This release adds 4 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryAdded unified Finding model Phase 1 enabling blast‑radius enrichment across Trivy/Grype/Syft.
Full changelog
What's Changed
- fix: remove unsupported license field from mcp-registry server.json by @msaad00 in https://github.com/msaad00/agent-bom/pull/617
- fix: parse_fixed_version PEP 503, scan cache LRU cap, pipeline 429 cooldown by @msaad00 in https://github.com/msaad00/agent-bom/pull/618
- fix: GHSA PEP 503 normalization for advisory matching + resolver debug logging by @msaad00 in https://github.com/msaad00/agent-bom/pull/619
- fix: add logging to all bare silent exception handlers by @msaad00 in https://github.com/msaad00/agent-bom/pull/620
- chore: remove dead code + bump to v0.70.1 by @msaad00 in https://github.com/msaad00/agent-bom/pull/621
- style: enforce E501 line-length compliance by @msaad00 in https://github.com/msaad00/agent-bom/pull/623
- feat: Trivy/Grype/Syft JSON ingestion with blast radius enrichment by @msaad00 in https://github.com/msaad00/agent-bom/pull/624
- feat: two-tier severity — warn vs fail thresholds by @msaad00 in https://github.com/msaad00/agent-bom/pull/625
- fix: replace hardcoded MCP tool counts with dynamic assertions by @msaad00 in https://github.com/msaad00/agent-bom/pull/626
- chore: bump version to 0.70.2 by @msaad00 in https://github.com/msaad00/agent-bom/pull/627
- feat: unified Finding model Phase 1 — core dataclasses, BlastRadius shim, dual-write by @msaad00 in https://github.com/msaad00/agent-bom/pull/628
- fix: preset ci two-tier defaults, README demo gif, MCP tool/client counts by @msaad00 in https://github.com/msaad00/agent-bom/pull/629
- feat: delta scanning — --delta flag, new-only exit code, baseline file I/O by @msaad00 in https://github.com/msaad00/agent-bom/pull/630
- feat: local embedded vulnerability database — SQLite, OSV/EPSS/KEV sync, agent-bom db CLI by @msaad00 in https://github.com/msaad00/agent-bom/pull/631
- fix: HTML report delta/warn-gate banners, vendor_severity in table and JSON by @msaad00 in https://github.com/msaad00/agent-bom/pull/632
- chore: bump version to 0.70.3 by @msaad00 in https://github.com/msaad00/agent-bom/pull/633
Full Changelog: https://github.com/msaad00/agent-bom/compare/v0...v0.70.3
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About msaad00/agent-bom
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Related context
Related tools
Beta — feedback welcome: [email protected]