This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Affected surfaces
Summary
AI summaryDependency scan now annotates each vulnerable package with reachability information.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Dependency scan now annotates each package with reachability status. Dependency scan now annotates each package with reachability status. Source: llm_adapter@2026-06-07 Confidence: high |
— |
| Feature | Low |
Reachability labels are shown as true/false without suppressing findings. Reachability labels are shown as true/false without suppressing findings. Source: granite4.1:30b@2026-06-07-audit Confidence: low |
— |
| Bugfix | Medium |
Transitive and dynamic imports remain visible in reachability annotations. Transitive and dynamic imports remain visible in reachability annotations. Source: granite4.1:30b@2026-06-07-audit Confidence: low |
— |
Full changelog
- Dependency scan now annotates each vulnerable package with reachability: is it actually imported in your source? Turns daily CVE intel into a prioritized signal — a flagged dependency you never import drops down the list
- Annotate, never suppress: findings are labeled reachable true/false but nothing is dropped (transitive/dynamic use stays visible), so no new false negatives
- Surfaced in scan_dependencies and the audit dependency section; no rule or tool changes (438 / 37); gate green (PASS/A/0)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Related tools
Beta — feedback welcome: [email protected]