Skip to content

goklab/guardvibe

v3.26.0 Breaking

This release includes breaking changes for platform teams planning a safe upgrade.

Published 1mo MCP Security & Auth
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

ai-security claude clerk cursor cve drizzle
+14 more
hono mcp mcp-server nextjs owasp prisma prompt-injection static-analysis security stripe supabase typescript vercel vibe-coding

Affected surfaces

auth rbac

Summary

AI summary

AST engine adds inter-procedural and nested-relation ownership detection for BOLA/IDOR.

Full changelog

AST engine: inter-procedural and nested-relation ownership detection for VG950/VG951 (BOLA/IDOR). Catches authorization checks performed in a helper the function calls, and ownership fields nested inside relation filters — shapes the same-function analysis could not see. Only session-derived ownership values count; request-controlled values keep firing. 3 corpus false positives removed, zero true positives lost, zero drift. Deterministic (bundled TypeScript parser). 450 rules / 39 tools.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track goklab/guardvibe

Get notified when new releases ship.

Sign up free

About goklab/guardvibe

Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.

All releases →

Related context

Beta — feedback welcome: [email protected]