
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
@sonenta/mcp
Advanced tools
MCP server for Sonenta translation management — pure TypeScript, no Python. Wires Claude Desktop and other MCP clients into your project's keys, translations, accessibility, and source-health tools.
Model Context Protocol server for Sonenta translation management — pure TypeScript, no Python, no uv, no bundled wheel. Runs on Node ≥18.
Wires Claude Desktop and other MCP clients into your Sonenta project's keys, translations, accessibility surfaces, source-health, and glossary tools — plus agent-observability tools (session_start / annotate / human_needed / session_end) that surface an agent's run as a live, timestamped thread in the Sonenta dashboard, and prompt-library reads (list_prompts / resolve_prompt) so agents can discover and reuse the project's curated prompts. propose_translation(s) carry ICU/CLDR plural_forms, and plural_categories returns the plural categories a language requires (babel-authoritative).
The launcher sends agent-identity headers on every request — X-Agent-Name / X-Agent-Type / X-Agent-Version (from SONENTA_AGENT_NAME / SONENTA_AGENT_TYPE / SONENTA_AGENT_VERSION, all optional) — so the backend can auto-open a live observability session even for agents that never call session_start. X-MCP-Session-Id is a per-process run id before session_start (the backend opens then adopts a single coarse session on it), then the returned session id (echoed), reverting to the run id after session_end — so each subagent's captured mutations route to its own session and concurrent subagents stay distinct.
Auto-wired by sonenta init / sonenta agents add. Manual .mcp.json:
{
"mcpServers": {
"sonenta": {
"command": "npx",
"args": ["-y", "@sonenta/mcp"],
"env": { "SONENTA_API_KEY": "<mcp:* key>", "SONENTA_PROJECTS": "<uuid,…>" }
}
}
}
Env: SONENTA_API_KEY / SONENTA_BASE_URL (default https://api.sonenta.dev) / SONENTA_PROJECTS
(legacy VERBUMIA_* accepted). With no key set, the server reads ~/.sonenta/credentials (from sonenta login).
FAQs
MCP server for Sonenta translation management. Pure TypeScript, no Python. Wires Claude Desktop and other MCP clients into your project's keys, translations, accessibility, and source-health tools.
The npm package @sonenta/mcp receives a total of 266 weekly downloads. As such, @sonenta/mcp popularity was classified as not popular.
We found that @sonenta/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.