Skip to content

msaad00/agent-bom

v0.97.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-agents ai-security ai-supply-chain aibom blast-radius cloud-security
+14 more
compliance container-security cyclonedx security kubernetes llm-security mcp mcp-server owasp sarif sbom security-scanner supply-chain-security vulnerability-scanning

Affected surfaces

auth deps

Summary

AI summary

Added an opt‑in store‑backed producer to the graph module, bound API keys to a stable principal ID in auth, and preserved finding and coverage parity in output.

Full changelog

What's Changed

  • test(auth): pin the auth posture 401/403/200 contract matrix by @msaad00 in https://github.com/msaad00/agent-bom/pull/4311
  • feat(auth): bind API keys to a stable principal id for id-based deprovision (closes #4274) by @msaad00 in https://github.com/msaad00/agent-bom/pull/4315
  • fix(deploy): make Helm defaults self-consistent by @msaad00 in https://github.com/msaad00/agent-bom/pull/4316
  • docs(parity): align release surfaces and personas by @msaad00 in https://github.com/msaad00/agent-bom/pull/4317
  • fix(check): fail closed on ambiguous package input by @msaad00 in https://github.com/msaad00/agent-bom/pull/4318
  • fix(output): preserve finding and coverage parity by @msaad00 in https://github.com/msaad00/agent-bom/pull/4319
  • perf(output)+fix(graph,deps): finding-projection reuse, graph edge/mutation bounds, brace-expansion CVE fix by @msaad00 in https://github.com/msaad00/agent-bom/pull/4323
  • fix(graph): publish bounded response completeness by @msaad00 in https://github.com/msaad00/agent-bom/pull/4325
  • docs(gateway): align runtime example with shipped CLI by @msaad00 in https://github.com/msaad00/agent-bom/pull/4327
  • feat(graph): add opt-in store-backed producer by @msaad00 in https://github.com/msaad00/agent-bom/pull/4326
  • fix(deploy): bound cloud scans and provision graph workspace by @msaad00 in https://github.com/msaad00/agent-bom/pull/4328
  • fix(output): publish advisory and asset identity contracts by @msaad00 in https://github.com/msaad00/agent-bom/pull/4329
  • fix(graph): honor mounted Postgres workspace secrets by @msaad00 in https://github.com/msaad00/agent-bom/pull/4330
  • chore(release): prepare 0.97.1 by @msaad00 in https://github.com/msaad00/agent-bom/pull/4331

Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.97.0...v0.97.1

Security Fixes

  • graph: fixed brace-expansion CVE

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track msaad00/agent-bom

Get notified when new releases ship.

Sign up free

About msaad00/agent-bom

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

All releases →

Beta — feedback welcome: [email protected]