This release fixes issues for SREs watching stability and regressions.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryFixed re-init upgrade flow so npx guardvibe init correctly updates .mcp.json when versions differ.
Full changelog
- Re-init upgrade flow fixed:
npx guardvibe init <host>was a no-op when GuardVibe was already configured — broke the documented upgrade path. Now reads the existing pinned version, compares against the running version, and rewrites the .mcp.json entry when they differ - README fix:
init claudecreates.mcp.json(was incorrectly documented as.claude.json); CLI section gainsdeep-scanexample block - Tests 1465/1465. Self-audit PASS / A / 100
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Beta — feedback welcome: [email protected]