This release fixes issues for SREs watching stability and regressions.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryTest files no longer trigger VG010, VG011, VG013, VG014, VG042, and VG678 rules.
Full changelog
Extended test-file rule skip list. VG010 (SQL injection), VG011 (cmd injection), VG013 (NoSQL), VG014 (eval), VG042 (security headers), and VG678 (X-Content-Type-Options) no longer fire in test files (.spec.ts, /tests/, tests, /cypress/, /playwright/). API test specs were generating ~96 FPs per repo from payload strings like agent.get('/?q=' + sqlPayload) that match injection regexes without being database calls. juice-shop dropped 360→262.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Beta — feedback welcome: [email protected]