This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryAdded cloud hierarchy OWNERS and EXPOSED_TO network paths, introduced API anonymous viewer opt‑in, and fixed deploy native‑app install blockers.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Adds opt‑in anonymous viewer alongside configured credentials for API. Adds opt‑in anonymous viewer alongside configured credentials for API. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Low |
Rolls up account→resource ownership in organization hierarchy for cloud module. Rolls up account→resource ownership in organization hierarchy for cloud module. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Low |
Completes live EXPOSED_TO network paths in cloud module. Completes live EXPOSED_TO network paths in cloud module. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Low |
Adds network entry EXPOSED_TO paths for cloud. Adds network entry EXPOSED_TO paths for cloud. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Feature | Low |
Introduces cross‑account inventory with toxic and fusion handling for cloud. Introduces cross‑account inventory with toxic and fusion handling for cloud. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Dependency | Low |
Combines compatible July 9 dependency updates. Combines compatible July 9 dependency updates. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Dedupes CIS checks per scan and surfaces persist failures in API. Dedupes CIS checks per scan and surfaces persist failures in API. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Resolves SPCS native‑app install blockers and hardens deployment process. Resolves SPCS native‑app install blockers and hardens deployment process. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Improves sign‑in screen to be clean and actionable in UI. Improves sign‑in screen to be clean and actionable in UI. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Improves pre‑release graph accuracy and hardens anonymous viewer in API/deploy. Improves pre‑release graph accuracy and hardens anonymous viewer in API/deploy. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
Full changelog
What's Changed
- feat(cloud): roll up account→resource OWNS in org hierarchy (#3742 PR 1) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3743
- feat(cloud): complete live EXPOSED_TO network paths (#3742 PR 2) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3744
- fix(api): dedupe CIS checks per scan and surface persist failures by @msaad00 in https://github.com/msaad00/agent-bom/pull/3746
- fix(deploy): SPCS native-app install blockers + deploy hardening by @msaad00 in https://github.com/msaad00/agent-bom/pull/3747
- fix(ui): clean, actionable sign-in screen by @msaad00 in https://github.com/msaad00/agent-bom/pull/3748
- feat(api): opt-in anonymous viewer alongside configured credentials by @msaad00 in https://github.com/msaad00/agent-bom/pull/3749
- chore(deps): combine compatible July 9 dependency updates by @msaad00 in https://github.com/msaad00/agent-bom/pull/3758
- feat(cloud): network entry EXPOSED_TO paths (#3742 PR 4) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3759
- feat(cloud): cross-account inventory → toxic + fusion (#3742 PR 5) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3760
- fix: pre-release graph-accuracy + anonymous-viewer hardening by @msaad00 in https://github.com/msaad00/agent-bom/pull/3761
- docs(readme): fold intro, Quickstart next, Snowflake vendor lockup by @msaad00 in https://github.com/msaad00/agent-bom/pull/3763
- chore(release): 0.94.2 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3762
Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.94.1...v0.94.2
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About msaad00/agent-bom
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Related context
Related tools
Beta — feedback welcome: [email protected]