This release keeps dependencies and maintenance posture current for teams operating this tool.
✓ No known CVEs patched in this version
Topics
+11 more
Summary
AI summaryMinor fixes and improvements.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Disables remote-capable Git commands. Disables remote-capable Git commands. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Disables external Git command execution. Disables external Git command execution. Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Feature | Low |
Disables shell alias usage. Disables shell alias usage. Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
Full changelog
Avibe-managed local-only Git runtime built from the pinned upstream source tarball.
Remote-capable commands, external Git commands, and shell aliases are disabled.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Avibe
All releases →Related context
Related tools
Earlier breaking changes
- v3.0.5 Removed protected Vault password factor path; now Passkey‑only for setup/unlock.
- v3.0.5 Changed `vibe agent run --session-id` to target existing sessions and reject mutation flags.
- v3.0.5 Replaced `vibe vault request --skill` with JSON spec via `--spec`/`--spec-json`.
- v3.0.5 Removed `vibe vault set`; Vault creation now requires browser‑side sealing instead of plaintext values.
Beta — feedback welcome: [email protected]