Skip to content
2,212 tools tracked · 52,482+ releases indexed

Security release intelligence for the open-source you actually depend on

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

AI Summaries

What changed and which changes matter for your security posture — in 10 seconds.

Critical Fix Alerts

When a critical CVE fix ships for a tool you track, you find out the same day — including downstream dependency exposure.

Supply-Chain Visibility

SBOM-derived transitive CVE exposure, per-tool security pages, and shared-risk clusters across the catalog. See the supply-chain map →

Breaking This Week

High-severity changes from the past 7 days

View all →

Latest Releases

Showing recent releases across all tools — sign in to see releases for your stack.

View full feed →
casibase · v2.42.1 → v2.42.2 · 2 releases · bugfix

Combined changes across v2.42.1 → v2.42.2 (2 releases)

Upgrade now
freescout 1.8.225 Security relevant
Auth RCE / SSRF Dependencies

Path traversal fix + CVE patches

deepagents · vlangchain-quickjs==0.2.0 → vlangchain-vercel-sandbox==0.0.1 · 2 releases · breaking

Combined changes across langchain-quickjs==0.2.0 → langchain-vercel-sandbox==0.0.1 (2 releases)

BREAKING CHANGES

  • Removed `skills_backend` module.
  • Added default `subagent` bridge (observable change in runtime configuration).

NOTABLE FEATURES

  • Add Vercel Sandbox provider

Browse by Category

Find tools for your workflow

Most-tracked tools this week

View all →

Explore Feeds

Subscribe by topic — track all tools at once

Browse all →

Community Lists

Curated collections from the community

View all →

AI-POWERED · WEEKLY

Weekly Supply Chain Security Brief

Breaking changes, security patches, and CVEs — curated weekly for your stack.

Beta — feedback welcome: [email protected]