
Security News
Open VSX Begins Implementing Pre-Publish Security Checks After Repeated Supply Chain Incidents
Following multiple malicious extension incidents, Open VSX outlines new safeguards designed to catch risky uploads earlier.
@codacy/codacy-mcp
Advanced tools
MCP Server for the Codacy API, enabling access to repositories, files, quality, coverage, security and more.
The following tools are available through the Codacy MCP Server:
codacy_list_repositories: List repositories in an organization with pagination support.codacy_list_repository_issues: Lists and filters code quality issues in a repository. This is the primary tool for investigating general code quality concerns (e.g. best practices, performance, complexity, style) but NOT security issues. For security-related issues, use the SRM items tool instead. Features include:
Common use cases:
codacy_list_files: List files in a repository with pagination support.codacy_get_file_issues: Get the issue list for a file in a repository.codacy_get_file_coverage: Get coverage information for a file in the head commit of a repository branch.codacy_list_srm_items: Primary tool to list security items/issues/vulnerabilities/findings. Results are related to the organization security and risk management (SRM) dashboard on Codacy. Provides comprehensive security analysis including:
codacy_list_repository_pull_requests: List pull requests from a repository that the user has access to. You can search this endpoint for either last-updated (default), impact or merged.codacy_list_pull_request_issues: Returns a list of issues found in a pull request. We can request either new or fixed issues.codacy_get_repository_pull_request_files_coverage: Get coverage information for all files in a pull request.codacy_get_pull_request_git_diff: Returns the human-readable Git diff of a pull request.For detailed information about the parameters and filtering options available for each tool, please refer to the Available Codacy API Actions section below.
Get your Codacy's Account API Token from your Codacy Account.
Depending on what are you connecting the MCP Server to, you can use the following methods:
.cursor/mcp.json file to add the followingclaude_desktop_config.json file to add the following{
"mcpServers": {
"codacy": {
"command": "npx",
"args": ["-y", "@codacy/codacy-mcp"],
"env": {
"CODACY_ACCOUNT_TOKEN": "<YOUR_TOKEN>"
}
}
}
}
When using NVM with Claude Desktop, NPX won't work. You should first install the MCP Server globally, and thenuse Node directly:
npm install -g @codacy/codacy-mcp
{
"mcpServers": {
"codacy": {
"command": "/Users/yourusername/.nvm/versions/node/vXX.X.X/bin/node",
"args": ["/path-to/codacy-mcp/dist/index.js"],
"env": {
"CODACY_ACCOUNT_TOKEN": "<YOUR_TOKEN>"
}
}
}
}
Local:
npm install
npm run update-api
npm run build
This MCP server is licensed under the MIT License. This means you are free to use, modify, and distribute the software, subject to the terms and conditions of the MIT License. For more details, please see the LICENSE file in the project repository.
FAQs
Codacy MCP server
The npm package @codacy/codacy-mcp receives a total of 1,945 weekly downloads. As such, @codacy/codacy-mcp popularity was classified as popular.
We found that @codacy/codacy-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Following multiple malicious extension incidents, Open VSX outlines new safeguards designed to catch risky uploads earlier.

Research
/Security News
Threat actors compromised four oorzc Open VSX extensions with more than 22,000 downloads, pushing malicious versions that install a staged loader, evade Russian-locale systems, pull C2 from Solana memos, and steal macOS credentials and wallets.

Security News
Lodash 4.17.23 marks a security reset, with maintainers rebuilding governance and infrastructure to support long-term, sustainable maintenance.