This release includes 4 security fixes for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summaryFixed multiple audit and security hardening issues.
Full changelog
What's Changed
- fix: restrict release workflow to semver tags only by @msaad00 in https://github.com/msaad00/agent-bom/pull/270
- fix: polish blast radius and scan pipeline diagrams by @msaad00 in https://github.com/msaad00/agent-bom/pull/271
- fix: P0 audit findings — Helm image repo, credential redaction by @msaad00 in https://github.com/msaad00/agent-bom/pull/272
- fix: audit hardening — tool count, log perms, SHA pin, CI matrix by @msaad00 in https://github.com/msaad00/agent-bom/pull/273
- fix: security hardening — DNS rebinding, sequence evasion, resource scanning, metrics auth by @msaad00 in https://github.com/msaad00/agent-bom/pull/281
- fix: SKILL.md VT heuristic + multi-stage Docker builds by @msaad00 in https://github.com/msaad00/agent-bom/pull/282
- chore: bump version to v0.59.3 by @msaad00 in https://github.com/msaad00/agent-bom/pull/283
Full Changelog: https://github.com/msaad00/agent-bom/compare/v0...v0.59.3
Security Fixes
- Helm image repository audit finding resolved.
- Credential redaction addressed in P0 audit findings.
- Audit hardening: reduced tool count, adjusted log permissions, added SHA pinning, expanded CI matrix.
- Security hardening: mitigated DNS rebinding, sequence evasion, resource scanning, and enforced metrics authentication.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About msaad00/agent-bom
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Related context
Related tools
Beta — feedback welcome: [email protected]