This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summarysecure_this now returns a runnable proofTest regression test.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
secure_this now returns a proofTest when it applies fixes secure_this now returns a proofTest when it applies fixes Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Low |
CLI displays the generated proofTest and --emit-proof writes it to <file>.guardvibe.test.ts by default CLI displays the generated proofTest and --emit-proof writes it to <file>.guardvibe.test.ts by default Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Feature | Low |
MCP returns the proofTest so agents can add it as a CI regression guard MCP returns the proofTest so agents can add it as a CI regression guard Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
Full changelog
- secure_this now returns a proofTest when it applies fixes: a runnable regression test that fails on the vulnerable code and passes on the fixed code (GuardVibe-as-oracle, an honest scan-based proof, not an exploit test)
- CLI shows it and --emit-proof writes it (default .guardvibe.test.ts); MCP returns it so agents can drop it into the suite as a CI regression guard
- No rule or tool changes (441 / 37); gate green (PASS/A/0)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Related tools
Beta — feedback welcome: [email protected]