
Security News
GitHub Actions Adds cache-mode to Limit Cache Poisoning Risk
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.
@helmdeck/mcp-bridge
Advanced tools
Stdio MCP bridge that connects Claude Code, Claude Desktop, OpenClaw, and Gemini CLI to a helmdeck control plane.
Stdio MCP bridge for helmdeck. Connects Claude Code, Claude Desktop, OpenClaw, and Gemini CLI to a helmdeck control plane via the Model Context Protocol.
# One-shot, no install
HELMDECK_URL=https://helmdeck.example HELMDECK_TOKEN=... npx @helmdeck/mcp-bridge
# Or install globally
npm install -g @helmdeck/mcp-bridge
helmdeck-mcp
The bridge reads two environment variables:
| Variable | Description |
|---|---|
HELMDECK_URL | Base URL of the helmdeck control plane (e.g. https://helmdeck.example) |
HELMDECK_TOKEN | Bearer JWT issued from the Management UI's API Tokens panel |
The control plane exposes ready-to-paste configuration snippets at
GET /api/v1/connect/{client} for each supported client. Example:
curl -H "Authorization: Bearer $HELMDECK_TOKEN" \
"$HELMDECK_URL/api/v1/connect/claude-code"
Supported clients: claude-code, claude-desktop, openclaw, gemini-cli.
postinstall downloads the platform-matching helmdeck-mcp binary
from the corresponding GitHub Release, verifies its SHA256 against
checksums.txt, and places it in bin/. Set
HELMDECK_MCP_SKIP_DOWNLOAD=1 to skip the download (useful in CI
images that bake the binary in another way).
Apache-2.0
FAQs
Stdio MCP bridge that connects Claude Code, Claude Desktop, OpenClaw, and Gemini CLI to a helmdeck control plane.
We found that @helmdeck/mcp-bridge demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.

Research
/Security News
A Twitch browser extension on Chrome and Firefox forwards users’ live OAuth session tokens through proxies controlled by a Russian bot service.