This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Affected surfaces
Summary
AI summaryUpdates audits, demo, and deps across a mixed release.
Full changelog
What's Changed
- ci(release): enforce version alignment across all deploy surfaces + fix 0.97.0 drift by @msaad00 in https://github.com/msaad00/agent-bom/pull/4332
- docs(audits): persona progress audit v0.93.5 → v0.97.1 by @msaad00 in https://github.com/msaad00/agent-bom/pull/4333
- fix(demo)+feat(attest,graph): harden demo path, MCP attest CLI, store-backed auto-enable by @msaad00 in https://github.com/msaad00/agent-bom/pull/4336
- chore(deps): batch UI + actions dependency bumps by @msaad00 in https://github.com/msaad00/agent-bom/pull/4345
- fix(deploy)+feat(auth): self-host first-run bootstrap, anonymous demo, and guided OIDC/SSO setup by @msaad00 in https://github.com/msaad00/agent-bom/pull/4335
- fix(helm): make control-plane self-host come up cleanly on first install by @msaad00 in https://github.com/msaad00/agent-bom/pull/4337
- fix(mcp,audit): align tool-count honesty and rich audit exit codes by @msaad00 in https://github.com/msaad00/agent-bom/pull/4346
- chore(release): prepare 0.97.2 by @msaad00 in https://github.com/msaad00/agent-bom/pull/4347
Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.97.1...v0.97.2
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About msaad00/agent-bom
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Related context
Related tools
Beta — feedback welcome: [email protected]