This release fixes issues for SREs watching stability and regressions.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryTaint walker now skips additional build directories, reducing false XSS findings.
Full changelog
- 4 yeni file-level FP narrow (writernext_v2 41→4): VG956/VG1004 per-route Next.js App Router rate-limiter pattern'lerini de tanıyor; VG1010 zod/joi/yup schema validation kullanan Server Action'larda atlıyor; VG601 Svix-style
verifyPolarWebhook/verifyWebhookSignatureçağrılarını tanıyor (verify-then-parse sırasını da kapsayan file-level kontrol) - Suppression chain'i artık çoklu satır açıklama yorumları ve peş peşe
guardvibe-ignoredirektifleri ile kırılmıyor - Taint walker:
.vercel,.output,.astro,.svelte-kit,.nuxt,.cachedizinleri de atlanıyor (build artifact'ları üzerinde TAINT:xss bulguları üretiyordu)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Beta — feedback welcome: [email protected]