SARIF explained: why linters speak it, and how mcpscore 1.14.0 writes it
What SARIF is, why a linter should emit it, and how mcpscore 1.14.0 turns MCP audit findings into GitHub code scanning alerts with one flag and one Action input.
Read articleBlog
Release notes, migration guidance, and what we learn from scoring MCP servers in the wild.
Subscribe via RSSWhat SARIF is, why a linter should emit it, and how mcpscore 1.14.0 turns MCP audit findings into GitHub code scanning alerts with one flag and one Action input.
Read articleCompare WebMCP and MCP: page tools vs server integrations, shared schemas, browser support, permissions, and when to use each.
Read articleTurn rules off and re-rank the rest with a mcpscore.toml, gate CI on severity, and keep the badge canonical. Per-project rule configuration in mcpscore 1.12.0.
Read articleSmoke-test real MCP tool calls after every change with mcpscore 1.11.0, while keeping invocation opt-in, deterministic, and separate from the quality score.
Read articleCompare mcpscore with official MCP conformance tests, Inspector v2, and security scanners—and learn which MCP testing tool to use for each job.
Read articleRun the same deterministic MCP audit against Go, Java, C#, Rust, or any other local stdio server, with secret-safe environment configuration.
Read articleThe new MCP release changes the protocol lifecycle, transport, caching, and schemas. See what changed and use mcpscore to find migration gaps.
Read articleAfter five months of building through 0.x, our first stable release brings 52-rule MCP server audits to the CLI, CI, and the web.
Read article