Skip to content

msaad00/agent-bom

v0.74.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-agents ai-security ai-supply-chain aibom blast-radius cloud-security
+14 more
compliance container-security cyclonedx security kubernetes llm-security mcp mcp-server owasp sarif sbom security-scanner supply-chain-security vulnerability-scanning

Summary

AI summary

Security hardening and compliance improvements were applied.

Full changelog

What's Changed

  • fix: MCP Registry description length (422 validation) by @msaad00 in https://github.com/msaad00/agent-bom/pull/1002
  • Use pyproject.toml as source of truth for version in publish workflow by @andres-linero in https://github.com/msaad00/agent-bom/pull/1001
  • Enterprise foundation: dev experience, scanner accuracy, bug fixes by @msaad00 in https://github.com/msaad00/agent-bom/pull/1003
  • fix: runtime security + compliance wiring audit fixes by @msaad00 in https://github.com/msaad00/agent-bom/pull/1004
  • feat: supply chain provenance + Go checksum DB + cloud timeout by @msaad00 in https://github.com/msaad00/agent-bom/pull/1005
  • release: v0.74.1 — security hardening, compliance wiring, README overhaul by @msaad00 in https://github.com/msaad00/agent-bom/pull/1006
  • chore: align Docker Hub + action.yml for v0.74.1 by @msaad00 in https://github.com/msaad00/agent-bom/pull/1007

Full Changelog: https://github.com/msaad00/agent-bom/compare/v0...v0.74.1

Security Fixes

  • Security hardening applied to runtime security and compliance wiring audit fixes

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track msaad00/agent-bom

Get notified when new releases ship.

Sign up free

About msaad00/agent-bom

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

All releases →

Related context

Beta — feedback welcome: [email protected]