Skip to content

msaad00/agent-bom

v0.78.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-agents ai-security ai-supply-chain aibom blast-radius cloud-security
+14 more
compliance container-security cyclonedx security kubernetes llm-security mcp mcp-server owasp sarif sbom security-scanner supply-chain-security vulnerability-scanning

Affected surfaces

auth rbac deps

Summary

AI summary

Add tenant_id column to ClickHouse analytics for row‑level isolation.

Full changelog

What's Changed

  • Prepare 0.77.0 release by @msaad00 in https://github.com/msaad00/agent-bom/pull/1497
  • Correct release to 0.77.1 by @msaad00 in https://github.com/msaad00/agent-bom/pull/1498
  • Phase 0+1 hardening: rotation, drain, webhook retry, README + visuals by @msaad00 in https://github.com/msaad00/agent-bom/pull/1499
  • Add backup-restore round-trip CI workflow by @msaad00 in https://github.com/msaad00/agent-bom/pull/1500
  • Add tenant_id column to ClickHouse analytics for row-level isolation by @msaad00 in https://github.com/msaad00/agent-bom/pull/1501
  • Add /v1/auth/debug for auth-method introspection by @msaad00 in https://github.com/msaad00/agent-bom/pull/1502
  • Add MCP tool-schema validation rule catalog (OWASP-mapped) by @msaad00 in https://github.com/msaad00/agent-bom/pull/1507
  • Tighten README diagrams + document the visual language by @msaad00 in https://github.com/msaad00/agent-bom/pull/1503
  • Add /v1/compliance/{framework}/report signed evidence bundle endpoint by @msaad00 in https://github.com/msaad00/agent-bom/pull/1504
  • Add docs/DATA_MODEL.md \u2014 single atlas for canonical model + DB + outputs by @msaad00 in https://github.com/msaad00/agent-bom/pull/1505
  • Update dashboard description for the Risk overview redesign by @msaad00 in https://github.com/msaad00/agent-bom/pull/1506
  • Add bounded depth cap to inter-procedural taint analyzer by @msaad00 in https://github.com/msaad00/agent-bom/pull/1508
  • Restructure README EKS section + prune redundant topology SVG by @msaad00 in https://github.com/msaad00/agent-bom/pull/1510
  • Harden compliance report (replay protection) + broaden LLM05 supply-chain tag by @msaad00 in https://github.com/msaad00/agent-bom/pull/1509
  • Fresh screenshots: demo GIF + dashboard PNG (recorded locally) by @msaad00 in https://github.com/msaad00/agent-bom/pull/1511
  • Add structured remediation field to CIS benchmark checks (#665 infra) by @msaad00 in https://github.com/msaad00/agent-bom/pull/1512
  • Document and enforce OCSF boundary (optional SIEM interop) by @msaad00 in https://github.com/msaad00/agent-bom/pull/1513
  • Wire CIS remediation through CLI, HTML, and SARIF (#665) by @msaad00 in https://github.com/msaad00/agent-bom/pull/1517
  • Add exploit_likelihood graded signal (EPSS + KEV) — closes #486 by @msaad00 in https://github.com/msaad00/agent-bom/pull/1518
  • Wire MCP schema rule findings and harden chart defaults by @msaad00 in https://github.com/msaad00/agent-bom/pull/1519
  • chore(release): backfill 0.77.0/0.77.1 CHANGELOG + align tools.json with 36 MCP decorators by @msaad00 in https://github.com/msaad00/agent-bom/pull/1523
  • ux(cli): polish Fix First output — spacing + $ command prefix by @msaad00 in https://github.com/msaad00/agent-bom/pull/1524
  • ux(dashboard): section headers + collapsibles on Risk overview page by @msaad00 in https://github.com/msaad00/agent-bom/pull/1525
  • chore(docs): replace vendor names with generic language in published docs by @msaad00 in https://github.com/msaad00/agent-bom/pull/1526
  • chore(skills): align openclaw SKILL.md with on-disk sub-skills + 36-tool catalog by @msaad00 in https://github.com/msaad00/agent-bom/pull/1527
  • security(oci): harden tar-member safety against traversal + symlink attacks by @msaad00 in https://github.com/msaad00/agent-bom/pull/1528
  • docs: sharpen self-hosted deployment story by @msaad00 in https://github.com/msaad00/agent-bom/pull/1529
  • fix: speed up demo scan path and polish check output by @msaad00 in https://github.com/msaad00/agent-bom/pull/1530
  • fix: restore inventory schema validation path by @msaad00 in https://github.com/msaad00/agent-bom/pull/1531
  • fix: enforce end-to-end inventory and graph contracts by @msaad00 in https://github.com/msaad00/agent-bom/pull/1532
  • release: wrap v0.78.0 stabilization by @msaad00 in https://github.com/msaad00/agent-bom/pull/1533

Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.77.0...v0.78.0

Security Fixes

  • security(oci): harden tar-member safety against traversal + symlink attacks

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track msaad00/agent-bom

Get notified when new releases ship.

Sign up free

About msaad00/agent-bom

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

All releases →

Related context

Beta — feedback welcome: [email protected]