This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryRemoved ToolHive integration and added live OS package scanning.
Full changelog
What's Changed
- chore: remove ToolHive integration by @msaad00 in https://github.com/msaad00/agent-bom/pull/882
- chore: weekly uv.lock upgrade 2026-03-16 by @msaad00 in https://github.com/msaad00/agent-bom/pull/883
- fix: ensure packaging installed in GitHub Action by @msaad00 in https://github.com/msaad00/agent-bom/pull/888
- chore: MCP registry sync — 0 new, 15 versions, 0 CVE-enriched by @msaad00 in https://github.com/msaad00/agent-bom/pull/884
- fix: skip CWD auto-detect when --sbom is provided by @msaad00 in https://github.com/msaad00/agent-bom/pull/889
- feat: live OS package scanning — dpkg, rpm, apk by @msaad00 in https://github.com/msaad00/agent-bom/pull/890
- feat: agent-bom run — launch MCP server through runtime proxy by @msaad00 in https://github.com/msaad00/agent-bom/pull/891
- feat: ingest ToolHive catalog as MCP server discovery source by @msaad00 in https://github.com/msaad00/agent-bom/pull/892
- chore: bump version to v0.71.1 by @msaad00 in https://github.com/msaad00/agent-bom/pull/893
- fix: guard against empty server spec in agent-bom run by @msaad00 in https://github.com/msaad00/agent-bom/pull/894
Full Changelog: https://github.com/msaad00/agent-bom/compare/v0...v0.71.1
Breaking Changes
- Removed ToolHive integration
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About msaad00/agent-bom
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Related context
Related tools
Beta — feedback welcome: [email protected]