This release adds 4 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Affected surfaces
Summary
AI summarySurface security-blocked servers in reports.
Full changelog
What's Changed
- feat: SBOM vendor metadata + supply chain enrichment by @msaad00 in https://github.com/msaad00/agent-bom/pull/473
- feat: AI-BOM training pipeline lineage + dataset cards by @msaad00 in https://github.com/msaad00/agent-bom/pull/474
- fix: harden URL/domain validation across codebase (CodeQL) by @msaad00 in https://github.com/msaad00/agent-bom/pull/475
- feat: compliance framework tags for training/dataset findings by @msaad00 in https://github.com/msaad00/agent-bom/pull/477
- feat: wire 6 scan types to MCP tools + fix browser_extensions persistence by @msaad00 in https://github.com/msaad00/agent-bom/pull/482
- fix: consistent _truncate_response on all MCP tool success paths by @msaad00 in https://github.com/msaad00/agent-bom/pull/483
- fix: credibility hardening — security, accuracy, and performance audit by @msaad00 in https://github.com/msaad00/agent-bom/pull/488
- fix: prod hardening round 2 — policy validation, log rotation, KEV resilience by @msaad00 in https://github.com/msaad00/agent-bom/pull/489
- feat: Cortex Code P0 — skill discovery, permission audit, hook validation by @msaad00 in https://github.com/msaad00/agent-bom/pull/490
- feat: production hardening — auth, VEX enforcement, API scope, filesystem by @msaad00 in https://github.com/msaad00/agent-bom/pull/491
- feat: surface security-blocked servers in reports by @msaad00 in https://github.com/msaad00/agent-bom/pull/492
- feat: dedicated REST API endpoints for 6 scan types by @msaad00 in https://github.com/msaad00/agent-bom/pull/494
- fix: Docker LICENSE, OCI labels, cross-platform alignment by @msaad00 in https://github.com/msaad00/agent-bom/pull/497
- feat: multi-vendor GPU detection — AMD ROCm, Intel, Windows WDDM by @msaad00 in https://github.com/msaad00/agent-bom/pull/499
- feat: upgrade license engine — full SPDX catalog, network-copyleft, MCP tool by @msaad00 in https://github.com/msaad00/agent-bom/pull/500
- docs: ADR structure with 5 initial architecture decision records by @msaad00 in https://github.com/msaad00/agent-bom/pull/501
- chore: bump version to v0.68.0 + sync docs, diagrams, and stats by @msaad00 in https://github.com/msaad00/agent-bom/pull/502
Full Changelog: https://github.com/msaad00/agent-bom/compare/v0...v0.68.0
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About msaad00/agent-bom
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Related context
Related tools
Beta — feedback welcome: [email protected]