This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryVG964 now requires Next.js context and will not fire on plain Node.
Full changelog
init claudewrites.mcp.json(Claude Code v2.x project-scope filename)- VG964 (server-only) requires Next.js context — no longer fires on plain Node
- 4 rule false-positive fixes: VG138, VG148, VG061, VG030
Breaking Changes
- VG964 (server-only) requires Next.js context and no longer fires on plain Node
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Beta — feedback welcome: [email protected]