Skip to content

msaad00/agent-bom

v0.70.12 Feature

This release adds 2 notable features for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

ai-agents ai-security ai-supply-chain aibom blast-radius cloud-security
+14 more
compliance container-security cyclonedx security kubernetes llm-security mcp mcp-server owasp sarif sbom security-scanner supply-chain-security vulnerability-scanning

Summary

AI summary

Fixed severity calculation on basic scans by capturing CVSS from OSV.

Full changelog

What's Changed

  • perf: 3x scan speed — fix DB query bottleneck by @msaad00 in https://github.com/msaad00/agent-bom/pull/835
  • chore(deps): bump sigstore/cosign-installer from 4.0.0 to 4.1.0 by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/837
  • chore(deps): bump actions/download-artifact from 8.0.0 to 8.0.1 by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/838
  • chore(deps): bump astral-sh/setup-uv from 7.3.1 to 7.5.0 by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/839
  • chore(deps): bump docker/setup-qemu-action from 3.6.0 to 4.0.0 by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/840
  • chore(deps): bump actions/cache from 4.3.0 to 5.0.3 by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/841
  • chore(deps-dev): bump @types/node from 20.19.33 to 25.5.0 in /ui by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/842
  • chore(deps-dev): bump @tailwindcss/postcss from 4.2.0 to 4.2.1 in /ui by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/843
  • docs: Trust & Transparency section in README by @msaad00 in https://github.com/msaad00/agent-bom/pull/844
  • feat: expand IaC rules 42 → 82 across 4 formats by @msaad00 in https://github.com/msaad00/agent-bom/pull/845
  • feat: CIS 100% coverage + CMMC 2.0 compliance module by @msaad00 in https://github.com/msaad00/agent-bom/pull/847
  • fix: scan guard accounts for all scan modes by @msaad00 in https://github.com/msaad00/agent-bom/pull/850
  • fix: compact output UX — framework tags + severity hint by @msaad00 in https://github.com/msaad00/agent-bom/pull/853
  • fix: severity on basic scans — capture CVSS from OSV by @msaad00 in https://github.com/msaad00/agent-bom/pull/854
  • chore: bump version to v0.70.12 by @msaad00 in https://github.com/msaad00/agent-bom/pull/855

Full Changelog: https://github.com/msaad00/agent-bom/compare/v0...v0.70.12

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track msaad00/agent-bom

Get notified when new releases ship.

Sign up free

About msaad00/agent-bom

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

All releases →

Related context

Beta — feedback welcome: [email protected]