
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@galaxy-stack/nebula-mcp
Advanced tools
Nebula MCP Server — exposes Galaxy UI components to AI assistants through the Model Context Protocol. Works with Claude Desktop, Cursor, Windsurf, Cline, and any MCP-compatible client.
| Tool | Description |
|---|---|
list_components | All components with per-framework availability (React, Vue, Angular, React Native, Flutter) |
get_component | Detailed manifest — props, files, dependencies, framework status |
get_component_source | Actual source code for a specific component file |
get_coverage | Coverage matrix across all 5 frameworks (67 components) |
search_components | Search by name or description |
All component data + 700 source files are bundled inside the package — zero setup, works offline.
npx -y @smithery/cli@latest install galaxy-stack/design-mcp --client claude
Add to your MCP client config:
{
"mcpServers": {
"galaxy-ui": {
"command": "npx",
"args": ["-y", "@galaxy-stack/nebula-mcp"]
}
}
}
~/Library/Application Support/Claude/claude_desktop_config.json~/.cursor/mcp.jsonPaste into clients that support remote MCP (Claude web Custom Connectors):
https://nebula-mcp--galaxy-stack.run.tools
"List Galaxy UI components for React"
"Show me the source code of the Vue Select component"
"Which components are missing in Flutter?"
Bump version in package.json
Push to main — GitHub Actions workflow publish-mcp.yml builds contracts artifacts, bundles data, verifies the version is new, and publishes via npm Trusted Publishing (OIDC) — no NPM_TOKEN required
Rebuild the MCPB bundle and run smithery mcp publish for Smithery
Publish to the Official MCP Registry (org namespace requires a PAT — device-flow login cannot read org roles, see registry#1468):
# PAT needs read:org scope (classic) or Organization → Members → Read-only (fine-grained)
mcp-publisher login github --token <YOUR_PAT> # requires mcp-publisher >= 1.8.1
mcp-publisher validate
mcp-publisher publish # → io.github.galaxy-nebula/nebula-mcp
FAQs
MCP server exposing Galaxy Nebula components for AI assistants.
The npm package @galaxy-stack/nebula-mcp receives a total of 270 weekly downloads. As such, @galaxy-stack/nebula-mcp popularity was classified as not popular.
We found that @galaxy-stack/nebula-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.