io.github.mattpicone/upgradelens
repo:https://github.com/mattpicone/upgradelens
Evidence-backed npm/PyPI upgrade risk analysis for agents: CVEs, breaking changes, EOL, compat.
- transport:
- remote
- credential class:
- self-provisionable
Owner verification
Not yet verified. Verifying proves you control this server and is free, permanently — it never changes a published score.
Start verification →Tools
- check_dependency_upgradeshallow
Use when asked for a go/no-go risk decision, cited assessment, or whether an existing npm or PyPI dependency can move from one exact installed version to one exact target version before editing. Returns decision/action_allowed plus source-cited vulnerability delta, registry-declared Node/Python compatibility, direct-dependency changes, EOL, and documented breaking-change evidence. Use plan_dependency_upgrade instead when migration, refactor, changelog, or test steps are requested. Do not use to choose a target, install a new package, inspect only one version, answer general documentation questions, or analyze another ecosystem. Read-only and safe to retry; validation or unavailable evidence is returned explicitly.
- find_safe_upgrade_targetshallow
Use only when asked which version to evaluate, rank, or recommend and an existing npm or PyPI dependency has an exact current version but no target yet. Ranks candidates using version distance and OSV advisory deltas; candidates are not declared safe. Every candidate requires either check_dependency_upgrade for a decision or plan_dependency_upgrade when migration steps are requested; the plan tool already includes the full check. This tool does not evaluate repository code or caller runtime compatibility. Do not use when a target is stated, for a new installation or simple latest-version lookup, or as authorization to modify files. Read-only and safe to retry; unavailable evidence is returned explicitly.
- plan_dependency_upgradeshallow
Use when asked for a migration checklist, refactor actions, ordered review actions, changelog links, or test steps and both exact current and target versions are known. Returns the complete upgrade check plus source-linked migration_actions and changelog_urls; actions remain gated by action_allowed. Supports npm and PyPI only. Use check_dependency_upgrade instead for a go/no-go risk decision without steps. Do not use to choose a target, install a package, provide general tutorials, or modify files. Read-only and safe to retry; validation or unavailable evidence is returned explicitly.
Embed this server’s score
Tool count and median score across every tool in this server’s corpus — honest in a way a single cherry-picked tool’s badge wouldn’t be.
[](https://vouch.tools/servers/21c102a3-625f-4ce0-8e9b-280d031d2626)