// docs / changelog
سجل التغييرات
FixVibe تحديثات محرك الفحص: تغطية جديدة، وتحسينات في السلامة، وتحسينات في الدقة. أحدث الإدخالات أولا.
September 26, 2026
- محسّنClearer evidence for security header checks. Header checks now capture the response context needed to recheck a supported deployed fix. Unavailable, changed, or blocked responses do not count as proof that an issue is fixed. It also recognizes invalid MIME-sniffing protection values more accurately.
- جديدKnown-vulnerability checks, September 2026. 16 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
9 سبتمبر 2026
- جديدShai-Hulud. تكتشف عمليات فحص مستودعات GitHub الآن أدلة قوية مرتبطة بعودة حملة npm في سبتمبر 2026 من دون تنزيل الحزم أو تشغيلها.
7 سبتمبر 2026
- مُصلحعمليات فحص أكثر موثوقية. أصلحنا مشكلة تعلّق الفحص عند فحص مواقع تُرجع استجابات مضغوطة كبيرة.
- محسّنعمليات فحص أكثر موثوقية. يمكن الآن استئناف عمليات الفحص الكبيرة بأمان دون فقدان النتائج المكتشفة.
2026-08-04
- جديدKnown-vulnerability checks, August 2026. 7 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
21 يوليو 2026
- جديدفحص استشاري لتبعية Next.js WebSocket SSRF. يمكن الآن لعمليات فحص GitHub repo وضع علامة على دليل بيان Next.js وملف القفل المرتبط بـ CVE-2026-44578 / GHSA-c4j6-fc7j-m34r. تظل النتائج مستندة إلى الإصدار، وتشير إلى أن عمليات النشر التي تستضيفها Vercel لم تتأثر، ولا ترسل أبدًا ترقيات WebSocket، أو تستكشف الوجهات الداخلية، أو تطالب بتأكيد SSRF المباشر.
- جديدKnown-vulnerability checks, July 2026. 43 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
13 يوليو 2026
- جديدInjective Labs npm wallet-key stealer advisory check. Repo scans now flag package manifests and lockfiles resolving @injectivelabs/sdk-ts 1.20.21 or related @injectivelabs 1.20.21 packages tied to the compromised SDK. Findings stay version-based: FixVibe does not install packages, execute dependency code, derive wallets, contact exfiltration infrastructure, or claim key theft.
- جديدReact Server Components CVE-2026-23864 advisory check. Repo scans now report npm manifest and lockfile evidence for react-server-dom-webpack, react-server-dom-parcel, or react-server-dom-turbopack versions affected by GHSA-83fc-fqcc-2hmg as version-based advisory context; they do not send crafted RSC requests, probe Server Function endpoints, crash-test services, or claim live denial-of-service confirmation.
2026-07-02
- مُصلحLegal-link false positives reduced. Privacy and terms links that are visible after client-side rendering now count correctly, so SPA footers are not reported as missing when users can see those links.
30 يونيو 2026
- جديدcodfish semantic-release GitHub Action compromise check. Repo scans can now flag workflow YAML references to codfish/semantic-release-action refs associated with the June 2026 compromise, reporting source/config evidence only. The check does not run GitHub Actions, read CI secrets, inspect runners, or claim credential theft.
- جديدKnown-vulnerability checks, June 2026. 67 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
June 18, 2026
- جديدMastra easy-day-js advisory check. GitHub repo scans flag easy-day-js manifest and lockfile evidence tied to the June 2026 Mastra npm incident. The finding stays limited to repository dependency evidence and does not verify stale npm owners, run package scripts, inspect hosts, or assert credential theft.
June 14, 2026
- مُصلحDOM XSS fragment probe stability fix. Verified active scans now skip the DOM fragment probe cleanly when browser automation is unavailable at startup, so reports no longer show internal browser-context errors for that check.
- محسّنExpanded Red Hat npm worm coverage. GitHub repo scans now include additional Wiz-reported @redhat-cloud-services package versions for the Miasma campaign, while still reporting repository dependency evidence without installing packages, executing lifecycle scripts, or claiming credential theft.
- جديدKnown npm typosquat package check. GitHub repo scans can now flag package manifests and lockfiles that resolve Microsoft-reported vpmdhaj npm typosquat package versions, reporting version-based advisory evidence without installing packages, executing lifecycle scripts, fetching tarballs, contacting attacker infrastructure, or claiming credential theft.
- جديدCodex Remote UI token-stealing npm package check. GitHub repo scans can now flag package manifests and lockfiles that resolve codexui-android 0.1.82 or newer, reporting version-based advisory evidence without installing the package, executing it, reading Codex auth files, contacting exfiltration infrastructure, or claiming token theft.
- جديدClaude Code GitHub Action workflow repo check. GitHub repo scans can now flag Claude Code Action workflows with mutable action refs, broad workflow token permissions, or risky access override inputs, reporting workflow YAML evidence without running Actions, executing Claude Code, reading CI secrets, or claiming prompt-injection exploitation.
- جديدNode-gyp / Phantom Gyp npm worm repo check. GitHub repo scans can now flag package manifests or lockfiles that resolve known malicious npm package versions from the binding.gyp supply-chain campaign, or flag matching binding.gyp source evidence, without running npm install, executing node-gyp, downloading tarballs, or claiming credential theft.
June 11, 2026
- جديدTanStack ArkType adapter malware dependency check. GitHub repo scans can now flag package manifests and lockfiles that resolve @tanstack/arktype-adapter to malicious versions 1.166.12 or 1.166.15 from CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx, reporting version-based advisory evidence without running npm install, executing lifecycle scripts, downloading tarballs, or claiming credential theft.
- جديدRed Hat npm worm dependency advisory check. GitHub repo scans can now flag package manifests and lockfiles that resolve known compromised @redhat-cloud-services npm versions associated with the credential-stealing worm campaign, reporting dependency evidence without executing install scripts or claiming credential theft.
May 27, 2026
- جديدKnown-vulnerability checks, May 2026. 33 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
May 25, 2026
- مُصلحActive scan reliability and SSTI accuracy fix. Active scans now safely store response-derived evidence that contains unsupported control characters, and SSTI reporting requires stronger target-specific template-evaluation evidence instead of common page or static-asset content.
16 May 2026
- جديدActive scans via REST API and MCP. يمكن الآن تشغيل عمليات الفحص النشطة من REST وMCP مقابل النطاقات التي تم التحقق منها والتي تم ترخيصها بشكل صريح من لوحة المعلومات. التفويض قابل للإلغاء في أي وقت.
- جديدSafer authorization levels for active scans. يميز ترخيص النطاق الآن بين عمليات التحقق النشطة الآلية الأكثر أمانًا والاختبار النشط الأعمق، بحيث يمكن للفرق أتمتة المستوى المناسب من التحقق لكل نطاق.
- جديدFirst-use webhook for API/MCP active scans. يمكن لخطاف الويب إخطار الفرق في المرة الأولى التي يتم فيها تشغيل فحص نشط API/MCP-triggered على مجال معتمد حديثًا.
- محسّنImproved Referrer-Policy findings. Missing or weak
Referrer-Policyresults now separate URL-referrer leakage from broad information exposure, show document-response evidence, and include generic plus static-host remediation guidance. - محسّنImproved Permissions-Policy findings. Missing or weak
Permissions-Policyresults now show feature-level evidence, separate broad feature allowlists from missing hardening, and include generic plus static-host remediation guidance for common hosts, proxies, and app servers. - محسّنImproved clickjacking header prompts. Missing
X-Frame-Optionsfindings now point agents to CSPframe-ancestorsas the modern protection, add Vercel/static SPA header guidance, and verifyx-frame-optionswith CSP. - محسّنCSP header evidence and fix prompts improved. التقارير المفقودة-CSP تتضمن الآن استضافة وسياق استجابة أكثر وضوحًا بالإضافة إلى إرشادات معالجة أكثر أمانًا تعتمد على إطار العمل.
- مُصلحVercel path-probe false positives reduced. FixVibe يتطلب الآن أدلة أقوى خاصة بالتطبيق قبل الإبلاغ عن عناصر إطار العمل المكشوفة في عمليات النشر التي تعيد كتابة مسارات غير معروفة إلى غلاف التطبيق.
- مُصلحلم تعد نتائج الامتثال تحمل علامات CWE مضللة. كان فحص legal-compliance يضع
CWE-359(كشف معلومات شخصية) على نتائج "سياسة خصوصية مفقودة" و"شروط خدمة مفقودة"، وهو ما لا يصف الثغرة الفعلية. تُنشر هذه النتائج الآن بدون CWE — فهي بنود امتثال وليست نقاط ضعف أمنية قابلة للتصنيف.
15 مايو 2026
- جديدRepository secret leak check. GitHub repo scans can now flag hardcoded provider keys and other secrets committed to source, with evidence masked and the standard FixVibe rotation prompt included.
- جديدفحص حماية نشر Vercel. يمكن الآن لعمليات الفحص السلبي وضع علامة على عناوين URL العامة للنشر التي تم إنشاؤها بواسطة
*.vercel.appوالتي تستجيب بدون نشر Vercel Protection، بينما تستمر عمليات فحص الرأس الحالية في تدقيق CSP وHSTS وتصلب المتصفح.
14 مايو 2026
- محسّنFirebase rules detection improved. BaaS تكتشف عمليات الفحص الآن المزيد من أشكال التطبيقات Firebase وتستخدم أدلة للقراءة فقط لتحديد التعرض الخطير للبيانات العامة.
13 مايو 2026
- جديدRepo Supabase RLS migration check. GitHub يمكن لعمليات فحص الريبو الآن وضع علامة على Supabase SQL عمليات الترحيل التي تنشئ جداول عامة بدون بيان
ALTER TABLE ... ENABLE ROW LEVEL SECURITYمطابق. - جديدSupabase Storage posture check. يمكن لعمليات الفحص السلبي الآن مراجعة مجموعات التخزين العامة Supabase والتعرض لقائمة الكائنات المجهولة جنبًا إلى جنب مع RLS وعمليات التحقق الرئيسية.
- جديدAI-generated code guardrail check. GitHub يمكن لعمليات فحص الريبو الآن وضع علامة على أتمتة الأمان المفقودة حول فحص التعليمات البرمجية، والمسح السري، وتحديثات التبعية، وتعليمات الوكيل AI-.
12 مايو 2026
- جديدRepo web-app risk checklist. GitHub يمكن لعمليات فحص الريبو الآن وضع علامة على مخاطر التعليمات البرمجية ذات النمط OWASP- عالية الثقة مثل الاستيفاء الأولي SQL، والمصارف غير الآمنة HTML، وأحرف البدل المعتمدة CORS، والتحقق المعطل TLS، والتراجعات السرية الضعيفة JWT.
- جديدNext.js middleware-bypass check. يمكن لعمليات الفحص النشطة للنطاقات التي تم التحقق منها الآن تأكيد التعرض CVE-2025-29927 للمسارات المحمية بالبرامج الوسيطة قبل الإبلاغ عنها، وتتضمن التقارير معيار FixVibe AI مطالبة الإصلاح للمعالجة.
9 مايو 2026
- أمانCross-origin scope hardening. تظل عمليات الفحص النشطة والتحقق من أصول العميل الآن ضمن النطاق المستهدف المعتمد وتجنب حمل بيانات الاعتماد المقدمة من العميل عبر عمليات إعادة التوجيه عبر الأصل.
- مُصلحSupabase RLS check is now strictly read-only. Supabase تتجنب عمليات التحقق من الوضعية الآن محاولات الكتابة والتركيز على إشارات التعرض الآمن. يظل الاختبار النشط للنطاق الذي تم التحقق منه هو الحد الأقصى للتأكيد الأعمق.
- محسّننتائج ترويسات الأمان تنطبق فقط على استجابات HTML الجذرية. لم يعد غياب CSP أو Permissions-Policy أو X-Frame-Options أو Referrer-Policy على 204 أو JSON API أو تنزيل ملف أو 404 ينتج نتيجة. ما زال HSTS وX-Content-Type-Options يقيّمان عبر كل الاستجابات.
- محسّنAuth-flow and rate-limit checks now require stronger evidence. FixVibe يبلغ الآن عن هذه المشكلات فقط عندما يدعم سلوك التطبيق الاكتشاف بشكل واضح، مما يقلل التشويش الناتج عن صفحات الخطأ العامة والأساليب غير المدعومة.
- محسّنFile-upload findings tier by exploitability evidence. تعمل تقارير تحميل الملفات الآن على فصل إشارات قبول الثقة المنخفضة عن الأدلة القوية على سلوك العرض المحفوف بالمخاطر، مما يقلل من الخطورة المفرطة على معالجات التحميل الحميدة.
7 مايو 2026
- مُصلحThreat-intel listing accuracy improved. FixVibe يميز الآن بين أدلة القائمة المحظورة الحقيقية وتشخيصات المحلل بحيث لا تفرط نتائج المعلومات المتعلقة بالتهديدات في الإبلاغ عن استجابات البحث من جانب البنية التحتية.
- جديدفحوص مستودعات GitHub. وصّل مستودعًا وسيفحص FixVibe المصدر بحثًا عن مفاتيح خدمة Supabase المسربة، ورموز Firebase admin، وملفات workflow الخطرة، والاعتماديات القديمة — من دون تحميل موقعك المنشور أبدًا. راجع أنواع الفحص.
- جديدفحوص SAST لـ JavaScript الخطرة. تضع فحوص المستودعات الآن علامة على
new Function()وsetTimeout("string")— وكلاهما مكافئ لـeval()عند تغذيته بإدخال غير موثوق. - مُصلحنتائج “ملف مكشوف” الكاذبة على مواقع Vercel / Cloudflare. لم تعد استجابات
403 Forbiddenالمجردة تُبلّغ على أنها “الملف موجود” — فمعظم مزودي الحافة يعيدون 403 للمسارات التي تبدو مريبة سواء كان الملف موجودًا أم لا. نطلب الآن إشارة HTTP إيجابية قبل الإشارة. - مُصلحRepo-code false positives reduced. تتجنب عمليات فحص Repo الآن وضع علامة على مصطلحات الأمان في التعليقات والوثائق ومساعدي الاختبار وسياقات الخادم فقط بشكل واضح لإجراء العديد من عمليات التحقق من رموز الإشارة العالية.
- مُصلحمفتاح Supabase anon في localStorage لم يعد يُبلغ كوثيقة JWT-in-storage — فمفتاح anon هو رمز العميل العام المقصود. رموز service-role الحقيقية في تخزين المتصفح أصبحت الآن حرجة بعنوان أوضح.
- مُصلحCSP weakness detection improved. Content-Security-Policy تكتشف عمليات التحقق الآن سياسات المصدر الأكثر تساهلاً مع الحفاظ على تركيز الأدلة والمعالجة على سياسة المتصفح الفعالة.
- مُصلحReflected-XSS check tightened. تتطلب عمليات الفحص النشطة الآن أدلة انعكاس أقوى قبل الإبلاغ عن مخاطر السياق القابل للتنفيذ، مما يقلل النتائج الإيجابية الخاطئة من العلامات غير ذات الصلة على الصفحة.
- مُصلحيتعامل تحقق النطاق مع عمليات إعادة التوجيه بين apex ↔ www بشكل صحيح، ويوضح أكثر أي قيمة تُوضع في حقل Host لسجل TXT.
الصيغة
كل إدخال موسوم حتى تتمكن من المسح سريعًا:
- جديد فحص أو سطح أو ميزة جديدة.
- محسّن سلوك موجود أصبح أفضل — أدق أو أسرع أو أوضح.
- مُصلح خطأ شحنّاه ثم أصلحناه.
- أمان تقوية أو إصلاحات ثغرات أو تغييرات امتثال.
رأيت شيئًا انكسر وليس مسجلًا هنا؟ راسل support@fixvibe.app.
