This release keeps dependencies and maintenance posture current for teams operating this tool.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryMinor fixes and improvements.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Refactor | Low |
Publish workflow made idempotent to handle transient registry outages Publish workflow made idempotent to handle transient registry outages Source: llm_adapter@2026-06-08 Confidence: high |
— |
Full changelog
- Re-sync: v3.14.0 published to npm but the MCP registry hit a transient 504; this re-publishes so npm and the registry match
- Hardened the publish workflow: npm publish is now idempotent, so a transient registry outage can be retried without a duplicate-publish failure
- No rule, tool, or behavior changes (442 / 37); gate green (PASS/A/0)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Related tools
Beta — feedback welcome: [email protected]