This release fixes issues for SREs watching stability and regressions.
✓ No known CVEs patched in this version
Topics
+14 more
Affected surfaces
Summary
AI summaryPrisma raw-query injection detection now ignores the safe tagged‑template form.
Full changelog
- VG432 Prisma raw-query injection: pattern only fires on the function-call form with raw backtick string (
$queryRaw(\...${x}...`)), which Prisma rejects at runtime. The tagged-template form ($queryRaw`...${x}``) is auto-parameterized per Prisma docs and no longer flagged.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Beta — feedback welcome: [email protected]