Skip to content

msaad00/agent-bom

v0.72.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-agents ai-security ai-supply-chain aibom blast-radius cloud-security
+14 more
compliance container-security cyclonedx security kubernetes llm-security mcp mcp-server owasp sarif sbom security-scanner supply-chain-security vulnerability-scanning

Summary

AI summary

Expanded IaC and K8s rule sets to 50 Terraform rules (TF-SEC-021‑050) and 30 Helm/K8s rules.

Full changelog

What's Changed

  • fix: upgrade Next.js 16.1.7 → 16.2.0 — fixes 3 HIGH GHSAs by @msaad00 in https://github.com/msaad00/agent-bom/pull/951
  • fix: handle Go pseudo-versions in vulnerability range comparison by @msaad00 in https://github.com/msaad00/agent-bom/pull/952
  • fix: suppress Scorecard-flagged GHSAs — all fixed at locked versions by @msaad00 in https://github.com/msaad00/agent-bom/pull/954
  • feat: expand Terraform IaC rules 20→50 (TF-SEC-021 through TF-SEC-050) by @msaad00 in https://github.com/msaad00/agent-bom/pull/955
  • feat: expand K8s rules 17→30 + Helm rules 8→15 by @msaad00 in https://github.com/msaad00/agent-bom/pull/956
  • fix: SARIF exclude-unfixable, Action scan-type, Scorecard hardening by @msaad00 in https://github.com/msaad00/agent-bom/pull/957
  • refactor: reorganize CLI — categorized help, command groups by @msaad00 in https://github.com/msaad00/agent-bom/pull/958
  • fix: rename OSV config for Scorecard auto-discovery (Vulnerabilities 0→10) by @msaad00 in https://github.com/msaad00/agent-bom/pull/959
  • chore: Docker Hub tag retention — keep last 10, auto-clean on release by @msaad00 in https://github.com/msaad00/agent-bom/pull/960
  • docs: update all command references to new CLI groups by @msaad00 in https://github.com/msaad00/agent-bom/pull/961
  • feat: CLI UX polish + input validation hardening by @msaad00 in https://github.com/msaad00/agent-bom/pull/962
  • feat: v0.72.0 — version accuracy, AI BOM tools, 30 MCP clients, compliance noise reduction by @msaad00 in https://github.com/msaad00/agent-bom/pull/963
  • docs: v0.72.0 architecture refresh — 30 clients, version bump, all surfaces updated by @msaad00 in https://github.com/msaad00/agent-bom/pull/964
  • docs: demo GIF for v0.72.0 by @msaad00 in https://github.com/msaad00/agent-bom/pull/965

Full Changelog: https://github.com/msaad00/agent-bom/compare/v0...v0.72.0

Security Fixes

  • fix: upgrade Next.js 16.1.7 → 16.2.0 — fixes 3 HIGH GHSAs

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track msaad00/agent-bom

Get notified when new releases ship.

Sign up free

About msaad00/agent-bom

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

All releases →

Related context

Beta — feedback welcome: [email protected]