This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Summary
AI summarySecurity hardening includes atomic writes, cache eviction, TOCTOU mitigation, and context‑aware compliance tags.
Full changelog
What's Changed
- chore: re-record demo GIF for v0.65.0 by @msaad00 in https://github.com/msaad00/agent-bom/pull/439
- fix: security hardening — atomic writes, cache eviction, TOCTOU mitigation by @msaad00 in https://github.com/msaad00/agent-bom/pull/440
- feat: README UX improvements — tagline, downloads badge, discussions by @msaad00 in https://github.com/msaad00/agent-bom/pull/441
- feat: CLI UX polish + MCP server discoverability by @msaad00 in https://github.com/msaad00/agent-bom/pull/442
- feat: Next.js proxy dashboard + audit log browser by @msaad00 in https://github.com/msaad00/agent-bom/pull/443
- fix: scanner depth audit — 6 accuracy fixes by @msaad00 in https://github.com/msaad00/agent-bom/pull/444
- fix: scanner depth round 2 — scoring accuracy and false positive reduction by @msaad00 in https://github.com/msaad00/agent-bom/pull/445
- fix: proxy/runtime depth — 4 correctness and security fixes by @msaad00 in https://github.com/msaad00/agent-bom/pull/446
- fix: proxy/runtime depth round 2 — detection accuracy and drift reliability by @msaad00 in https://github.com/msaad00/agent-bom/pull/447
- fix: toxic_combos word boundary — normalize separators before matching by @msaad00 in https://github.com/msaad00/agent-bom/pull/448
- feat: security hardening + context-aware compliance tags by @msaad00 in https://github.com/msaad00/agent-bom/pull/449
- chore: bump version to v0.66.0 by @msaad00 in https://github.com/msaad00/agent-bom/pull/450
Full Changelog: https://github.com/msaad00/agent-bom/compare/v0...v0.66.0
Security Fixes
- Security hardening — atomic writes, cache eviction, TOCTOU mitigation; context‑aware compliance tags added
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About msaad00/agent-bom
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Related context
Related tools
Beta — feedback welcome: [email protected]