
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
@ravendb/mcp
Advanced tools
Read-only MCP diagnostics server for RavenDB. Run it with npx; no .NET required.
A local, read-only MCP diagnostics server for RavenDB.
No .NET required. Run it with npx (Node.js 18+).
{
"command": "npx",
"args": ["-y", "@ravendb/mcp"],
"env": { "RAVENDB_URLS": "http://localhost:8080" }
}
Or with Claude Code:
claude mcp add ravendb --scope user --env RAVENDB_URLS=http://localhost:8080 -- npx -y @ravendb/mcp
RAVENDB_URLS is required: comma-separated node URLs of a single cluster. For secured (HTTPS)
clusters, client certificates, the --config file, and the full configuration reference, see
INSTALL.md.
Windows (x64, arm64), macOS (x64, arm64), Linux (x64).
FAQs
Read-only MCP diagnostics server for RavenDB. Run it with npx; no .NET required.
The npm package @ravendb/mcp receives a total of 47 weekly downloads. As such, @ravendb/mcp popularity was classified as not popular.
We found that @ravendb/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.