Versions-LE
io.github.nolindnaidoov1.0.0更新於 Oct 4, 2026
Find where one dependency is constrained differently across a repository's manifests.
概覽
讓助理比較倉庫各清單檔案中的相依性約束,並回報版本衝突或無法同時滿足的情況。
- 功能
- 提供 compare_versions 工具,接收清單檔案的路徑與內容參數並回傳結構化報告。它檢查 package.json、Cargo.toml、pyproject.toml、go.mod 與 GitHub 工作流檔案,找出互斥約束、需求衝突、MSRV 不符、預發布版本固定與浮動固定。它從不修改清單、不解析相依性圖、不發出網路請求;未建模的約束會列為拒絕項並排除在比較之外。
- 適用情境
- 適用於 monorepo 或多清單專案:排查建置無法解析的原因、審查相依性升級,或核對 CI 工具鏈固定版本是否與宣告的最低版本一致。適合需要機器可讀漂移報告、而非人工比對清單的助理。
- 執行需求
- 透過 npx versions-le-mcp 以 stdio 在本機執行(需要 Node.js),也可用 npm 全域安裝。無需環境變數、API 金鑰或額外設定。此工具本身不讀取檔案,清單內容由參數傳入。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Versions-LE,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
Versions-LE: Two Pins, One Dependency
Find where one dependency is constrained differently across a repository's manifests — and where no version can satisfy both
package.json · Cargo.toml · pyproject.toml · go.mod · GitHub workflows
[Install from VS Code Marketplace] [Open VSX downloads] [versions-le-mcp on npm] [versions-le on crates.io] [LE Tools]
Useful? A star or rating is how other developers find it — ★ GitHub · ★ Open VSX · ★ Marketplace
What it does
The build broke because api asks for regex = "1" and web asks for regex = "2", and no one version satisfies both. Or it did not break, and will: CI has built on Rust 1.80 since March while rust-version says 1.88.
Press Ctrl+Alt+V (Cmd+Alt+V on Mac) and every manifest in the workspace is compared as one set — or every manifest under a folder, from the Explorer. The report opens beside the editor: each problem by severity with every file, key and constraint that produced it, then what was deliberately not compared and why. Works in VS Code and in VS Code–based editors like Cursor and VSCodium (installable from Open VSX).
- In a monorepo — the crate pinned to
serde 0.9while the rest moved to1.0 - Before a release — CI testing on a toolchain older than the minimum you publish
- Reviewing a dependency bump — the one package that did not move with the others
It never edits a manifest, and never guesses: a constraint it does not model is named and left out of every comparison.
Install
The six checks
Different and unsatisfiable are two findings. constraint-conflict
is a smell; disjoint-constraint is a build that cannot resolve. They
are never conflated.
Disjointness is decided by interval arithmetic over the modelled
ranges, not by string comparison — which is also why >=20 and
>=20.0.0 are not reported as a conflict. They are one requirement typed
twice.
One finding per drifted dependency, carrying every site. A dependency constrained four ways is one problem with four sites, and four findings would read as four problems.
The four refusals
It never guesses. A constraint in a grammar this tool does not model
is named in the report's refusals and takes part in no comparison —
never approximated into a range.
malformed-constraint is a finding, not a refusal, and the
difference is deliberate: it is the narrower verdict that the value is
shaped like a constraint of its own ecosystem and is broken. The tool
blames the manifest only when it is sure; everything else it blames on
itself. ^^1.0.0 is malformed. latest is not — it is a syntax with a
meaning this tool chose not to model.
Comparison never crosses an ecosystem. An npm semver and a Cargo
semver are unrelated packages that share a word — and a bare
"1.0.200" means exactly 1.0.200 in npm and anything below 2.0.0 in
Cargo. One bridge exists, msrv-mismatch, and it is built by naming both
keys rather than by matching a name.
What it reads
That last row is why this exists as much as the first: a CI toolchain drifting away from the floor a manifest declares is exactly the failure nobody notices until a release.
node_modules, vendor and .git are never read. .github always
is — a workflow lives in a hidden directory by definition.
What it will not do
- It never edits a manifest. No
--fix, no--pin, no--update. The right version for a drifted dependency is a decision, not a derivation. - It never resolves a dependency graph. It reads what the manifests say, not what a resolver would pick — no lockfiles, no transitive analysis.
- It never hits the network. It does not know which versions exist, which are yanked, or which are newest; only whether two stated requirements can be met at once.
- It does not lint style. Ordering, quoting and formatting of a manifest are somebody else's job.
Use it from an AI agent
The same engine runs as an MCP server, so an agent can call it directly instead of diffing manifests by eye.
It returns the report the editor renders, as data — findings capped at 500 by default with meta.truncated. It reads no files and makes no network requests. Published as versions-le-mcp on npm and as io.github.nolindnaidoo/versions-le in the MCP registry. It answers exactly as the Rust CLI's server does: one corpus runs against both, and a differential test feeds both thousands of generated manifest sets — broken JSON and TOML included — and compares every answer.
Configuring it by hand — any host with an MCP config file
Or install it once with npm install -g versions-le-mcp and point at versions-le-mcp. It needs no environment variables, no API key and no configuration of its own. To check it:
The CLI
The same comparison runs over a tree from a terminal or a CI step: a Rust CLI in crate/, sharing one corpus with the extension — crate/fixtures/ — so the two can never read a constraint differently.
The exit code is the product — 0 nothing above info, 1 findings, 2 the question was malformed. No manifests at all is 0: nothing can conflict with nothing.
Commands
Settings
Languages
Twelve languages besides English:
German · Spanish · French · Indonesian · Italian · Japanese · Korean · Portuguese (Brazil) · Russian · Ukrainian · Vietnamese · Chinese (Simplified)
Both halves are covered — the manifest (command titles, setting names and descriptions) and everything shown while the extension runs (notifications, the status bar and the report's headings). A finding's message is the engine's English, identical to the CLI's.
Privacy & security
- No network access. The extension never sends data anywhere; it does not know which versions exist, only whether two stated requirements can be met at once. The
telemetryEnabledsetting only writes events to a local Output Channel you can inspect (Versions-LE). - It reads manifests and nothing else, and never writes to one.
- The MCP server holds the same line. It takes content as an argument and returns data: no filesystem access, no network calls, no telemetry.
- Error notifications redact home directories and credential-shaped fragments.
Documentation
Performance
Median of 7 runs after warmup, on Apple M5 Pro, 24 GB RAM, Node 24.3.0. Inputs are generated
by scripts/benchmark.ts rather than checked in, so the sizes above are
exactly what was measured. Reproduce with bun run benchmark.
These are machine-specific and are not asserted in CI — a benchmark that gates a build only tells you how busy the runner was.
Testing
265 test cases across 13 files, plus an integration suite that runs
in a real VS Code extension host and an end-to-end test that installs the
built .vsix into a clean profile.
Generated from a real run — coverage/coverage-summary.json and
coverage/test-results.json — by scripts/coverage-readme.js; CI fails if
this section drifts. Reproduce with bun run test:coverage, and the case
count is the one vitest prints.
More from the LE family
Sixteen single-purpose tools for the work in front of every model. Each ships a Rust CLI and an MCP server. One page: letools.dev
Get it out
- String-LE — Extract every string in a codebase, with its position, so a person can read them
- Numbers-LE — Extract every hardcoded number in a codebase, so a person can check them
- Units-LE — Extract every quantity with its unit, normalized, and refuse the ambiguous ones by name
- Dates-LE — Extract every date and timestamp, and the exact instant each one resolves to
- IDs-LE — Extract every UUID, ULID, NanoID, ObjectId and Snowflake, and decode the time inside
- IPs-LE — Extract every IP address, CIDR block and MAC, normalized and classified by scope
- URLs-LE — Extract every URL in a codebase, with its protocol and exact position
- Paths-LE — Extract every file path in a codebase, and say whether it still points at anything
- Colors-LE — Extract every color in a codebase, and say which ones are not in your palette
Check it
- Regex-LE — Find every regex in a codebase, and report which can be driven into catastrophic backtracking
- Versions-LE — Find where one dependency is constrained differently across a repository's manifests
- i18n-LE — Identify the i18n library a project uses, then audit its catalogs by that library's rules
- Scrape-LE — Check whether a page is scrapeable before the scraper is written, and say when it cannot tell
Guard it
- Secrets-LE — Find hardcoded credentials in a codebase, and never print one into the report
- EnvSync-LE — Compare the dotenv files in a tree, and say which keys are missing from which
- Unicode-LE — Find the Unicode that hides meaning — bidi controls, invisibles, homoglyphs, mixed scripts
Each stands on its own: no shared crate, no published core. Where two of them agree, it is because the same answer was right twice.
Contact — nolindnaidoo.com · GitHub · LinkedIn
Also by nolindnaidoo
Rust — pixelcoords and pixelactions are one loop: pixelcoords answers where, pixelactions acts there. Their own tools, their own voice — not part of the LE family.
- pixelcoords — Freeze your screen, mark regions, get pixel-exact coordinates and crops pixelcoords.dev · crates.io · docs.rs
- pixelactions — Consume human-verified coordinates, perform the interaction, confirm it landed pixelactions.dev · crates.io · docs.rs
License
MIT © nolindnaidoo
來源:README.md,提交 2e95d72
工具
0版本歷史
1- v1.0.0最新Oct 4, 2026

