Skip to content

msaad00/agent-bom

v0.97.5 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-agents ai-security ai-supply-chain aibom blast-radius cloud-security
+14 more
compliance container-security cyclonedx security kubernetes llm-security mcp mcp-server owasp sarif sbom security-scanner supply-chain-security vulnerability-scanning

Affected surfaces

deps

Summary

AI summary

Updates deploy, ui, and deps across a mixed release.

Full changelog

What's Changed

  • fix(deploy): preserve legacy demo overlay before pull by @msaad00 in https://github.com/msaad00/agent-bom/pull/4409
  • chore: drop public co-author deny-list and harden release README by @msaad00 in https://github.com/msaad00/agent-bom/pull/4410
  • fix(deploy): use shipped driver for postgres migrations by @msaad00 in https://github.com/msaad00/agent-bom/pull/4411
  • feat(ui): make context and investigation graphs the canvas hero by @msaad00 in https://github.com/msaad00/agent-bom/pull/4412
  • feat(ui): punchier graph captures and skill capability contracts by @msaad00 in https://github.com/msaad00/agent-bom/pull/4414
  • chore(ops): fail closed on missing UI Hub tag and fix pilot compose by @msaad00 in https://github.com/msaad00/agent-bom/pull/4413
  • feat(ui): distinct graph proof shots and labeled relationships by @msaad00 in https://github.com/msaad00/agent-bom/pull/4415
  • chore(deps): bump aws-actions/configure-aws-credentials from 6.2.2 to 6.2.3 by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/4416
  • chore(deps): bump lucide-react from 1.25.0 to 1.26.0 in /ui by @dependabot[bot] in https://github.com/msaad00/agent-bom/pull/4417
  • fix(deps): bump postcss to 8.5.12 for CVE-2026-45623 by @msaad00 in https://github.com/msaad00/agent-bom/pull/4420
  • fix(deploy): harden EKS reference install path by @msaad00 in https://github.com/msaad00/agent-bom/pull/4421
  • docs(arch): Python-primary runtime; optional Go sidecar later by @msaad00 in https://github.com/msaad00/agent-bom/pull/4423
  • chore(release): 0.97.5 by @msaad00 in https://github.com/msaad00/agent-bom/pull/4422

Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.97.4...v0.97.5

Security Fixes

  • postcss bumped to 8.5.12 — fixes CVE-2026-45623

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track msaad00/agent-bom

Get notified when new releases ship.

Sign up free

About msaad00/agent-bom

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

All releases →

Beta — feedback welcome: [email protected]