Skip to content

msaad00/agent-bom

v0.75.14 Security

This release includes 4 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 4 known CVEs

Topics

ai-agents ai-security ai-supply-chain aibom blast-radius cloud-security
+14 more
compliance container-security cyclonedx security kubernetes llm-security mcp mcp-server owasp sarif sbom security-scanner supply-chain-security vulnerability-scanning

Affected surfaces

auth deps

Summary

AI summary

Require Railway bearer token for MCP startup.

Full changelog

What's Changed

  • fix(mcp): shorten registry description for schema validation by @msaad00 in https://github.com/msaad00/agent-bom/pull/1181
  • docs(mcp): expand first-class client integration guides by @msaad00 in https://github.com/msaad00/agent-bom/pull/1182
  • chore: tighten audit-driven docs and config hygiene by @msaad00 in https://github.com/msaad00/agent-bom/pull/1183
  • feat(skills): deepen review verdicts and behavior analysis by @msaad00 in https://github.com/msaad00/agent-bom/pull/1184
  • fix: resolve remaining v0.75.13 audit findings by @msaad00 in https://github.com/msaad00/agent-bom/pull/1185
  • docs: clarify local UI traffic vs third-party network calls by @msaad00 in https://github.com/msaad00/agent-bom/pull/1188
  • feat(action): add skills scan mode and verdict gating by @msaad00 in https://github.com/msaad00/agent-bom/pull/1187
  • fix(action): keep skills mode off vuln-scan flags by @msaad00 in https://github.com/msaad00/agent-bom/pull/1190
  • docs: clean low-visibility hygiene stragglers by @msaad00 in https://github.com/msaad00/agent-bom/pull/1191
  • perf: improve scan latency and cache hit rate across enrichment by @msaad00 in https://github.com/msaad00/agent-bom/pull/1192
  • remediation: avoid prerelease fix suggestions by default by @msaad00 in https://github.com/msaad00/agent-bom/pull/1193
  • tests: eliminate leaked runtime coroutine warnings by @msaad00 in https://github.com/msaad00/agent-bom/pull/1194
  • scorecard: improve transient failure handling and coverage reporting by @msaad00 in https://github.com/msaad00/agent-bom/pull/1195
  • fix(ui): align scan result contract with backend payload by @msaad00 in https://github.com/msaad00/agent-bom/pull/1196
  • fix(scorecard): bound long-lived service caches by @msaad00 in https://github.com/msaad00/agent-bom/pull/1197
  • fix(mcp): harden tool path handling and error output by @msaad00 in https://github.com/msaad00/agent-bom/pull/1198
  • fix(api): fail closed on unauthenticated non-loopback binds by @msaad00 in https://github.com/msaad00/agent-bom/pull/1199
  • fix(action): harden argv handling and CI summaries by @msaad00 in https://github.com/msaad00/agent-bom/pull/1200
  • feat(mcp): add tool governance and metrics by @msaad00 in https://github.com/msaad00/agent-bom/pull/1201
  • feat(docker): add enterprise proxy and CA support by @msaad00 in https://github.com/msaad00/agent-bom/pull/1202
  • fix(action): harden execution contract and summaries by @msaad00 in https://github.com/msaad00/agent-bom/pull/1203
  • feat(mcp): require auth on remote transports by @msaad00 in https://github.com/msaad00/agent-bom/pull/1204
  • feat(docker): add snowpark proxy and ca support by @msaad00 in https://github.com/msaad00/agent-bom/pull/1205
  • fix(deploy): require railway bearer token for mcp startup by @msaad00 in https://github.com/msaad00/agent-bom/pull/1207
  • chore(deps): bump litellm from 1.82.6 to 1.83.0 by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/1206
  • fix(docker): build runtime image from source by @msaad00 in https://github.com/msaad00/agent-bom/pull/1208
  • fix(action): validate thresholds and sanitize comments by @msaad00 in https://github.com/msaad00/agent-bom/pull/1209
  • fix(mcp): govern sync tool execution by @msaad00 in https://github.com/msaad00/agent-bom/pull/1210
  • feat(mcp): add caller rate limits and request traces by @msaad00 in https://github.com/msaad00/agent-bom/pull/1211
  • chore(release): prepare v0.75.14 by @msaad00 in https://github.com/msaad00/agent-bom/pull/1212

Full Changelog: https://github.com/msaad00/agent-bom/compare/v0...v0.75.14

Breaking Changes

  • Require Railway bearer token for MCP startup (deploy:fix).

Security Fixes

  • Harden tool path handling and error output in mcp (mcp:fix)
  • Fail closed on unauthenticated non-loopback binds in api (api:fix)
  • Harden argv handling and CI summaries in action (action:fix)
  • Validate thresholds and sanitize comments in action (action:fix)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track msaad00/agent-bom

Get notified when new releases ship.

Sign up free

About msaad00/agent-bom

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

All releases →

Related context

Beta — feedback welcome: [email protected]