Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

skillspector-mcp-2.9.6-1.1 RPM for noarch

From OpenSuSE Tumbleweed for noarch

Name: skillspector-mcp Distribution: openSUSE Tumbleweed
Version: 2.9.6 Vendor: openSUSE
Release: 1.1 Build date: Thu Aug 20 20:46:27 2026
Group: Unspecified Build host: reproducible
Size: 0 Source RPM: skillspector-2.9.6-1.1.src.rpm
Packager: https://bugs.opensuse.org
Url: https://github.com/NVIDIA/skillspector
Summary: MCP server mode for SkillSpector
This subpackage enables the Model Context Protocol (MCP) server mode of
SkillSpector, exposed through the "skillspector mcp" subcommand. It pulls
in the optional MCP runtime dependency so the FastMCP-based server can be
started for local CLI agents or over HTTP.

Provides

Requires

License

Apache-2.0

Changelog

* Thu Aug 20 2026 Martin Pluskal <mpluskal@suse.com>
  - Update to version 2.9.6:
    * MCP registry posture scanning
    * Ollama, Azure OpenAI, and generic OpenAI-compatible providers
    * Opt-in discovery of an author-shipped baseline
      (.skillspector-baseline.yaml)
    * Detect insecure deserialization (AST10, TT6, DS1-DS4)
    * Detect whitespace-padding prompt injection (P9)
    * HIGH SC8 when a skill ships __pycache__ or .pyc
    * Bound URL, zip and git ingest to limit resource exhaustion
    * SC4 reports only verified OSV hits; use lockfile versions
    * HTTP MCP rejects local filesystem targets and local YARA dirs
    * Reject symlink traversal in skill content; disable git
      symlinks on clone
    * PE3 no longer flags ordinary OAuth "access token"
      documentation
    * LLM analyzers retry or isolate malformed responses and
      connection failures; incomplete analysis is recorded as
      skipped
    * Reduce false positives (instructional prose, Markdown
      tables, JS RegExp.exec, negated safety constraints, OMS
      signatures)
    * Map YARA matches via byte offsets; scope the locality guard
      to the built-in rule namespace
  - Switch source to the official GitHub release tarball
  - Drop _service, skillspector-2.5.1.obscpio and
    skillspector.obsinfo
  - Add packaging >= 24.0 (requirement parsing for OSV lookups)
* Tue Aug 04 2026 Martin Pluskal <mpluskal@suse.com>
  - Update to version 2.5.1 (first tagged releases; switches the package
    from a pinned git snapshot to the upstream release tags):
    * Canonical inspection-ledger reporting: JSON and SARIF reports now
      carry execution-completeness and analyzer status, so a consumer
      can distinguish a clean zero-finding scan from one that did not
      execute reliably
    * SKILLSPECTOR_MAX_LLM_CONCURRENCY serializes or bounds asynchronous
      LLM analyzer batches for rate-limited providers
    * Read exact versions from Python lockfiles for OSV lookups
    * Exclude valid OMS signatures from content analysis
  - Ship the wheel metadata under the release version again: upstream's
    pyproject version now matches the tag, so the dist-info glob follows
    the package version
* Fri Jul 03 2026 Martin Pluskal <mpluskal@suse.com>
  - Relax over-strict dependency floors set by upstream at initial
    release (pin-inflation, not API requirements; the code only uses
    long-stable APIs of all three):
    * pydantic >= 2.12.0 -> 2.11.7
    * rich >= 14.3.0 -> 14.0.0
    * typer >= 0.23.0 -> 0.16.0
  - Verified against Leap 16.0's shipped versions (pydantic 2.11.7,
    rich 14.0.0, typer 0.16.0, click 8.2.1, Python 3.13): full
    offline unit suite passes (1249 passed, 12 skipped, 6 xfailed)
    and the CLI entry point works.
* Wed Jul 01 2026 Martin Pluskal <mpluskal@suse.com>
  - Switch source acquisition to an obs_scm git snapshot of upstream
    main: NVIDIA/skillspector publishes no git tags, no GitHub releases
    and nothing on PyPI, so no downloadable release tarball exists
  - Version changed from 2.3.10 (a locally-built sdist that exists
    nowhere upstream) to the snapshot 2.3.9~git20260701.326a2b48
    (upstream main HEAD, commit 326a2b48)
  - Add _service; drop the hand-built skillspector-2.3.10.tar.gz
* Mon Jun 29 2026 Martin Pluskal <mpluskal@suse.com>
  - Use %{primary_python} instead of a hardwired python flavor
* Sun Jun 28 2026 Martin Pluskal <mpluskal@suse.com>
  - Initial package skillspector 2.3.10 (CLI scanner; -mcp subpackage
    for the MCP server)
  - Enable the pytest test suite now that the full langchain/langgraph
    runtime stack is packaged; the offline unit tests run at build time
    (integration/provider markers and four SSRF allowed-host tests that
    require live DNS are deselected)

Files

No Filelist in the Package !

Generated by rpm2html 1.8.1

Fabrice Bellet, Sun Aug 23 00:03:09 2026