This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summaryUpdates affect runtime, cloud services, CI pipelines, documentation, database migrations, dependencies, UI, and release tooling.
Full changelog
What's Changed
- docs(perf): gateway relay baseline and Go-gate measurement by @msaad00 in https://github.com/msaad00/agent-bom/pull/4424
- feat(runtime): extract gateway pure-relay contract (Phase 2) by @msaad00 in https://github.com/msaad00/agent-bom/pull/4425
- feat(runtime): Go gateway-relay sidecar spike (Phase 3) by @msaad00 in https://github.com/msaad00/agent-bom/pull/4427
- fix(cloud): align Connections org copy and Helm fan-out flags by @msaad00 in https://github.com/msaad00/agent-bom/pull/4428
- feat(runtime): event-collector Go Phase 1 stub and contract by @msaad00 in https://github.com/msaad00/agent-bom/pull/4429
- fix(ci): cancel superseded required runs promptly by @msaad00 in https://github.com/msaad00/agent-bom/pull/4432
- feat(cloud): Connections org fan-out on scan by @msaad00 in https://github.com/msaad00/agent-bom/pull/4430
- fix(demo): persist findings with migrated postgres by @msaad00 in https://github.com/msaad00/agent-bom/pull/4433
- feat(cloud): Connections continuous scan stack by @msaad00 in https://github.com/msaad00/agent-bom/pull/4431
- feat(cloud): Connections scheduler drain concurrency by @msaad00 in https://github.com/msaad00/agent-bom/pull/4437
- feat(cloud): Connections continuous wizard and CLI parity by @msaad00 in https://github.com/msaad00/agent-bom/pull/4442
- fix(ci): treat blank surface-freshness env vars as unset by @msaad00 in https://github.com/msaad00/agent-bom/pull/4444
- chore(deps): combine dependency updates (2026-07-24) by @andres-linero in https://github.com/msaad00/agent-bom/pull/4441
- fix(docs): split AppSec and GRC persona cards by @msaad00 in https://github.com/msaad00/agent-bom/pull/4446
- chore(ci): combine readme quick start and CI test timing fixes by @msaad00 in https://github.com/msaad00/agent-bom/pull/4449
- fix(docs): correct SECURITY.md CSP claim for the UI preview config by @msaad00 in https://github.com/msaad00/agent-bom/pull/4450
- fix(cloud): bind tenant context and sanitize scheduler scan failures by @msaad00 in https://github.com/msaad00/agent-bom/pull/4452
- fix(db): add Connections scope and scan-mode columns to the Postgres migration authority by @msaad00 in https://github.com/msaad00/agent-bom/pull/4451
- fix(deploy): bundle the dashboard in the API image and make the airgap profile render by @msaad00 in https://github.com/msaad00/agent-bom/pull/4453
- fix(ui): fit and theme the exposure-path board without hiding tool and credential hops by @msaad00 in https://github.com/msaad00/agent-bom/pull/4454
- fix(deps): replace vulnerable brace-expansion dependency line by @msaad00 in https://github.com/msaad00/agent-bom/pull/4458
- fix(ci): run the Postgres contract job for scheduler and ingest changes by @msaad00 in https://github.com/msaad00/agent-bom/pull/4455
- fix(sarif): carry advisory description and remediation into exported rules by @msaad00 in https://github.com/msaad00/agent-bom/pull/4456
- fix(release): align collector, scheduler, and public proof contracts by @msaad00 in https://github.com/msaad00/agent-bom/pull/4461
- fix(cli): normalize scan push URL and give the gateway a runnable first command by @msaad00 in https://github.com/msaad00/agent-bom/pull/4460
- fix(cloud): make connection scope authoritative and secure collector forwarding by @msaad00 in https://github.com/msaad00/agent-bom/pull/4459
- fix(tests): restore full-suite lint compliance by @msaad00 in https://github.com/msaad00/agent-bom/pull/4462
- chore(release): prepare 0.98.0 by @msaad00 in https://github.com/msaad00/agent-bom/pull/4463
Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.97.5...v0.98.0
Security Fixes
- Replace vulnerable brace-expansion dependency
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About msaad00/agent-bom
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Related context
Related tools
Beta — feedback welcome: [email protected]