Skip to content

msaad00/agent-bom

v0.93.5 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-agents ai-security ai-supply-chain aibom blast-radius cloud-security
+14 more
compliance container-security cyclonedx security kubernetes llm-security mcp mcp-server owasp sarif sbom security-scanner supply-chain-security vulnerability-scanning

Summary

AI summary

Updates across ui, output, deploy, runtime, audit, findings, proof, parsers, api, and docs modules.

Full changelog

What's Changed

  • chore(deps): consolidate weekly dependency and registry updates by @msaad00 in https://github.com/msaad00/agent-bom/pull/3600
  • feat(ui): guided demo lock cards on runtime surfaces (Part of #3468) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3602
  • feat(output): svg/html formatter convergence (Part of #2918) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3601
  • feat(ui,deploy): /login + collector mTLS defaults (Part of #3175) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3603
  • refactor(parsers): extract skill metadata checks into skill_audit_metadata by @andres-linero in https://github.com/msaad00/agent-bom/pull/3604
  • refactor(api): split postgres_store into per-store modules by @andres-linero in https://github.com/msaad00/agent-bom/pull/3605
  • feat(ui): rollup-by-default and asset drift lens (Part of #3192) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3606
  • feat(ast,output): PHP/Swift symbol reach and Parquet export (Part of #3499) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3607
  • docs(audit): consolidate epic queue merge state (#3601–#3607) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3611
  • feat(runtime): OIDC discovery shim for legacy IdP MCP interop (Part of #3609) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3612
  • feat(findings): runtime evidence + compliance moat lift (Part of #3608, #3610) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3613
  • fix(scan,output): CLI AST gate + Parquet compliance_tags parity (audit P1/P2) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3614
  • feat(runtime): trace explorer joined to findings and compliance (Part of #3608) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3615
  • feat(ui,graph): runtime evidence overlay badges (Part of #3610) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3616
  • feat(proof): release smoke, demo estate, trust doc, proof-path nav (#3618) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3619
  • docs(deploy): unified install script, quickstart, and intake diagrams by @msaad00 in https://github.com/msaad00/agent-bom/pull/3621
  • fix(audit): P3 login redirect, Swift bare calls, rollup URL persistence by @msaad00 in https://github.com/msaad00/agent-bom/pull/3622
  • feat(scan,docs): GLM/Zhipu inventory + BYOM quickstart (closes #3609 tail) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3623
  • fix(audit): malicious findings stream, COUNT cache, demo hardening, SCIM keys by @msaad00 in https://github.com/msaad00/agent-bom/pull/3624
  • fix(ui): capture hydration + refreshed product-proof screenshots by @msaad00 in https://github.com/msaad00/agent-bom/pull/3625
  • fix(audit): post-3624 follow-up — reachability, demo safety, scale bench by @msaad00 in https://github.com/msaad00/agent-bom/pull/3626
  • chore(release): v0.93.5 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3628
  • fix(pre-release): CI isolation, README SVGs, and UI readability by @msaad00 in https://github.com/msaad00/agent-bom/pull/3629
  • fix(audit): SARIF malware flag on CVE path + PHP heredoc/nowdoc reach masking by @msaad00 in https://github.com/msaad00/agent-bom/pull/3630

Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.93.0...v0.93.5

Security Fixes

  • SARIF malware flag on CVE path + PHP heredoc/nowdoc reach masking in audit

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track msaad00/agent-bom

Get notified when new releases ship.

Sign up free

About msaad00/agent-bom

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

All releases →

Beta — feedback welcome: [email protected]