This release fixes issues for SREs watching stability and regressions.
✓ No known CVEs patched in this version
Topics
+14 more
Affected surfaces
Summary
AI summaryFixed false positive VG002 when detecting auth guards and added support for express‑style middleware patterns.
Full changelog
VG002 false positive on requireAuth fixed (word boundary). hasAuthGuardPattern now recognizes express-style middleware (function requireAuth(req,res,next), inline middleware in route registration). Skip VG863 for non-publishable apps signaled by start script + no publishing fields.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Beta — feedback welcome: [email protected]