Repository navigation
Release notes: Vibgrate CLI 2026.1005.1 — JUnit reports and EPSS/KEV for smarter vuln triage #371
vibgrate-team
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
What's new in 2026.1005.1
Shipped 5 Oct 2026. Full release: https://github.com/vibgrate/cli/releases/tag/v2026.1005.1 · Changelog: https://vibgrate.com/changelog/cli/2026.1005.1
Headline: CI-ready vulnerability output you can actually triage
This cut is about making
vg scanresults easier to act on in CI.vg scan --junit <file>now writes a deterministic JUnit XML report alongside the other formats, so findings show up in the test views your CI already has.--vulns --format jsonadds EPSS score, EPSS percentile and CISA KEV flags when available, so you can sort by "likely to be exploited" rather than just severity. SARIF now writes one result per package and advisory, which makes code-scanning dashboards much less noisy.Baselines got more transparent too:
vg scan --baselinenow records the findings that matched the baseline (with detailed JSON), so you can see what was suppressed and why.Also in this cut
New
vg scan --junit <file>for deterministic JUnit XMLvg scan --vulns --format jsonwhen availablevg scan --baselinerecords baseline-matched findings in JSONvg scan --vulns --offline --package-manifestdocuments the local manifest shape, with stable findings orderDOCS.mdlists command messages and the next command to run for eachImproved
vg sbom exportdocs explain how resolved versions are identifiedFixed
vg scanandvg reportcorrectly show when a vulnerability has a fix availablevversion prefix are handled in the code graphSecurity
Try it
No-install try:
npx @vibgrate/cli scanBenchmarks (honest)
Two-arm benchmark vs
2026.1003.3on the pinned corpus (236 metrics compared). Extraction held steady (19 languages, 26,499 definitions, 18,833 call edges, locate accuracy 0.94, dependency detection 0.96). Startup median ~727 → ~730 ms. Regressions are published, not omitted: agent tokens with vg on comparable tasks rose 578,766 → 636,808 (+10.0%) and median tool calls per task went 6 → 7 (+16.7%). We're looking into both. Details: https://vibgrate.com/cli/benchmarksDiscuss
--junitinto your CI? Tell us which system (GitHub Actions, GitLab, Jenkins…) and whether the report renders the way you'd expect.— maintainers (
vibgrate-team)All reactions