Skip to content

msaad00/agent-bom

v0.71.3 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-agents ai-security ai-supply-chain aibom blast-radius cloud-security
+14 more
compliance container-security cyclonedx security kubernetes llm-security mcp mcp-server owasp sarif sbom security-scanner supply-chain-security vulnerability-scanning

Affected surfaces

deps breaking_upgrade

Summary

AI summary

Patch OS CVEs in Docker images and add supply chain attestations.

Full changelog

What's Changed

  • chore(deps): bump next from 16.1.6 to 16.1.7 in /ui by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/916
  • fix: release hardening — Docker Hub sync, demo clean, HELM-003 Jinja, transitive log, docs flag by @msaad00 in https://github.com/msaad00/agent-bom/pull/919
  • fix: release hardening — Docker Hub auto-sync, demo clean paths, HELM-003 Jinja, transitive log, prod docs flag by @msaad00 in https://github.com/msaad00/agent-bom/pull/918
  • ci: mark Python 3.14 as experimental (pre-release, non-blocking) by @msaad00 in https://github.com/msaad00/agent-bom/pull/920
  • fix: update compliance framework count in SVG diagrams 11 → 14 by @msaad00 in https://github.com/msaad00/agent-bom/pull/921
  • fix: bump base images python 3.12.13-slim + enforce Trivy image gate by @msaad00 in https://github.com/msaad00/agent-bom/pull/922
  • fix: resolve GitHub code scanning — privileged checkout + token-permissions by @msaad00 in https://github.com/msaad00/agent-bom/pull/923
  • fix: close scanner coverage gap — osv-scanner uv.lock + real self-scan SBOM by @msaad00 in https://github.com/msaad00/agent-bom/pull/924
  • fix: patch OS CVEs in Docker images + add supply chain attestations by @msaad00 in https://github.com/msaad00/agent-bom/pull/925
  • Improve security, error handling, and deployment configuration by @andres-linero in https://github.com/msaad00/agent-bom/pull/928
  • fix: mask Docker Hub token + pin Alpine digest + Glama healthcheck by @msaad00 in https://github.com/msaad00/agent-bom/pull/929
  • fix: bound BFS queue in context graph to prevent OOM (#877) by @msaad00 in https://github.com/msaad00/agent-bom/pull/930
  • fix: close scanner self-scan gap — OS package scan in Docker CI by @msaad00 in https://github.com/msaad00/agent-bom/pull/931
  • fix: replace urllib callers with retry-capable httpx client (#878) by @msaad00 in https://github.com/msaad00/agent-bom/pull/932
  • fix: pre-release audit — empty version guard, CMMC API, action.yml by @msaad00 in https://github.com/msaad00/agent-bom/pull/933
  • release: v0.71.3 — scanner accuracy, HTTP reliability, Docker hardening by @msaad00 in https://github.com/msaad00/agent-bom/pull/942

New Contributors

  • @andres-linero made their first contribution in https://github.com/msaad00/agent-bom/pull/928

Full Changelog: https://github.com/msaad00/agent-bom/compare/v0...v0.71.3

Security Fixes

  • Patch OS CVEs in Docker images and add supply chain attestations

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track msaad00/agent-bom

Get notified when new releases ship.

Sign up free

About msaad00/agent-bom

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

All releases →

Related context

Beta — feedback welcome: [email protected]