A Model Context Protocol (MCP) server that can help pin 3rd party dependencies to immutable digests. Supported dependency types include:
Run as a container with stdio
transport.
docker run -it --rm ghcr.io/safedep/pinner-mcp:latest
Add the following to your .cursor/mcp.json
file. You must enable the MCP server in the settings. Learn more here.
{ "mcpServers": { "pinner-mcp-stdio-server": { "command": "docker", "args": [ "run", "--rm", "-i", "ghcr.io/safedep/pinner-mcp:latest" ] } } }
Use a Composer prompt like the following to pin a specific commit hash.
Pin GitHub Actions to their commit hash
Pin container base images to digests
To update pinned versions, you can use a prompt like the following.
Update pinned versions of container base images
Updates for the MCP server are automatically pushed to the latest
tag on GitHub Container Registry. You must manually update your local container image to the latest version.
docker pull ghcr.io/safedep/pinner-mcp:latest
RetroSearch is an open source project built by @garambo | Open a GitHub Issue
Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo
HTML:
3.2
| Encoding:
UTF-8
| Version:
0.7.4