This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryThreat intel now prioritizes CISA Known-Exploited-Vulnerabilities and scaffolds draft rules for uncovered advisories.
Full changelog
- npm run intel --scaffold now drafts a ready-to-review rule + version-range test for each uncovered advisory (printed only; never auto-committed)
- Threat intel cross-references the CISA Known-Exploited-Vulnerabilities catalog and surfaces actively-exploited CVEs first
- New tested semver-range to 0-FP-regex generator; no rule or tool changes (441 / 37); gate green (PASS/A/0)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Related tools
Beta — feedback welcome: [email protected]