Repository navigation
v2026.1006.1
·
38 commits
to main
since this release
Vibgrate CLI 2026.1006.1
Released 2026-10-06
This release of the Vibgrate CLI includes several improvements to documentation and functionality, particularly around scanning and SBOM exports. Notably, it enhances the clarity of GitHub Actions integration and addresses various issues related to dependency handling.
What changed
Improved
- GitHub Actions examples now clarify drift gate job failures, warn mode behavior, version pinning, and DriftScore badge display.
vg scan --vulnsdocumentation now details matching of Go pseudo-versions and+incompatibleversions against a local advisory manifest.- Documentation for
vg sbomandscanJSON now specifies fields that identify a component, clarifying matching criteria. vg scandocumentation now explains how.tfand.tofufiles are processed, noting limitations in scoring Terraform provider and module drift.- Documentation for
vg sbom exportnow maps dependency types to CycloneDX and SPDX fields, detailing omitted fields. - The CLI reference now describes how
vg sbom exportsets CycloneDX component type and omits SPDXprimaryPackagePurpose.
Changed
- After an interactive scan, Vibgrate now displays the biggest drift driver and offers a way to scan every pull request with
vg init --ci github. - The Vibgrate GitHub Action introduces a max-score input that fails the job if the DriftScore exceeds a specified budget.
Fixed
vg sbom exportnow includes each dependency's declared license in output formats, reporting unrepresentable licenses on components.vg scanandvg buildnow stop with a clear error for invalid paths, requiring users to narrow the path or adjust file budget settings.vg scanno longer misinterprets placeholder npm versions as the latest release, skipping dependencies with non-real major-version gaps.
Benchmarks
Two-arm benchmark of this release against 2026.1005.1, interleaved on one runner against the pinned corpus (236 metrics compared).
| Metric | Previous | This release |
|---|---|---|
| Languages with extraction | 19 count | 19 count |
| Definitions extracted (corpus total) | 26573 count | 26573 count |
| Call edges extracted (corpus total) | 18969 count | 18969 count |
| Locate accuracy (top-1) | 0.94 ratio | 0.94 ratio |
| Dependency detection (authored manifest truth) | 0.96 ratio | 0.96 ratio |
| CLI startup (--version, median) | 791 ms | 792.70 ms |
2 regression(s) — published, not omitted:
- Agent tokens with vg (comparable tasks, total): 578766 → 636808 (10.0%)
- Tool calls per task with vg (median, comparable tasks): 6 → 7 (16.7%)
Full report and methodology: https://vibgrate.com/cli/benchmarks
Install or update
npm install -g @vibgrate/cli
vgFull changelog: https://vibgrate.com/changelog/cli/2026.1006.1