Skip to content

v2.0.0 — The Vibe Code Edition

Choose a tag to compare

@luisfer luisfer released this 01 Feb 19:10
· 12 commits to main since this release

What's New

Vibe Code Detection — 4 new rules for AI-generated code:

  • VIBE001: Hallucinated imports — packages not in package.json
  • VIBE002: Copy-paste artifacts — repeated code blocks
  • VIBE003: Incomplete implementations — placeholders, stubs
  • VIBE004: Orphaned exports — unused exports

New Features:

  • Security Posture Score (0-100) with visual bar
  • ubon explain <rule> command for detailed rule info
  • --preview-fixes for diff-like fix preview
  • confidenceReason field on all findings
  • All 15 scanners exported for programmatic use
  • Cursor integration (docs/CURSOR.md)

Architecture:

  • Modular security rules (SEC001-SEC017)
  • BaseScanner with caching utilities
  • CLI refactor with shared logic

Bug Fixes:

  • Watch mode debounces rapid file changes
  • Fixed VIBE001 import detection regex
  • Fixed LSP server TextDocumentSyncKind import

See CHANGELOG.md for full details.