lockvet MCP Server
by matteo-sungio.github.matteo-sung/lockvetv0.6.20
Explain any lockfile or workflow-pin change: bumps, vulns, ages, deprecations — 61 formats
context tax
queued
security
queued
cold start
queued
freshness
Active23d ago
Install lockvet MCP server
Install in Claude Code
claude mcp add lockvet -e GITHUB_TOKEN='<github-token>' -e GITLAB_TOKEN='<gitlab-token>' -e BITBUCKET_TOKEN='<bitbucket-token>' -e GITEA_TOKEN='<gitea-token>' -e AZURE_DEVOPS_TOKEN='<azure-devops-token>' -- docker run -i --rm -e GITHUB_TOKEN -e GITLAB_TOKEN -e BITBUCKET_TOKEN -e GITEA_TOKEN -e AZURE_DEVOPS_TOKEN ghcr.io/matteo-sung/lockvet:0.6.20 lockvet mcpInstall in Cursor
{
"mcpServers": {
"lockvet": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"GITHUB_TOKEN",
"-e",
"GITLAB_TOKEN",
"-e",
"BITBUCKET_TOKEN",
"-e",
"GITEA_TOKEN",
"-e",
"AZURE_DEVOPS_TOKEN",
"ghcr.io/matteo-sung/lockvet:0.6.20",
"lockvet",
"mcp"
],
"env": {
"GITHUB_TOKEN": "<github-token>",
"GITLAB_TOKEN": "<gitlab-token>",
"BITBUCKET_TOKEN": "<bitbucket-token>",
"GITEA_TOKEN": "<gitea-token>",
"AZURE_DEVOPS_TOKEN": "<azure-devops-token>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"lockvet": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"GITHUB_TOKEN",
"-e",
"GITLAB_TOKEN",
"-e",
"BITBUCKET_TOKEN",
"-e",
"GITEA_TOKEN",
"-e",
"AZURE_DEVOPS_TOKEN",
"ghcr.io/matteo-sung/lockvet:0.6.20",
"lockvet",
"mcp"
],
"env": {
"GITHUB_TOKEN": "<github-token>",
"GITLAB_TOKEN": "<gitlab-token>",
"BITBUCKET_TOKEN": "<bitbucket-token>",
"GITEA_TOKEN": "<gitea-token>",
"AZURE_DEVOPS_TOKEN": "<azure-devops-token>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"lockvet": {
"type": "stdio",
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"GITHUB_TOKEN",
"-e",
"GITLAB_TOKEN",
"-e",
"BITBUCKET_TOKEN",
"-e",
"GITEA_TOKEN",
"-e",
"AZURE_DEVOPS_TOKEN",
"ghcr.io/matteo-sung/lockvet:0.6.20",
"lockvet",
"mcp"
],
"env": {
"GITHUB_TOKEN": "<github-token>",
"GITLAB_TOKEN": "<gitlab-token>",
"BITBUCKET_TOKEN": "<bitbucket-token>",
"GITEA_TOKEN": "<gitea-token>",
"AZURE_DEVOPS_TOKEN": "<azure-devops-token>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"lockvet": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"GITHUB_TOKEN",
"-e",
"GITLAB_TOKEN",
"-e",
"BITBUCKET_TOKEN",
"-e",
"GITEA_TOKEN",
"-e",
"AZURE_DEVOPS_TOKEN",
"ghcr.io/matteo-sung/lockvet:0.6.20",
"lockvet",
"mcp"
],
"env": {
"GITHUB_TOKEN": "<github-token>",
"GITLAB_TOKEN": "<gitlab-token>",
"BITBUCKET_TOKEN": "<bitbucket-token>",
"GITEA_TOKEN": "<gitea-token>",
"AZURE_DEVOPS_TOKEN": "<azure-devops-token>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| GITHUB_TOKEN | — | yes | GitHub token — private repos and higher API rate limits for vet_url/queue |
| GITLAB_TOKEN | — | yes | GitLab token (read_api) — private projects and self-hosted instances |
| BITBUCKET_TOKEN | — | yes | Bitbucket Cloud access token or app password — private repos, workspace queue scans |
| GITEA_TOKEN | — | yes | Gitea/Forgejo/Codeberg token — private repos |
| AZURE_DEVOPS_TOKEN | — | yes | Azure DevOps PAT (Code: Read) — private projects |
Freshness
Active — last maintenance signal 23d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-09-17 · 23d ago · GitHub
Latest release
2026-09-15 · 24d ago · GitHub · v0.6.20
Package published
no data · npm/PyPI
Registry entry updated
2026-09-15 · 24d ago · official registry · v0.6.20
FAQ
›How do I install the lockvet MCP server in Claude Code?
Run: claude mcp add lockvet -e GITHUB_TOKEN='<github-token>' -e GITLAB_TOKEN='<gitlab-token>' -e BITBUCKET_TOKEN='<bitbucket-token>' -e GITEA_TOKEN='<gitea-token>' -e AZURE_DEVOPS_TOKEN='<azure-devops-token>' -- docker run -i --rm -e GITHUB_TOKEN -e GITLAB_TOKEN -e BITBUCKET_TOKEN -e GITEA_TOKEN -e AZURE_DEVOPS_TOKEN ghcr.io/matteo-sung/lockvet:0.6.20 lockvet mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does lockvet require an API key?
Yes. It expects GITHUB_TOKEN, GITLAB_TOKEN, BITBUCKET_TOKEN, GITEA_TOKEN, AZURE_DEVOPS_TOKEN, of which 5 are secrets.
›Can I use lockvet as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is lockvet in the official MCP registry?
Yes, as io.github.matteo-sung/lockvet.
Alternatives to lockvet
Other productivity & office MCP servers.