kit 5.23.0
Changed
- bumblebee pin bumped 0.1.1 → 0.1.2, with the digests verified by download rather than
copied. All four release tarballs were fetched and their SHA-256 recomputed against the
release'schecksums.txt(4/4 match); v0.1.1's published checksums were also confirmed to
equal the digests already embedded here, cross-validating the source.- Threat intel: 6 → 11 catalogs, newest authoring date 2026-05-18 → 2026-06-18
(65 → 38 days, under the 60-day staleness threshold, so the advisory clears). Adds
glassworm,trapdoor-crypto-stealer,mastra-2026-06-17,laravel-lang-2026-05-23,
mini-shai-hulud-redhat-cloud-services. - Inventory coverage widens into kit's own domain: an
agent-skillecosystem
(skills.sh / vercel-labs lock files, including the project-localskills-lock.jsonkit
already manages),homebrewinstall receipts, and~/.claude.jsonMCP parsing for
Claude Code's user- and project-scoped servers.
- Threat intel: 6 → 11 catalogs, newest authoring date 2026-05-18 → 2026-06-18
Fixed
- Corrected the 5.22.0 claim that a newer bumblebee release brings no fresher threat
intel. It does here. The error was methodological and is now recorded in
bumblebee-update.tsso it is not repeated: the six pre-existing catalogs are
byte-identical across the two tags, andraw.githubusercontent.comcannot list a
directory — so comparing only the filenames already known makes five ADDED catalogs
invisible and looks like "nothing changed". Compare the release tarball, not a guessed
file list. The suggestion text no longer asserts either direction: whether a bump
refreshes the catalogs depends on the release, so it points at the evidence instead.
Full changelog: https://github.com/sandstream/kit/blob/v5.23.0/CHANGELOG.md
Verify this release:
git tag -v v5.23.0
npm audit signatures