Skip to content

v2026.1006.1

Choose a tag to compare

@github-actions github-actions released this 06 Oct 12:17
· 38 commits to main since this release
d696cdd

Vibgrate CLI 2026.1006.1

Released 2026-10-06

This release of the Vibgrate CLI includes several improvements to documentation and functionality, particularly around scanning and SBOM exports. Notably, it enhances the clarity of GitHub Actions integration and addresses various issues related to dependency handling.

What changed

Improved

  • GitHub Actions examples now clarify drift gate job failures, warn mode behavior, version pinning, and DriftScore badge display.
  • vg scan --vulns documentation now details matching of Go pseudo-versions and +incompatible versions against a local advisory manifest.
  • Documentation for vg sbom and scan JSON now specifies fields that identify a component, clarifying matching criteria.
  • vg scan documentation now explains how .tf and .tofu files are processed, noting limitations in scoring Terraform provider and module drift.
  • Documentation for vg sbom export now maps dependency types to CycloneDX and SPDX fields, detailing omitted fields.
  • The CLI reference now describes how vg sbom export sets CycloneDX component type and omits SPDX primaryPackagePurpose.

Changed

  • After an interactive scan, Vibgrate now displays the biggest drift driver and offers a way to scan every pull request with vg init --ci github.
  • The Vibgrate GitHub Action introduces a max-score input that fails the job if the DriftScore exceeds a specified budget.

Fixed

  • vg sbom export now includes each dependency's declared license in output formats, reporting unrepresentable licenses on components.
  • vg scan and vg build now stop with a clear error for invalid paths, requiring users to narrow the path or adjust file budget settings.
  • vg scan no longer misinterprets placeholder npm versions as the latest release, skipping dependencies with non-real major-version gaps.

Benchmarks

Two-arm benchmark of this release against 2026.1005.1, interleaved on one runner against the pinned corpus (236 metrics compared).

Metric Previous This release
Languages with extraction 19 count 19 count
Definitions extracted (corpus total) 26573 count 26573 count
Call edges extracted (corpus total) 18969 count 18969 count
Locate accuracy (top-1) 0.94 ratio 0.94 ratio
Dependency detection (authored manifest truth) 0.96 ratio 0.96 ratio
CLI startup (--version, median) 791 ms 792.70 ms

2 regression(s) — published, not omitted:

  • Agent tokens with vg (comparable tasks, total): 578766 → 636808 (10.0%)
  • Tool calls per task with vg (median, comparable tasks): 6 → 7 (16.7%)

Full report and methodology: https://vibgrate.com/cli/benchmarks

Install or update

npm install -g @vibgrate/cli
vg

Full changelog: https://vibgrate.com/changelog/cli/2026.1006.1