This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryFixed severity calculation on basic scans by capturing CVSS from OSV.
Full changelog
What's Changed
- perf: 3x scan speed — fix DB query bottleneck by @msaad00 in https://github.com/msaad00/agent-bom/pull/835
- chore(deps): bump sigstore/cosign-installer from 4.0.0 to 4.1.0 by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/837
- chore(deps): bump actions/download-artifact from 8.0.0 to 8.0.1 by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/838
- chore(deps): bump astral-sh/setup-uv from 7.3.1 to 7.5.0 by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/839
- chore(deps): bump docker/setup-qemu-action from 3.6.0 to 4.0.0 by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/840
- chore(deps): bump actions/cache from 4.3.0 to 5.0.3 by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/841
- chore(deps-dev): bump @types/node from 20.19.33 to 25.5.0 in /ui by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/842
- chore(deps-dev): bump @tailwindcss/postcss from 4.2.0 to 4.2.1 in /ui by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/843
- docs: Trust & Transparency section in README by @msaad00 in https://github.com/msaad00/agent-bom/pull/844
- feat: expand IaC rules 42 → 82 across 4 formats by @msaad00 in https://github.com/msaad00/agent-bom/pull/845
- feat: CIS 100% coverage + CMMC 2.0 compliance module by @msaad00 in https://github.com/msaad00/agent-bom/pull/847
- fix: scan guard accounts for all scan modes by @msaad00 in https://github.com/msaad00/agent-bom/pull/850
- fix: compact output UX — framework tags + severity hint by @msaad00 in https://github.com/msaad00/agent-bom/pull/853
- fix: severity on basic scans — capture CVSS from OSV by @msaad00 in https://github.com/msaad00/agent-bom/pull/854
- chore: bump version to v0.70.12 by @msaad00 in https://github.com/msaad00/agent-bom/pull/855
Full Changelog: https://github.com/msaad00/agent-bom/compare/v0...v0.70.12
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About msaad00/agent-bom
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Related context
Related tools
Beta — feedback welcome: [email protected]