This release keeps dependencies and maintenance posture current for teams operating this tool.
✓ No known CVEs patched in this version
Topics
+14 more
ReleasePort's take
Light signalThe UI module now uses @tanstack/react-virtual version 3.13.25, updating from 3.13.24.
Why it matters: Patch the UI dependency to 3.13.25 as part of releasing v0.88.1; no immediate security trigger is noted.
Summary
AI summaryMinor fixes and improvements.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Dependency | Medium |
Dependency @tanstack/react-virtual updated from 3.13.24 to 3.13.25 in UI module. Dependency @tanstack/react-virtual updated from 3.13.24 to 3.13.25 in UI module. Source: llm_adapter@2026-05-22 Confidence: low |
— |
| Other | Medium |
Release preparation for version v0.88.1 completed. Release preparation for version v0.88.1 completed. Source: llm_adapter@2026-05-22 Confidence: low |
— |
| Other | Medium |
MCP catalog refreshed for the upcoming release. MCP catalog refreshed for the upcoming release. Source: llm_adapter@2026-05-22 Confidence: low |
— |
| Other | Low |
Release prepared for version v0.88.1. Release prepared for version v0.88.1. Source: granite4.1:30b@2026-05-22-audit Confidence: low |
— |
Full changelog
What's Changed
- chore(deps): bump @tanstack/react-virtual from 3.13.24 to 3.13.25 in /ui by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/2732
- chore(registry): refresh MCP catalog for release by @msaad00 in https://github.com/msaad00/agent-bom/pull/2733
- release: prepare v0.88.1 by @msaad00 in https://github.com/msaad00/agent-bom/pull/2734
Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.88.0...v0.88.1
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About msaad00/agent-bom
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Related context
Related tools
Beta — feedback welcome: [email protected]