This release fixes issues for SREs watching stability and regressions.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryScan behavior now distinguishes deployed runtime from static analysis, avoiding false‑positive enabled status for capability layers.
Full changelog
合规工具最不能做的事,是给用户虚假的安心。
变更
- 体检区分「已部署运行时」与「静态扫描」两种上下文
npx shellward scan(未部署 ShellWard 运行时)下,能力层 / 审计类控制项不再判为 ✅"已启用",改为 ⚪「运行时可提供,静态扫描无法验证」- 只对可静态观测的项(境外端点/依赖、是否 root)如实评分;得分基于真实证据
- MCP / 插件上下文(ShellWard 实际在运行)保持如实评估
全套 262 测试通过。
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About jnMetaCode/shellward
AI Agent Security Middleware & MCP Server with 8-layer defense including prompt injection detection, DLP data flow tracking, command blocking, and PII detection. 7 MCP tools, zero dependencies.
Related context
Related tools
Beta — feedback welcome: [email protected]