This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summaryHarden local vulnerability database with security measures.
Full changelog
What's Changed
- fix: harden local vuln DB security — chmod 0600, HTTPS-only sync, path validation, integrity check + Alpine CI by @msaad00 in https://github.com/msaad00/agent-bom/pull/634
- chore: bump version to 0.70.4 by @msaad00 in https://github.com/msaad00/agent-bom/pull/635
Full Changelog: https://github.com/msaad00/agent-bom/compare/v0...v0.70.4
Security Fixes
- Harden local vulnerability DB: enforce chmod 0600, HTTPS-only sync, path validation, integrity check
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About msaad00/agent-bom
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Related context
Related tools
Beta — feedback welcome: [email protected]