This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Affected surfaces
Summary
AI summaryVG106 timing‑unsafe secret comparison handling extended to all string/template literals.
Full changelog
- VG106 (timing-unsafe secret comparison): existing string-literal skip only matched empty literals; extended to cover any string/template literal so
typeof x === "object"and=== "string"checks no longer fire - VG106 also skipped in React client components — comparisons that run in the user's own browser are not exposed to remote timing attacks
- VG001/VG062 (hardcoded credential): added canonical-form name=value match (covers
IncorrectEmailPassword = "incorrect-email-password"and HTTP-header constants likeX_CAL_SECRET_KEY = "x-cal-secret-key") plus seed/scripts/fixtures path skip
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Beta — feedback welcome: [email protected]