Skip to content

msaad00/agent-bom

v0.97.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-agents ai-security ai-supply-chain aibom blast-radius cloud-security
+14 more
compliance container-security cyclonedx security kubernetes llm-security mcp mcp-server owasp sarif sbom security-scanner supply-chain-security vulnerability-scanning

Affected surfaces

auth rbac

Summary

AI summary

Refactored the API's auth resolution pipeline, fixed boot-time DB preflight for non‑superusers, and added random‑access reads plus a store‑backed UnifiedGraph export to the graph module.

Full changelog

What's Changed

  • refactor(api): consolidate auth resolution into one resolve_principal pipeline (#4274) by @msaad00 in https://github.com/msaad00/agent-bom/pull/4290
  • fix(auth): boot-time non-superuser DB preflight; guard the audit fork-guard index by @msaad00 in https://github.com/msaad00/agent-bom/pull/4292
  • fix(audit): select the audit chain head by chain link, not timestamp by @msaad00 in https://github.com/msaad00/agent-bom/pull/4293
  • feat(graph): random-access reads for the graph build workspace by @msaad00 in https://github.com/msaad00/agent-bom/pull/4295
  • chore(deps): consolidate weekly dependency and registry updates by @msaad00 in https://github.com/msaad00/agent-bom/pull/4301
  • fix(output): harden evidence exports and graph rendering by @msaad00 in https://github.com/msaad00/agent-bom/pull/4302
  • fix(runtime): close matching and Postgres correctness gaps by @msaad00 in https://github.com/msaad00/agent-bom/pull/4303
  • feat(graph)+fix(export): store-backed UnifiedGraph (unwired) and unified-type parquet/lake export by @msaad00 in https://github.com/msaad00/agent-bom/pull/4308
  • fix(security): auth posture single-source + OIDC-invalid decision; legacy audit-checkpoint backfill by @msaad00 in https://github.com/msaad00/agent-bom/pull/4309
  • chore(release): prepare 0.97.0 by @msaad00 in https://github.com/msaad00/agent-bom/pull/4310

Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.96.4...v0.97.0

Security Fixes

  • Auth posture single‑source and OIDC‑invalid decision handling; legacy audit‑checkpoint backfill improves security

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track msaad00/agent-bom

Get notified when new releases ship.

Sign up free

About msaad00/agent-bom

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

All releases →

Beta — feedback welcome: [email protected]