Message-Authenticator + Mellanox dict
Supply Chain Security
SBOM generation, software signing, policy-as-code, and dependency vulnerability scanning.
Upgrade now
Breaking upgrade
Review required
Auth
SES escalation logic change
v0.11.0
(25d)
SPA probes + CVE engine + Agent loop
No immediate action
Signal handling + completion + grouped help + JSON
v3.1.16
(1mo)
Credential‑required connection strings
v3.1.4
(1mo)
ADD matching, USER/HEALTHCHECK skipping, .env file restriction
v3.0.57
(1mo)
SDK flag removals
v3.0.54
(1mo)
Removed markdown library names
Breaking changes
- Breaking changes to OpenTelemetry support
- Removal of default auxData.jwt.disableVerification configuration value
Notable features
- Permissions advisor workflow
- Path functions added to Cerbos CEL library
- TraceBatch format for compact trace representation
Review required
Auth
RBAC
Dependencies
Next 16 export fix
v3.0.26
(1mo)
VG964 Next.js requirement
Review required
Auth
RBAC
Tenant-scoped gateway routing
No immediate action
Docs: perf claim removal + version table update
v0.4.0
(1mo)
kLayoutVersion bump + policy v6
Review required
Auth
RCE / SSRF
Rate limiter improvement
v3.0.14
(1mo)
GuardVibe npx invocation
v3.0.13
(1mo)
Score includes all sections
v2.9.2
(1mo)
Truncated scan_directory
v2.9.1
(1mo)
compliance_mapping rename
Review required
Auth
Dependencies
Railway bearer token required
Config change
Breaking upgrade
Dependencies
MCP mandatory
Get this as a security brief. Track Supply Chain Security releases straight to your inbox.