This release adds 8 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Affected surfaces
Summary
AI summaryUpdates span UI dashboard exposure paths and navigation, onboarding quickstart commands, gateway baseline policies, findings triage queue APIs/UI, observability session store, graph evidence workflows, hardening audit gaps, dependency bumps, and runtime governance features.
Full changelog
What's Changed
- fix(ci): retry pip-audit with pypi source by @msaad00 in https://github.com/msaad00/agent-bom/pull/2797
- chore(deps-dev): bump typescript-eslint from 8.59.4 to 8.60.0 in /ui by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/2795
- chore(deps): bump @tanstack/react-virtual from 3.13.25 to 3.13.26 in /ui by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/2796
- fix(gateway): expose empty policy posture by @msaad00 in https://github.com/msaad00/agent-bom/pull/2806
- fix(api): avoid postgres rls bypass noise for in-memory schedules by @msaad00 in https://github.com/msaad00/agent-bom/pull/2807
- fix(ui): serve dashboard client routes without api auth by @msaad00 in https://github.com/msaad00/agent-bom/pull/2808
- fix(skills): separate prompt risk from malicious verdict by @msaad00 in https://github.com/msaad00/agent-bom/pull/2809
- test(deploy): capture eks verification evidence by @msaad00 in https://github.com/msaad00/agent-bom/pull/2810
- feat(ui): lead dashboard with exposure paths by @msaad00 in https://github.com/msaad00/agent-bom/pull/2814
- feat(onboarding): add quickstart command by @msaad00 in https://github.com/msaad00/agent-bom/pull/2815
- feat(gateway): add baseline policy pack by @msaad00 in https://github.com/msaad00/agent-bom/pull/2816
- fix(ui): harden dashboard offline and navigation states by @msaad00 in https://github.com/msaad00/agent-bom/pull/2817
- feat(onboarding): execute quickstart with --run by @msaad00 in https://github.com/msaad00/agent-bom/pull/2818
- fix(ui): keep dashboard topology within bundle budget by @msaad00 in https://github.com/msaad00/agent-bom/pull/2819
- test(graph): add security-graph cockpit e2e evidence by @msaad00 in https://github.com/msaad00/agent-bom/pull/2820
- fix(graph): finish cockpit drilldown evidence by @msaad00 in https://github.com/msaad00/agent-bom/pull/2821
- chore(deps): bump docker/setup-qemu-action from 4.0.0 to 4.1.0 by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/2822
- chore(deps): bump lucide-react from 1.16.0 to 1.17.0 in /ui by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/2823
- feat(ui): connect jobs to source evidence workflow by @msaad00 in https://github.com/msaad00/agent-bom/pull/2824
- feat(observability): add runtime event session store by @msaad00 in https://github.com/msaad00/agent-bom/pull/2825
- feat(ui): link source evidence workflows by @msaad00 in https://github.com/msaad00/agent-bom/pull/2826
- feat(findings): add triage queue vex API by @msaad00 in https://github.com/msaad00/agent-bom/pull/2827
- feat(findings): surface triage queue in UI by @msaad00 in https://github.com/msaad00/agent-bom/pull/2831
- fix(api): fail closed without auth config by @msaad00 in https://github.com/msaad00/agent-bom/pull/2832
- test(first-run): isolate GHSA enrichment fixture by @msaad00 in https://github.com/msaad00/agent-bom/pull/2849
- fix(hardening): close week-one audit gaps by @msaad00 in https://github.com/msaad00/agent-bom/pull/2850
- perf(graph): add Postgres latency benchmark scaffold by @msaad00 in https://github.com/msaad00/agent-bom/pull/2851
- feat(runtime): v0.88.5 runtime governance — FinOps, identity lifecycle, drift incidents, gateway policy fusion by @msaad00 in https://github.com/msaad00/agent-bom/pull/2852
Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.88.4...v0.88.5
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About msaad00/agent-bom
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Related context
Related tools
Beta — feedback welcome: [email protected]