Skip to content

msaad00/agent-bom

v0.75.13 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

ai-agents ai-security ai-supply-chain aibom blast-radius cloud-security
+14 more
compliance container-security cyclonedx security kubernetes llm-security mcp mcp-server owasp sarif sbom security-scanner supply-chain-security vulnerability-scanning

Affected surfaces

auth breaking_upgrade

Summary

AI summary

Guided remediation commands added for fixing and verifying issues.

Full changelog

What's Changed

  • fix(release): harden provenance bundle export by @msaad00 in https://github.com/msaad00/agent-bom/pull/1157
  • feat(cli): add operator summary and mesh view by @msaad00 in https://github.com/msaad00/agent-bom/pull/1158
  • feat(skills): add deterministic bundle identity by @msaad00 in https://github.com/msaad00/agent-bom/pull/1164
  • docs: clarify capabilities and deployment guidance by @msaad00 in https://github.com/msaad00/agent-bom/pull/1167
  • feat(remediation): add guided fix and verify commands by @msaad00 in https://github.com/msaad00/agent-bom/pull/1159
  • chore(deps): bump pygments from 2.19.2 to 2.20.0 by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/1171
  • chore: remove toolhive discovery surface by @msaad00 in https://github.com/msaad00/agent-bom/pull/1173
  • chore(deps): bump lucide-react from 0.577.0 to 1.7.0 in /ui by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/1135
  • chore(deps-dev): bump typescript from 5.9.3 to 6.0.2 in /ui by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/1137
  • chore: weekly uv.lock upgrade 2026-03-30 by @github-actions[bot] in https://github.com/msaad00/agent-bom/pull/1169
  • docs(mcp): deepen Claude and Cortex integration guides by @msaad00 in https://github.com/msaad00/agent-bom/pull/1174
  • docs: add canonical product brief and metrics by @msaad00 in https://github.com/msaad00/agent-bom/pull/1175
  • fix(scan): fail closed offline and surface incomplete results by @msaad00 in https://github.com/msaad00/agent-bom/pull/1176
  • fix(cli): sharpen sarif defaults and first-run guidance by @msaad00 in https://github.com/msaad00/agent-bom/pull/1177
  • fix: tighten release-facing CLI trust surfaces by @msaad00 in https://github.com/msaad00/agent-bom/pull/1178
  • release: prepare v0.75.13 by @msaad00 in https://github.com/msaad00/agent-bom/pull/1179

New Contributors

  • @github-actions[bot] made their first contribution in https://github.com/msaad00/agent-bom/pull/1169

Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.75.12...v0.75.13

Security Fixes

  • Tightened release‑facing CLI trust surfaces
  • Harden provenance bundle export
  • Remove toolhive discovery surface

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track msaad00/agent-bom

Get notified when new releases ship.

Sign up free

About msaad00/agent-bom

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

All releases →

Related context

Beta — feedback welcome: [email protected]