This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryNew test repository ai-chatbot added using Vercel AI SDK, Drizzle, and Next.js.
Full changelog
- VG850 (AI Prompt Injection): skip when system-prompt template literal interpolates only constant identifiers (e.g.
${codePrompt}). Still fires onreq/body/paramsand bareuserInput/userMessage/userPrompt. - VG999 (AI maxTokens): skip when call uses structured output (
output: Output.array(...)/Output.object(...)) — token usage is bounded by schema. - VG1027 (Messages serialized to client): skip when surrounding code uses a filter helper (
convertToUIMessages,filterMessages,pickRole,sanitizeMessages). - ai-chatbot onboarded as new test repo (Vercel AI SDK + Drizzle + Next.js).
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Beta — feedback welcome: [email protected]