This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Summary
AI summarySecurity hardening of ClawHub trust transparency was applied.
Full changelog
What's Changed
- fix: ClawHub trust + fail-loud registry publish by @msaad00 in https://github.com/msaad00/agent-bom/pull/212
- feat: cloud security skills + CSPM benchmark guides by @msaad00 in https://github.com/msaad00/agent-bom/pull/213
- fix: Glama license detection + cloud security skill feedback loop by @msaad00 in https://github.com/msaad00/agent-bom/pull/214
- fix: redesign modes diagram + correct cloud-security-audit architecture by @msaad00 in https://github.com/msaad00/agent-bom/pull/215
- fix: bump Dockerfile.snowpark version 0.54.0 → 0.57.0 by @msaad00 in https://github.com/msaad00/agent-bom/pull/216
- feat: parametric policy expressions + runtime-scan correlation (v0.58.0) by @msaad00 in https://github.com/msaad00/agent-bom/pull/217
- fix: CodeQL 'configuration not found' for actions language by @msaad00 in https://github.com/msaad00/agent-bom/pull/218
- fix: sync stale tool counts, versions, and registry metadata by @msaad00 in https://github.com/msaad00/agent-bom/pull/219
- fix: ClawHub trust transparency — address Suspicious rating by @msaad00 in https://github.com/msaad00/agent-bom/pull/220
- release: v0.58.1 — security hardening + CodeQL fix + version alignment by @msaad00 in https://github.com/msaad00/agent-bom/pull/221
Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.57.0...v0.58.1
Security Fixes
- ClawHub trust transparency — address Suspicious rating (hardening)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About msaad00/agent-bom
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Related context
Related tools
Beta — feedback welcome: [email protected]