This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryScanner now recognizes remediation patterns and stops producing false positives for fixed files.
Full changelog
v2.9.4 — Fix-Aware Scanning
Problem
Güvenlik düzeltmeleri uygulandıktan sonra skor düşüyordu — scanner düzeltmeleri tanımıyordu.
Çözüm
Scanner artık remediation pattern'larını tanıyor ve düzeltilmiş dosyalarda false positive üretmiyor:
| Düzeltme Pattern'ı | Skip Edilen Kurallar |
|----|-----|
| DOMPurify.sanitize() / sanitizeHtml() | VG408, VG012, VG042 |
| URL validation / allowlist pattern | VG120 |
| crypto.randomUUID() / nanoid() | VG993 |
| Custom cron verification function | VG968, VG503 |
| Migration/seed directories | VG439 |
| peerDependencies (version ranges) | VG903 |
| 40+ legitimate npm packages (fast-glob, safe-array-concat, etc.) | VG872, VG873 |
Etki
Düzeltme yapıldıktan sonra skor artık doğru yönde hareket eder — düşmez.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Beta — feedback welcome: [email protected]