Skip to content

v3.1.32

Choose a tag to compare

@goklab goklab released this 06 Jun 17:04
  • Four new CVE rules, all surfaced by the new npm run intel daily gap check: vitest < 4.1.0 UI-server RCE (CVE-2026-47429), @vitest/browser otelCarrier XSS (CVE-2026-47428), liquidjs < 10.26.0 RCE (CVE-2026-45618), tinymce XSS cluster (CVE-2026-47759/60/61/62)
  • Proves the intel -> rule -> gate -> release pipeline end to end; VG1076 already flags a real vulnerable pin (vitest 4.0.8) in a production codebase
  • 433 rules, 67 CVE-version rules; +24 tests; self-audit PASS A 100