Skip to content

goklab/guardvibe

v2.9.2 Breaking

This release includes 3 breaking changes for platform teams planning a safe upgrade.

Published 1mo MCP Security & Auth
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

ai-security claude clerk cursor cve drizzle
+14 more
gemini-cli-extension hono mcp nextjs owasp prisma static-analysis security stripe supabase supply-chain typescript vercel vibe-coding

Summary

AI summary

Truncated scan_directory output to max 50 findings and removed fixCode for large projects.

Full changelog

v2.9.2 — MCP Output Truncation

Büyük projelerde scan_directory çıktısının Claude Code token limitini aşması sorununu düzeltti.

Problem

343K+ karakter çıktı → "exceeds maximum allowed tokens" hatası → tool sonucu tamamen kayboluyordu.

Çözüm

  • scan_directory JSON: Max 50 finding (severity sıralı), fixCode kaldırıldı
  • scan_directory Markdown: Max 30 detaylı finding, description ve fixCode kaldırıldı
  • check_project: Max 30 detaylı finding
  • compliance_report: Max 50 finding
  • Tüm truncated çıktılarda scan_file yönlendirmesi var

Özet (grade, score, severity count, top 5 action items) her zaman tam döner — sadece per-finding detay kısılıyor.

334 rules, 31 tools, 23 CVEs

Breaking Changes

  • `scan_directory` JSON now limited to max 50 findings (severity‑sorted) and removes `fixCode` field
  • `scan_directory` Markdown now limited to max 30 detailed findings and removes `description` and `fixCode` fields
  • `check_project` output limited to max 30 detailed findings

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track goklab/guardvibe

Get notified when new releases ship.

Sign up free

About goklab/guardvibe

Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.

All releases →

Beta — feedback welcome: [email protected]