{"name":"Black Duck Inc."},"license":"MIT","engines":{"node":">=24.0.0"},"os":["darwin","linux","win32"],"dependencies":{"@modelcontextprotocol/sdk":"1.29.0","axios":"1.16.1","dotenv":"17.4.2","inversify":"8.1.0","reflect-metadata":"0.2.2","rotating-file-stream":"3.2.9","simple-git":"3.36.0","winston":"3.19.0"},"devDependencies":{"@eslint/js":"10.0.1","@types/node":"25.6.0","@vitest/coverage-v8":"4.1.5","eslint":"10.4.0","eslint-config-prettier":"10.1.8","eslint-plugin-prettier":"5.5.5","husky":"9.1.7","license-checker-rseidelsohn":"4.4.2","lint-staged":"16.4.0","prettier":"3.8.3","typescript":"5.9.3","typescript-eslint":"8.59.1","vitest":"4.1.5"},"overrides":{"js-yaml":"4.1.1","minimatch":"10.2.2"},"lint-staged":{"src/**/*.{ts,tsx}":["eslint --fix","prettier --write"]},"gitHead":"5bec9b9aef2ae8e073aa972780e6db678e9b810a","types":"./dist/index.d.ts","_id":"@black-duck/mcp-server@1.1.8","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-4f7RXEHeso8ybg7/+nZQjCcCppPLpaV50+Go/LiNs2XL/P11DjCDxtfyqy2PT4edMXKe3cgP/J8hQUZK54EFHA==","shasum":"651852705f55b6605cb65947fb8d1ab97439f948","tarball":"https://registry.npmjs.org/@black-duck/mcp-server/-/mcp-server-1.1.8.tgz","fileCount":312,"unpackedSize":659569,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDKvfL7w56w/DIWECClqKYfLtpD8v2pIZQ/Lhq6Zb+YhAIgVB/YadrkMxu5e/epXW/duGinoMEGkSfbmDqGnwonnE8="}]},"_npmUser":{"name":"blackduck-admin","email":"luisp@blackduck.com"},"directories":{},"maintainers":[{"name":"blackduck-admin","email":"luisp@blackduck.com"},{"name":"jfitzpat-bd","email":"jfitzpat@blackduck.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-server_1.1.8_1784320727286_0.6303396542643849"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-19T23:11:15.417Z","modified":"2026-07-17T20:38:47.650Z","1.1.0":"2026-02-19T22:37:05.054Z","1.1.1":"2026-02-19T23:11:15.699Z","1.1.2":"2026-02-20T19:10:45.568Z","1.1.3":"2026-03-11T14:18:50.933Z","1.1.4":"2026-03-11T18:52:21.059Z","1.1.5":"2026-06-04T03:30:42.636Z","1.1.6":"2026-06-04T21:19:13.405Z","1.1.7":"2026-06-11T17:06:58.869Z","1.1.8":"2026-07-17T20:38:47.473Z"},"author":{"name":"Black Duck Inc."},"license":"MIT","keywords":["mcp","model-context-protocol","black-duck","security","vulnerability","scanning","ai","sarif","static-analysis"],"description":"Black Duck MCP brings Signal's AI-powered security analysis directly into your development environment. Provides vulnerability detection through the Model Context Protocol.","maintainers":[{"name":"blackduck-admin","email":"luisp@blackduck.com"},{"name":"jfitzpat-bd","email":"jfitzpat@blackduck.com"}],"readme":"# Black Duck MCP\n\nBlack Duck MCP brings Signal's AI-powered security analysis directly into your development environment. It enables code scanning through leading coding assistants – including Claude, Gemini, Cursor, Copilot, and others – so you can detect security issues, receive actionable insights, and apply recommended fixes quickly and consistently.\n\n## Key Features & Benefits\n\n- **Changes Scan**:\n  - Performs fast, incremental security scans focused only on the code changes introduced by the developer. \n  - Ideal for early-stage detection of issues as code is written\n- **File Scan**:\n  - Runs a targeted security analysis on specific files or directories. \n  - Best suited for projects that do not use Git or for developers who want to analyze specific portions of the codebase\n- **Cross-Platform Support**:\n  - Works on Windows, macOS, and Linux\n\n## Requirements\n\n- [Signal License](https://www.blackduck.com/signal-ai-appsec/early-access.html)\n- [Node.js](https://nodejs.org/) v24.0.0 or newer\n\n## Getting started\n\n### Step 1: Add to your MCP client\n\nAdd the following configuration to your MCP client (using Claude user level config as example):\n```json\n{\n  \"mcpServers\": {\n    \"black-duck-signal\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@black-duck/mcp-server\"],\n      \"env\": {\n        \"BLACKDUCK_MCP_GATEWAY_KEY\": \"your-api-key-here\"\n      }\n    }\n  }\n}\n```\n\n### Step 2: Your first scan\n\nUse one of following prompts in your MCP client to get you started:\n\n```\nScan my code changes for security vulnerabilities\n```\n\nYour MCP client should execute a security scan and report any vulnerabilities found on the **code changes made**. Requires that the project is git based to determine what files have changed.\n\n```\nScan the changed files with respect to the main branch\n```\n\nYour MCP client should execute a security scan taking into account **only code changes in the current branch** vs the main branch and report any vulnerabilities found on the code changes made. Requires that the project is git based to determine what files have changed.\n\n```\nScan all files under folder foobar for security vulnerabilities\n```\n\nYour MCP client should execute a security scan and report any vulnerabilities found.\n\n## Tools\n\n| Tool | Parameters | Returns | Best Use Cases |\n|------|------------|---------|----------------|\n| **`run_changes_security_scan`** | **`projectPath`** (required): Absolute path to git project<br><br>**`gitPatchMode`** (required):<br>• `all-uncommitted`: Scan staged + unstaged changes<br>• `reference-branch`: Scan changes since branching<br><br>**`referenceBranch`** (optional): Reference branch name (e.g., `main`)<br><br>**`scanEntireFileContent`** (optional): When `true`, scans entire content of changed files instead of just changed lines. Default: `false` | • `sarifFilePath`: Path to SARIF report<br>• `status`: `success` or `failure`<br>• `resourceUris`: MCP resource URIs<br>• `issueCounts`: Counts by severity<br>• `analysisGuidance`: Analysis steps | • **Faster**: Analyzes only changed code<br>• **Focused**: Shows issues from your changes<br>• **Iterative**: Perfect for dev workflows & CI/CD<br>• **Efficient**: Reduces scan cost and time |\n| **`run_security_scan`** | **`projectPath`** (required): Absolute path to project<br><br>**`filePaths`** (required): Array of file/directory absolute paths to scan | • `sarifFilePath`: Path to SARIF report<br>• `status`: `success` or `failure`<br>• `resourceUris`: MCP resource URIs<br>• `issueCounts`: Counts by severity<br>• `analysisGuidance`: Analysis steps | • Analyzing specific files/directories<br>• Focused security review of critical paths<br>• Quick checks during development<br>• Non-git projects |\n\n## Optional Configuration\n\nThe Black Duck Signal MCP server supports the following environment variables:\n\n| Variable | Default | Description |\n|----------|---------|-------------|\n| `BLACKDUCK_MCP_GATEWAY_KEY` | None (required) | API key for enhanced AI analysis |\n| `BLACKDUCK_HOME` | User's home directory | Override the default `.blackduck` folder location |\n| `BLACKDUCK_MCP_TOOL_TIMEOUT` | `1800000` (30 min) | Scan timeout in milliseconds |\n| `BLACKDUCK_MCP_LOG_LEVEL` | `info` | Log level: `error`, `warn`, `info`, or `debug` |\n\nYou can set these variables in your MCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"black-duck\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@black-duck/mcp-server\"],\n      \"env\": {\n        \"BLACKDUCK_MCP_GATEWAY_KEY\": \"your-api-key-here\",\n        \"BLACKDUCK_MCP_LOG_LEVEL\": \"debug\"\n      }\n    }\n  }\n}\n```\n\n\n## Logging and Troubleshooting\n\n### Log Location\n\nAll MCP logs are written to `/Users/<username>/.blackduck/mcp/logs/` for linux/mac and `C:\\Users\\<Username>\\AppData\\Roaming\\BlackDuck\\mcp\\logs\\` (customizable via `BLACKDUCK_HOME`):\n\n- `black-duck-mcp.log` - Combined log (all levels)\n- `black-duck-mcp-error.log` - Error-only log\n\n## IP Allowlist\n\nThe following URLs and IP addresses must be accessible for the MCP server to function properly:\n\n| URL | IP Address |\n|-----|------------|\n| `repo.blackduck.com` | `34.149.5.115` |\n| `llm.core.blackduck.com` | `104.18.36.253` |\n\n> Ensure your firewall allows outbound HTTPS (port 443) connections to these endpoints\n\n\n## License\n\nThis project is licensed under the [MIT License](LICENSE).\n\n\n## Resources\n- [Documentation](https://documentation.blackduck.com/bundle/signal/page/topics/c_signal_overview.html)\n- [Black Duck Signal](https://www.blackduck.com/signal-ai-appsec.html)\n- [Contact Us](https://www.blackduck.com/signal-ai-appsec/early-access.html)\n- [Request SBOM](mailto:sbom_request@blackduck.com)","readmeFilename":"README.md"}