Skip to content

msaad00/agent-bom

v0.98.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-agents ai-security ai-supply-chain aibom blast-radius cloud-security
+14 more
compliance container-security cyclonedx security kubernetes llm-security mcp mcp-server owasp sarif sbom security-scanner supply-chain-security vulnerability-scanning

Affected surfaces

deps

Summary

AI summary

Updates affect runtime, cloud services, CI pipelines, documentation, database migrations, dependencies, UI, and release tooling.

Full changelog

What's Changed

  • docs(perf): gateway relay baseline and Go-gate measurement by @msaad00 in https://github.com/msaad00/agent-bom/pull/4424
  • feat(runtime): extract gateway pure-relay contract (Phase 2) by @msaad00 in https://github.com/msaad00/agent-bom/pull/4425
  • feat(runtime): Go gateway-relay sidecar spike (Phase 3) by @msaad00 in https://github.com/msaad00/agent-bom/pull/4427
  • fix(cloud): align Connections org copy and Helm fan-out flags by @msaad00 in https://github.com/msaad00/agent-bom/pull/4428
  • feat(runtime): event-collector Go Phase 1 stub and contract by @msaad00 in https://github.com/msaad00/agent-bom/pull/4429
  • fix(ci): cancel superseded required runs promptly by @msaad00 in https://github.com/msaad00/agent-bom/pull/4432
  • feat(cloud): Connections org fan-out on scan by @msaad00 in https://github.com/msaad00/agent-bom/pull/4430
  • fix(demo): persist findings with migrated postgres by @msaad00 in https://github.com/msaad00/agent-bom/pull/4433
  • feat(cloud): Connections continuous scan stack by @msaad00 in https://github.com/msaad00/agent-bom/pull/4431
  • feat(cloud): Connections scheduler drain concurrency by @msaad00 in https://github.com/msaad00/agent-bom/pull/4437
  • feat(cloud): Connections continuous wizard and CLI parity by @msaad00 in https://github.com/msaad00/agent-bom/pull/4442
  • fix(ci): treat blank surface-freshness env vars as unset by @msaad00 in https://github.com/msaad00/agent-bom/pull/4444
  • chore(deps): combine dependency updates (2026-07-24) by @andres-linero in https://github.com/msaad00/agent-bom/pull/4441
  • fix(docs): split AppSec and GRC persona cards by @msaad00 in https://github.com/msaad00/agent-bom/pull/4446
  • chore(ci): combine readme quick start and CI test timing fixes by @msaad00 in https://github.com/msaad00/agent-bom/pull/4449
  • fix(docs): correct SECURITY.md CSP claim for the UI preview config by @msaad00 in https://github.com/msaad00/agent-bom/pull/4450
  • fix(cloud): bind tenant context and sanitize scheduler scan failures by @msaad00 in https://github.com/msaad00/agent-bom/pull/4452
  • fix(db): add Connections scope and scan-mode columns to the Postgres migration authority by @msaad00 in https://github.com/msaad00/agent-bom/pull/4451
  • fix(deploy): bundle the dashboard in the API image and make the airgap profile render by @msaad00 in https://github.com/msaad00/agent-bom/pull/4453
  • fix(ui): fit and theme the exposure-path board without hiding tool and credential hops by @msaad00 in https://github.com/msaad00/agent-bom/pull/4454
  • fix(deps): replace vulnerable brace-expansion dependency line by @msaad00 in https://github.com/msaad00/agent-bom/pull/4458
  • fix(ci): run the Postgres contract job for scheduler and ingest changes by @msaad00 in https://github.com/msaad00/agent-bom/pull/4455
  • fix(sarif): carry advisory description and remediation into exported rules by @msaad00 in https://github.com/msaad00/agent-bom/pull/4456
  • fix(release): align collector, scheduler, and public proof contracts by @msaad00 in https://github.com/msaad00/agent-bom/pull/4461
  • fix(cli): normalize scan push URL and give the gateway a runnable first command by @msaad00 in https://github.com/msaad00/agent-bom/pull/4460
  • fix(cloud): make connection scope authoritative and secure collector forwarding by @msaad00 in https://github.com/msaad00/agent-bom/pull/4459
  • fix(tests): restore full-suite lint compliance by @msaad00 in https://github.com/msaad00/agent-bom/pull/4462
  • chore(release): prepare 0.98.0 by @msaad00 in https://github.com/msaad00/agent-bom/pull/4463

Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.97.5...v0.98.0

Security Fixes

  • Replace vulnerable brace-expansion dependency

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track msaad00/agent-bom

Get notified when new releases ship.

Sign up free

About msaad00/agent-bom

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

All releases →

Beta — feedback welcome: [email protected]