Skip to content

msaad00/agent-bom

v0.92.0 Feature

This release adds 5 notable features for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

ai-agents ai-security ai-supply-chain aibom blast-radius cloud-security
+14 more
compliance container-security cyclonedx security kubernetes llm-security mcp mcp-server owasp sarif sbom security-scanner supply-chain-security vulnerability-scanning

Affected surfaces

auth

Summary

AI summary

Updates span UI navigation, CLI authentication, MCP workflow startup, Cloud posture ingestion, DSPM sampling, CWPP side‑scan lifecycle, and documentation improvements.

Full changelog

What's Changed

  • fix(gateway): sanitize relay errors and document release gates by @msaad00 in https://github.com/msaad00/agent-bom/pull/3354
  • feat(mcp): add curated workflow bundles and live demo script by @msaad00 in https://github.com/msaad00/agent-bom/pull/3355
  • fix(cli): make loopback first-run auth coherent (serve banner + quickstart) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3356
  • fix(cli): friendlier output extensions, idle compliance, CLI footgun guards by @msaad00 in https://github.com/msaad00/agent-bom/pull/3357
  • perf(graph): publish Postgres latency evidence by @msaad00 in https://github.com/msaad00/agent-bom/pull/3359
  • feat(cloud): event-driven AWS posture — CloudTrail/EventBridge ingestion + per-resource rule re-eval by @msaad00 in https://github.com/msaad00/agent-bom/pull/3358
  • chore(docs): refresh engine-internals counts + align README screenshots by @msaad00 in https://github.com/msaad00/agent-bom/pull/3362
  • feat(ui): consolidate IA — one home, one security-graph lens, trimmed nav, registry in nav by @msaad00 in https://github.com/msaad00/agent-bom/pull/3360
  • feat(ui): compliance export pack + fleet-quarantine→gateway-deny one-click (+ API findings test) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3361
  • docs(images): clip SVG text and enlarge evidence hub icons by @msaad00 in https://github.com/msaad00/agent-bom/pull/3363
  • fix(ci): stabilize lineage-graph dense-view E2E — green main by @msaad00 in https://github.com/msaad00/agent-bom/pull/3368
  • feat(ui): home scorecard + slim dashboard + Govern 3-group nav by @msaad00 in https://github.com/msaad00/agent-bom/pull/3367
  • fix(ci): stop order-dependent test failures — reset all runtime-written env vars by @msaad00 in https://github.com/msaad00/agent-bom/pull/3369
  • feat(cli): zero-config loopback serve — auto-generate + print a dev API key by @msaad00 in https://github.com/msaad00/agent-bom/pull/3364
  • feat(cloud): event-driven Azure + GCP posture — Activity Log / Asset feed ingestion + per-resource rule re-eval by @msaad00 in https://github.com/msaad00/agent-bom/pull/3370
  • fix(ui): keep product visuals bounded and current by @msaad00 in https://github.com/msaad00/agent-bom/pull/3371
  • feat(ui): surface graph lenses in navigation by @msaad00 in https://github.com/msaad00/agent-bom/pull/3377
  • feat(ui): make findings a queue with evidence drawer by @msaad00 in https://github.com/msaad00/agent-bom/pull/3378
  • chore(deps): combine UI dependency updates by @msaad00 in https://github.com/msaad00/agent-bom/pull/3381
  • feat(cli): add lane-branded compact output by @msaad00 in https://github.com/msaad00/agent-bom/pull/3382
  • feat(mcp): make server startup workflow-first by @msaad00 in https://github.com/msaad00/agent-bom/pull/3383
  • feat(ui): share pagination controls across list pages by @msaad00 in https://github.com/msaad00/agent-bom/pull/3384
  • feat(ui): expose older security graph snapshots by @msaad00 in https://github.com/msaad00/agent-bom/pull/3385
  • fix(ui): route insights to dashboard analytics by @msaad00 in https://github.com/msaad00/agent-bom/pull/3386
  • feat(ui): page the attack-path queue by @msaad00 in https://github.com/msaad00/agent-bom/pull/3387
  • feat(cli): page compact findings output by @msaad00 in https://github.com/msaad00/agent-bom/pull/3388
  • feat(cli): compact posture card by default and paged findings by @andres-linero in https://github.com/msaad00/agent-bom/pull/3389
  • feat(ui): add full-canvas graph lens bar by @msaad00 in https://github.com/msaad00/agent-bom/pull/3390
  • fix(ui): standardize offline and empty-state next steps by @msaad00 in https://github.com/msaad00/agent-bom/pull/3391
  • feat(mcp): make runtime startup workflow-first by @msaad00 in https://github.com/msaad00/agent-bom/pull/3392
  • fix(deploy): scope pilot compose to loopback CORS by @msaad00 in https://github.com/msaad00/agent-bom/pull/3393
  • feat(dspm): add opt-in S3 content sampling by @msaad00 in https://github.com/msaad00/agent-bom/pull/3395
  • feat(cloud): surface event posture freshness by @msaad00 in https://github.com/msaad00/agent-bom/pull/3394
  • perf(graph): gate checked-in Postgres scale evidence by @msaad00 in https://github.com/msaad00/agent-bom/pull/3398
  • feat(dspm): add opt-in GCS content sampling by @msaad00 in https://github.com/msaad00/agent-bom/pull/3399
  • feat(cloud): expose multi-cloud side-scan targets by @msaad00 in https://github.com/msaad00/agent-bom/pull/3400
  • perf(graph): cap filtered graph attack paths by @msaad00 in https://github.com/msaad00/agent-bom/pull/3401
  • docs(readme): tighten front door for skimmable onboarding by @msaad00 in https://github.com/msaad00/agent-bom/pull/3404
  • feat(dspm): map content classification into graph risk by @msaad00 in https://github.com/msaad00/agent-bom/pull/3402
  • perf(graph): cap governance payloads by @msaad00 in https://github.com/msaad00/agent-bom/pull/3403
  • feat(cwpp): execute multicloud side-scan lifecycle by @msaad00 in https://github.com/msaad00/agent-bom/pull/3406
  • fix(ui): keep explicit WebGL graph renderer stable by @msaad00 in https://github.com/msaad00/agent-bom/pull/3407
  • docs(hosted): clarify current editions and hosted POC boundaries by @msaad00 in https://github.com/msaad00/agent-bom/pull/3408
  • feat(hosted): close customer-zero readiness loop by @msaad00 in https://github.com/msaad00/agent-bom/pull/3409
  • fix(ci): stabilize large-graph-overview E2E search drilldown by @msaad00 in https://github.com/msaad00/agent-bom/pull/3411
  • feat(ui): findings paging, auth fail-closed, unified runtime by @msaad00 in https://github.com/msaad00/agent-bom/pull/3412
  • fix(ci): clear UI lint errors from #3412 merge by @msaad00 in https://github.com/msaad00/agent-bom/pull/3413
  • fix(ui): hide duplicate headers on unified runtime tabs by @msaad00 in https://github.com/msaad00/agent-bom/pull/3414
  • refactor(output): Finding-native exposure path projection (#2918) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3415
  • refactor(output): Markdown/HTML exposure paths via Finding (#2918 PR-2) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3416
  • refactor(output): SARIF/JSON exposure paths via Finding (#2918 PR-3) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3417
  • refactor(ui): split vulns page and sync filters to URL by @msaad00 in https://github.com/msaad00/agent-bom/pull/3418
  • docs: fix Snowflake connect accuracy, prune orphan docs, restore README product proof by @msaad00 in https://github.com/msaad00/agent-bom/pull/3419
  • chore(deps): consolidate weekly dependency updates by @msaad00 in https://github.com/msaad00/agent-bom/pull/3427
  • chore(release): prepare 0.92.0 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3428

Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.91.0...v0.92.0

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track msaad00/agent-bom

Get notified when new releases ship.

Sign up free

About msaad00/agent-bom

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

All releases →

Beta — feedback welcome: [email protected]