This release includes breaking changes for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
Summary
AI summaryPrivate registry detection now works for pnpm, Yarn Classic, and Bun lockfiles.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Dev dependency labeling added for terminal output and HTML report Dev dependency labeling added for terminal output and HTML report Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Bugfix | Medium |
Private registry detection now works for pnpm, Yarn Classic, and Bun lockfiles Private registry detection now works for pnpm, Yarn Classic, and Bun lockfiles Source: llm_adapter@2026-06-11 Confidence: high |
— |
Full changelog
Added
- Dev dependency labelling: terminal output and HTML report now show
direct · dev/transitive · devfor findings from devDependencies; Yarn Classic and Berry parsers updated to detect dev status yarn-within-rangeanddev-only-findingexample fixtures for regression testing
Fixed
- Private registry detection (
⚠ Unverifiable (private source)) now works for pnpm (legacy and v9), Yarn Classic, and Bun lockfiles — previously only npm was supported
Validation
- npm test
- npm run build
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About OWASP/cve-lite-cli
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]