Skip to content

Release history

msaad00/agent-bom releases

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

All releases

106 shown

Review required
v0.88.5 New feature
Auth RBAC Breaking upgrade

UI, onboarding, gateway, findings, observability, graph, hardening, deps, runtime

Review required
v0.88.4 Mixed
Auth Breaking upgrade

Scope catalog + registry + TS SDK

Review required
v0.88.3 New feature
Auth Dependencies

mcp, intel, sdk, api, connectors

No immediate action
v0.88.1 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.87.1 New feature

runtime, api, intel, ci, product

Upgrade now
v0.87.0 Breaking risk
Dependencies

Cryptography core dependency

Upgrade now
v0.86.5 Maintenance
Dependencies

Routine maintenance and dependency updates.

Review required
v0.86.2 Maintenance
Auth RBAC

Routine maintenance and dependency updates.

No immediate action
v0.86.1 New feature

Gateway guard hardening

No immediate action
v0.85.0 New feature

Inter-agent firewall foundation

No immediate action
v0.84.6 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.84.5 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.84.4 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.84.0 Bug fix

Unified findings rendering

Config change
v0.83.4 Breaking risk
Auth

Auth for remote HTTP

No immediate action
v0.83.3 Bug fix

Package inventory schema fixed

No immediate action
v0.83.2 Maintenance

Routine maintenance and dependency updates.

Upgrade now
v0.82.3 New feature
Dependencies

Graph‑walk reachability

No immediate action
v0.82.2 Bug fix

Arm64 UI image fix

Review required
v0.82.1 Breaking risk
Auth RBAC Dependencies

Next 16 export fix

Review required
v0.81.3 Maintenance
Auth Breaking upgrade

Routine maintenance and dependency updates.

Review required
v0.81.1 Breaking risk
Auth RBAC

Tenant-scoped gateway routing

No immediate action
v0.81.0 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.80.1 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.80.0 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.78.1 Maintenance

Routine maintenance and dependency updates.

Review required
v0.78.0 New feature
Auth RBAC Dependencies

tenant_id column

No immediate action
v0.76.4 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.76.2 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.76.1 Maintenance

Routine maintenance and dependency updates.

Review required
v0.76.0 Bug fix
Dependencies Auth RBAC +1 more

Scanner state & cache fix

Review required
v0.75.15 New feature
Auth RBAC

PostgreSQL RLS slice + API features

Review required
v0.75.14 Breaking risk
Auth Dependencies

Railway bearer token required

Review required
v0.75.13 New feature
Auth Breaking upgrade

Guided remediation

No immediate action
v0.75.12 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.75.11 New feature

CWE impact classification

No immediate action
v0.75.10 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.75.9 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.75.8 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.75.7 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.75.6 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.75.3 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.75.2 Bug fix

Offline behavior fixes

Monitor
v0.75.1 Security relevant

Security hardening

Review required
v0.75.0 New feature
Auth RBAC

Dashboard UX improvements

Review required
v0.74.1 Security relevant

Security hardening

No immediate action
v0.74.0 Breaking risk

CLI refactor + PCI DSS compliance

Review required
v0.72.0 New feature

IaC & K8s rule expansion

Upgrade now
v0.71.4 Mixed
Dependencies

Pipeline fixes + pip CVE upgrades

Review required
v0.71.3 Security relevant
Dependencies Breaking upgrade

OS CVE patches + attestations

Review required
v0.71.2 Mixed
Auth Dependencies

Auto‑scan containers

No immediate action
v0.71.1 Breaking risk

ToolHive removal + OS scan

No immediate action
v0.71.0 New feature

Focused scans + Cloud commands

No immediate action
v0.70.12 Bug fix

CVSS capture for basic scan severity

No immediate action
v0.70.11 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.70.10 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.70.9 New feature

native‑first scanning

No immediate action
v0.70.8 New feature

Blast radius + OS package scans

No immediate action
v0.70.7 Breaking risk

AI scanning + DeepSeek + outputs

No immediate action
v0.70.6 Breaking risk

Severity default mapping

Review required
v0.70.5 Security relevant
Auth Dependencies

Credential security hardening

Review required
v0.70.4 Security relevant
Dependencies

Vuln DB hardening

No immediate action
v0.70.3 New feature

Unified Finding model

No immediate action
v0.70.0 New feature

Runtime resolvers + scanner robustness

No immediate action
v0.69.1 Maintenance

Routine maintenance and dependency updates.

Review required
v0.68.2 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.68.1 Maintenance

Routine maintenance and dependency updates.

Review required
v0.68.0 New feature
Auth RBAC

Security‑blocked servers

No immediate action
v0.67.0 Maintenance

Routine maintenance and dependency updates.

Review required
v0.66.0 Security relevant

Security hardening

No immediate action
v0.65.0 Breaking risk

Native OCI layer parser

Config change
v0.64.0 Breaking risk
Auth

Zero‑trust auth model

Review required
v0.63.2 New feature
Auth

Zero‑trust auth model

No immediate action
v0.63.1 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.63.0 New feature

Weekly lock upgrades + AI/GPU scanners

No immediate action
v0.62.1 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.62.0 New feature

Graph export + OIDC/SAML

No immediate action
v0.60.2 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.60.1 Breaking risk

_meta.tools removal

No immediate action
v0.60.0 New feature

MAESTRO tagging + vector DB scanning

Review required
v0.59.3 Security relevant
Auth RBAC

Audit & security fixes

No immediate action
v0.59.2 Maintenance

Routine maintenance and dependency updates.

Review required
v0.59.1 Bug fix
Auth RBAC

Audit backlog fixes

No immediate action
v0.59.0 Security relevant

Security hardening

Review required
v0.58.1 Security relevant

ClawHub trust hardening

No immediate action
v0.57.0 New feature

fleet_scan

No immediate action
v0.56.0 New feature

CVE enrichment

No immediate action
v0.55.0 New feature

--self-scan + Streamlit dashboard

No immediate action
v0.54.0 New feature

ClickHouse + CIS benchmarks

No immediate action
v0.51.0 New feature

AI Assistant + MCP client

Upgrade now
v0.50.0 Maintenance

Version bump

Review required
v0.38.1 New feature
RBAC

Enterprise security gaps

Review required
v0.38.0 New feature
Dependencies Breaking upgrade

Posture scorecard + PG coverage

No immediate action
v0.36.1 New feature

Alert pipeline + runtime protection

Review required
v0.36.0 Mixed
Auth RBAC Breaking upgrade

Security hardening + fleet sync

No immediate action
v0.35.0 New feature

Phase 2 APIs + lineage graph + Snowflake features

No immediate action
v0.34.0 New feature

OWASP MCP Top 10 mapping

No immediate action
v0.33.0 New feature

Enforcement engine

No immediate action
v0.32.0 New feature

New MCP tools, resources, discovery clients

No immediate action
v0.31.9 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.31.8 Maintenance

Routine maintenance and dependency updates.

No immediate action
v0.31.7 New feature

verify command

No immediate action
v0.31.6 New feature

ClawHub‑style trust scanner

No immediate action
v0.31.5 New feature

Supply chain visualization + Docker hardening

No immediate action
v0.31.4 Bug fix

ClawHub trust fix

Review required
v0.31.3 Security relevant
Auth RBAC

ClawHub trust hardening

Beta — feedback welcome: [email protected]