Skip to content

msaad00/agent-bom

v0.98.1 Breaking

This release includes 1 breaking change for platform teams planning a safe upgrade.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

ai-agents ai-security ai-supply-chain aibom blast-radius cloud-security
+14 more
compliance container-security cyclonedx security kubernetes llm-security mcp mcp-server owasp sarif sbom security-scanner supply-chain-security vulnerability-scanning

Affected surfaces

auth breaking_upgrade

Summary

AI summary

Updates span deploy, auth, trial, ui, db, cloud, jobs, readme, accuracy, and ticketing modules.

Full changelog

What's Changed

  • fix(deploy): tighten public demo AWS boundary by @msaad00 in https://github.com/msaad00/agent-bom/pull/4464
  • fix(deploy): allow demo redeploy session to complete by @msaad00 in https://github.com/msaad00/agent-bom/pull/4465
  • fix(auth): provision hosted invitations atomically by @msaad00 in https://github.com/msaad00/agent-bom/pull/4466
  • feat(trial): enforce managed AWS guardrails by @msaad00 in https://github.com/msaad00/agent-bom/pull/4467
  • fix(product): align filters, links, metrics, jobs, and telemetry by @msaad00 in https://github.com/msaad00/agent-bom/pull/4468
  • fix(jobs): preserve status counts for legacy responses by @msaad00 in https://github.com/msaad00/agent-bom/pull/4469
  • feat(trial): complete durable execution and tenant lifecycle by @msaad00 in https://github.com/msaad00/agent-bom/pull/4470
  • refactor(ui): simplify workspaces and make graphs interactive by @msaad00 in https://github.com/msaad00/agent-bom/pull/4471
  • fix(db): keep every vulnerable window from multi-branch advisories by @msaad00 in https://github.com/msaad00/agent-bom/pull/4473
  • chore(runtime): retire the Go runtime tier by @msaad00 in https://github.com/msaad00/agent-bom/pull/4474
  • docs(release): refresh product proof and lock release contracts by @msaad00 in https://github.com/msaad00/agent-bom/pull/4475
  • fix(api): keep blocking request work off the event loop by @msaad00 in https://github.com/msaad00/agent-bom/pull/4476
  • fix(scan): match every vulnerable window and stop reading dates as SHAs by @msaad00 in https://github.com/msaad00/agent-bom/pull/4477
  • fix(reachability): match distributions to the import names code uses by @msaad00 in https://github.com/msaad00/agent-bom/pull/4478
  • fix(graph): bound the investigation load and declare what it omits by @msaad00 in https://github.com/msaad00/agent-bom/pull/4479
  • docs(readme): restore the badge row and tighten the hero by @msaad00 in https://github.com/msaad00/agent-bom/pull/4480
  • fix(readme): restore the storefront contract the badge row broke by @msaad00 in https://github.com/msaad00/agent-bom/pull/4483
  • fix(deploy): compose the control-plane database URL in cluster by @msaad00 in https://github.com/msaad00/agent-bom/pull/4481
  • chore(release): target 0.98.1 instead of an unpublished 0.99.0 by @msaad00 in https://github.com/msaad00/agent-bom/pull/4485
  • fix(cloud): gate the routes that spend the platform's own cloud identity by @msaad00 in https://github.com/msaad00/agent-bom/pull/4482
  • docs(readme): restore the MCP tool-count sentence Glama reads by @msaad00 in https://github.com/msaad00/agent-bom/pull/4487
  • perf(jobs): cache the status counts the dashboard polls by @msaad00 in https://github.com/msaad00/agent-bom/pull/4486
  • fix(ui): redact unhandled error boundary messages by @msaad00 in https://github.com/msaad00/agent-bom/pull/4488
  • fix(ticketing): make Postgres schema migration-owned by @msaad00 in https://github.com/msaad00/agent-bom/pull/4489
  • feat(accuracy): measure CVE range matching against advisory ground truth by @msaad00 in https://github.com/msaad00/agent-bom/pull/4491
  • fix(auth): enforce roles in no-auth mode by @msaad00 in https://github.com/msaad00/agent-bom/pull/4490
  • fix(product): canonicalize finding facets and observed metrics by @msaad00 in https://github.com/msaad00/agent-bom/pull/4493
  • refactor(ui): simplify navigation, connect, and scan by @msaad00 in https://github.com/msaad00/agent-bom/pull/4494

Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.98.0...v0.98.1

Breaking Changes

  • Retire the Go runtime tier (chore(runtime))

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track msaad00/agent-bom

Get notified when new releases ship.

Sign up free

About msaad00/agent-bom

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

All releases →

Beta — feedback welcome: [email protected]