This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+14 more
Affected surfaces
Summary
AI summaryRequire authentication for remote runtime HTTP requests.
Full changelog
What's Changed
- fix: preserve fleet endpoint identity in mesh by @msaad00 in https://github.com/msaad00/agent-bom/pull/2116
- fix: harden gateway upstream resilience by @msaad00 in https://github.com/msaad00/agent-bom/pull/2117
- docs: align skill CLI examples by @msaad00 in https://github.com/msaad00/agent-bom/pull/2118
- fix: gate SSE proxy policy methods by @msaad00 in https://github.com/msaad00/agent-bom/pull/2119
- fix: preserve discovery provenance in exports by @msaad00 in https://github.com/msaad00/agent-bom/pull/2120
- fix: surface discovery trust contracts in UI by @msaad00 in https://github.com/msaad00/agent-bom/pull/2121
- fix: preserve fleet endpoint identity in graph by @msaad00 in https://github.com/msaad00/agent-bom/pull/2122
- feat: add Snowflake operator pull adapter by @msaad00 in https://github.com/msaad00/agent-bom/pull/2123
- docs: clarify Helm Postgres deployment contract by @msaad00 in https://github.com/msaad00/agent-bom/pull/2124
- feat: gate stale MCP registry status by @msaad00 in https://github.com/msaad00/agent-bom/pull/2125
- fix: require auth for remote runtime HTTP by @msaad00 in https://github.com/msaad00/agent-bom/pull/2126
- fix: isolate local db scan preference by @msaad00 in https://github.com/msaad00/agent-bom/pull/2127
- chore: prepare v0.83.4 release by @msaad00 in https://github.com/msaad00/agent-bom/pull/2128
Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.83.3...v0.83.4
Breaking Changes
- Require auth for remote runtime HTTP requests.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About msaad00/agent-bom
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Related context
Related tools
Beta — feedback welcome: [email protected]