This release includes 4 security fixes for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summaryRequire Railway bearer token for MCP startup.
Full changelog
What's Changed
- fix(mcp): shorten registry description for schema validation by @msaad00 in https://github.com/msaad00/agent-bom/pull/1181
- docs(mcp): expand first-class client integration guides by @msaad00 in https://github.com/msaad00/agent-bom/pull/1182
- chore: tighten audit-driven docs and config hygiene by @msaad00 in https://github.com/msaad00/agent-bom/pull/1183
- feat(skills): deepen review verdicts and behavior analysis by @msaad00 in https://github.com/msaad00/agent-bom/pull/1184
- fix: resolve remaining v0.75.13 audit findings by @msaad00 in https://github.com/msaad00/agent-bom/pull/1185
- docs: clarify local UI traffic vs third-party network calls by @msaad00 in https://github.com/msaad00/agent-bom/pull/1188
- feat(action): add skills scan mode and verdict gating by @msaad00 in https://github.com/msaad00/agent-bom/pull/1187
- fix(action): keep skills mode off vuln-scan flags by @msaad00 in https://github.com/msaad00/agent-bom/pull/1190
- docs: clean low-visibility hygiene stragglers by @msaad00 in https://github.com/msaad00/agent-bom/pull/1191
- perf: improve scan latency and cache hit rate across enrichment by @msaad00 in https://github.com/msaad00/agent-bom/pull/1192
- remediation: avoid prerelease fix suggestions by default by @msaad00 in https://github.com/msaad00/agent-bom/pull/1193
- tests: eliminate leaked runtime coroutine warnings by @msaad00 in https://github.com/msaad00/agent-bom/pull/1194
- scorecard: improve transient failure handling and coverage reporting by @msaad00 in https://github.com/msaad00/agent-bom/pull/1195
- fix(ui): align scan result contract with backend payload by @msaad00 in https://github.com/msaad00/agent-bom/pull/1196
- fix(scorecard): bound long-lived service caches by @msaad00 in https://github.com/msaad00/agent-bom/pull/1197
- fix(mcp): harden tool path handling and error output by @msaad00 in https://github.com/msaad00/agent-bom/pull/1198
- fix(api): fail closed on unauthenticated non-loopback binds by @msaad00 in https://github.com/msaad00/agent-bom/pull/1199
- fix(action): harden argv handling and CI summaries by @msaad00 in https://github.com/msaad00/agent-bom/pull/1200
- feat(mcp): add tool governance and metrics by @msaad00 in https://github.com/msaad00/agent-bom/pull/1201
- feat(docker): add enterprise proxy and CA support by @msaad00 in https://github.com/msaad00/agent-bom/pull/1202
- fix(action): harden execution contract and summaries by @msaad00 in https://github.com/msaad00/agent-bom/pull/1203
- feat(mcp): require auth on remote transports by @msaad00 in https://github.com/msaad00/agent-bom/pull/1204
- feat(docker): add snowpark proxy and ca support by @msaad00 in https://github.com/msaad00/agent-bom/pull/1205
- fix(deploy): require railway bearer token for mcp startup by @msaad00 in https://github.com/msaad00/agent-bom/pull/1207
- chore(deps): bump litellm from 1.82.6 to 1.83.0 by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/1206
- fix(docker): build runtime image from source by @msaad00 in https://github.com/msaad00/agent-bom/pull/1208
- fix(action): validate thresholds and sanitize comments by @msaad00 in https://github.com/msaad00/agent-bom/pull/1209
- fix(mcp): govern sync tool execution by @msaad00 in https://github.com/msaad00/agent-bom/pull/1210
- feat(mcp): add caller rate limits and request traces by @msaad00 in https://github.com/msaad00/agent-bom/pull/1211
- chore(release): prepare v0.75.14 by @msaad00 in https://github.com/msaad00/agent-bom/pull/1212
Full Changelog: https://github.com/msaad00/agent-bom/compare/v0...v0.75.14
Breaking Changes
- Require Railway bearer token for MCP startup (deploy:fix).
Security Fixes
- Harden tool path handling and error output in mcp (mcp:fix)
- Fail closed on unauthenticated non-loopback binds in api (api:fix)
- Harden argv handling and CI summaries in action (action:fix)
- Validate thresholds and sanitize comments in action (action:fix)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About msaad00/agent-bom
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Related context
Related tools
Beta — feedback welcome: [email protected]