// docs / changelog
Changelog
FixVibe scan-engine updates: new coverage, safety improvements, and accuracy improvements. Newest entries first.
September 26, 2026
- IMPROVEDClearer evidence for security header checks. Header checks now capture the response context needed to recheck a supported deployed fix. Unavailable, changed, or blocked responses do not count as proof that an issue is fixed. It also recognizes invalid MIME-sniffing protection values more accurately.
- NEWKnown-vulnerability checks, September 2026. 16 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
September 9, 2026
- NEWShai-Hulud repository checks. GitHub repo scans now flag strong repository evidence tied to the September 2026 npm campaign recurrence without downloading or executing packages.
September 7, 2026
- FIXEDMore reliable scans. Fixed a stall when scanning sites that return large compressed responses.
- IMPROVEDMore reliable scans. Large scans can now resume safely without losing findings.
August 4, 2026
- NEWKnown-vulnerability checks, August 2026. 7 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
July 21, 2026
- NEWNext.js WebSocket SSRF dependency advisory check. GitHub repo scans can now flag Next.js manifest and lockfile evidence associated with CVE-2026-44578 / GHSA-c4j6-fc7j-m34r. Findings remain version-based, state that Vercel-hosted deployments are not affected, and never send WebSocket upgrades, probe internal destinations, or claim live SSRF confirmation.
- NEWKnown-vulnerability checks, July 2026. 43 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
July 13, 2026
- NEWInjective Labs npm wallet-key stealer advisory check. GitHub repo scans can now flag package manifests and lockfiles that resolve @injectivelabs/sdk-ts 1.20.21 or associated @injectivelabs 1.20.21 packages that pinned the compromised SDK, reporting version-based advisory evidence without installing packages, executing them, deriving wallets, contacting exfiltration infrastructure, or claiming key theft.
- NEWReact Server Components dependency advisory check. GitHub repo scans can now flag npm manifests and lockfiles that resolve react-server-dom-webpack, react-server-dom-parcel, or react-server-dom-turbopack versions affected by CVE-2026-23864 / GHSA-83fc-fqcc-2hmg, reporting version-based advisory evidence without sending crafted RSC requests, probing Server Function endpoints, crash-testing services, or claiming live denial-of-service confirmation.
July 2, 2026
- FIXEDLegal-link false positives reduced. Privacy and terms links that appear after client-side rendering now count correctly, so SPA footers are not reported as missing when the links are visible to users.
June 30, 2026
- NEWcodfish semantic-release GitHub Action compromise check. GitHub repo scans can now flag workflow YAML that references codfish/semantic-release-action refs associated with the June 2026 compromise, reporting source/config evidence without running GitHub Actions, reading CI secrets, inspecting runners, or claiming credential theft.
- NEWKnown-vulnerability checks, June 2026. 67 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
June 18, 2026
- NEWMastra npm scope compromise advisory check. GitHub repo scans can now flag npm manifests and lockfiles that resolve easy-day-js versions associated with the June 2026 Mastra supply-chain incident, reporting repository dependency evidence without verifying stale npm owner access, running package scripts, inspecting developer hosts, or claiming credential theft.
June 14, 2026
- FIXEDDOM XSS fragment probe stability fix. Verified active scans now skip the DOM fragment probe cleanly when browser automation is unavailable at startup, so reports no longer show internal browser-context errors for that check.
- IMPROVEDExpanded Red Hat npm worm coverage. GitHub repo scans now include additional Wiz-reported @redhat-cloud-services package versions for the Miasma campaign, while still reporting repository dependency evidence without installing packages, executing lifecycle scripts, or claiming credential theft.
- NEWKnown npm typosquat package check. GitHub repo scans can now flag package manifests and lockfiles that resolve Microsoft-reported vpmdhaj npm typosquat package versions, reporting version-based advisory evidence without installing packages, executing lifecycle scripts, fetching tarballs, contacting attacker infrastructure, or claiming credential theft.
- NEWCodex Remote UI token-stealing npm package check. GitHub repo scans can now flag package manifests and lockfiles that resolve codexui-android 0.1.82 or newer, reporting version-based advisory evidence without installing the package, executing it, reading Codex auth files, contacting exfiltration infrastructure, or claiming token theft.
- NEWClaude Code GitHub Action workflow repo check. GitHub repo scans can now flag Claude Code Action workflows with mutable action refs, broad workflow token permissions, or risky access override inputs, reporting workflow YAML evidence without running Actions, executing Claude Code, reading CI secrets, or claiming prompt-injection exploitation.
- NEWNode-gyp / Phantom Gyp npm worm repo check. GitHub repo scans can now flag package manifests or lockfiles that resolve known malicious npm package versions from the binding.gyp supply-chain campaign, or flag matching binding.gyp source evidence, without running npm install, executing node-gyp, downloading tarballs, or claiming credential theft.
June 11, 2026
- NEWTanStack ArkType adapter malware dependency check. GitHub repo scans can now flag package manifests and lockfiles that resolve @tanstack/arktype-adapter to malicious versions 1.166.12 or 1.166.15 from CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx, reporting version-based advisory evidence without running npm install, executing lifecycle scripts, downloading tarballs, or claiming credential theft.
- NEWRed Hat npm worm dependency advisory check. GitHub repo scans can now flag package manifests and lockfiles that resolve known compromised @redhat-cloud-services npm versions associated with the credential-stealing worm campaign, reporting dependency evidence without executing install scripts or claiming credential theft.
May 27, 2026
- NEWKnown-vulnerability checks, May 2026. 33 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
May 25, 2026
- FIXEDActive scan reliability and SSTI accuracy fix. Active scans now safely store response-derived evidence that contains unsupported control characters, and SSTI reporting requires stronger target-specific template-evaluation evidence instead of common page or static-asset content.
May 16, 2026
- NEWActive scans via REST API and MCP. Active scans can now be triggered from REST and MCP against verified domains that have been explicitly authorized from the dashboard. Authorization is revocable at any time.
- NEWSafer authorization levels for active scans. Domain authorization now distinguishes safer automated active checks from deeper active testing, so teams can automate the right level of verification for each domain.
- NEWFirst-use webhook for API/MCP active scans. A webhook can notify teams the first time an API/MCP-triggered active scan runs against a newly authorized domain.
- IMPROVEDReferrer-Policy findings improved. Missing or weak
Referrer-Policyfindings now distinguish URL-referrer leakage from broader information exposure, include document-response evidence, and provide generic plus static-host fix guidance. - IMPROVEDPermissions-Policy findings improved. Missing or weak
Permissions-Policyfindings now include feature-level evidence, distinguish broad feature allowlists from missing hardening, and provide generic plus static-host fix guidance for Vercel, Netlify, Cloudflare Pages, proxies, and app servers. - IMPROVEDClickjacking header prompts improved. Missing
X-Frame-Optionsfindings now explain that CSPframe-ancestorsis the modern control, include Vercel/static SPA header guidance, and verifyx-frame-optionsalongside CSP. - IMPROVEDCSP header evidence and fix prompts improved. Missing-CSP reports now include clearer hosting and response context plus safer framework-aware remediation guidance.
- FIXEDVercel path-probe false positives reduced. FixVibe now requires stronger application-specific evidence before reporting exposed framework artifacts on deployments that rewrite unknown routes to the app shell.
- FIXEDCompliance findings no longer carry misleading CWE tags. The legal-compliance check previously tagged "missing privacy policy" and "missing terms of service" findings with
CWE-359(PII exposure), which doesn't describe the actual gap. Those findings now ship without a CWE — they're compliance/governance items, not classifiable security weaknesses.
May 15, 2026
- NEWRepository secret leak check. GitHub repo scans can now flag hardcoded provider keys and other secrets committed to source, with evidence masked and the standard FixVibe rotation prompt included.
- NEWVercel deployment protection check. Passive scans can now flag public
*.vercel.appgenerated deployment URLs that respond without Vercel Deployment Protection, while existing header checks continue to audit CSP, HSTS, and browser hardening.
May 14, 2026
- IMPROVEDFirebase rules detection improved. BaaS scans now detect more Firebase app shapes and use read-only evidence to identify risky public data exposure.
May 13, 2026
- NEWRepo Supabase RLS migration check. GitHub repo scans can now flag Supabase SQL migrations that create public tables without a matching
ALTER TABLE ... ENABLE ROW LEVEL SECURITYstatement. - NEWSupabase Storage posture check. Passive scans can now review public Supabase Storage buckets and anonymous object-listing exposure alongside existing RLS and key checks.
- NEWAI-generated code guardrail check. GitHub repo scans can now flag missing security automation around code scanning, secret scanning, dependency updates, and AI-agent instructions.
May 12, 2026
- NEWRepo web-app risk checklist. GitHub repo scans can now flag high-confidence OWASP-style code risks such as raw SQL interpolation, unsafe HTML sinks, credentialed wildcard CORS, disabled TLS verification, and weak JWT secret fallbacks.
- NEWNext.js middleware-bypass check. Active scans for verified domains can now confirm CVE-2025-29927 exposure on middleware-protected routes before reporting it, and reports include the standard FixVibe AI fix prompt for remediation.
May 9, 2026
- SECURITYCross-origin scope hardening. Active scans and client-asset checks now stay within the authorized target scope and avoid carrying customer-provided credentials across cross-origin redirects.
- FIXEDSupabase RLS check is now strictly read-only. Supabase posture checks now avoid write attempts and focus on safe exposure signals. Verified-domain active testing remains the boundary for deeper confirmation.
- IMPROVEDSecurity-header findings only apply to root HTML responses. Missing CSP, Permissions-Policy, X-Frame-Options, or Referrer-Policy on a 204, JSON API, file download, or 404 no longer produces a finding. HSTS and X-Content-Type-Options still grade across all responses.
- IMPROVEDAuth-flow and rate-limit checks now require stronger evidence. FixVibe now reports these issues only when the application behavior clearly supports the finding, reducing noise from generic error pages and unsupported methods.
- IMPROVEDFile-upload findings tier by exploitability evidence. File-upload reports now separate low-confidence acceptance signals from stronger evidence of risky serving behavior, reducing over-severity on benign upload handlers.
May 7, 2026
- FIXEDThreat-intel listing accuracy improved. FixVibe now distinguishes real blocklist evidence from resolver diagnostics so threat-intel findings do not over-report on infrastructure-side lookup responses.
- NEWGitHub repo scans. Connect a repo and FixVibe checks the source for leaked Supabase service keys, Firebase admin tokens, risky workflow files, and outdated dependencies — without ever loading your deployed site. See Scan types.
- NEWSAST checks for risky JavaScript. Repo scans now flag
new Function()andsetTimeout("string")— both equivalent toeval()when fed untrusted input. - FIXEDFalse “exposed file” findings on Vercel / Cloudflare sites. Bare
403 Forbiddenresponses are no longer reported as “file exists” — most edge providers return 403 for suspicious-looking paths whether the file is there or not. We now require a positive HTTP signal before flagging. - FIXEDRepo-code false positives reduced. Repo scans now avoid flagging security terms in comments, documentation, test helpers, and clearly server-only contexts for several high-signal code checks.
- FIXEDSupabase anon key in localStorage no longer reports as a JWT-in-storage finding — the anon key is the publicly-intended client token. Real service-role tokens in browser storage are now critical with a clearer title.
- FIXEDCSP weakness detection improved. Content-Security-Policy checks now catch more permissive source policies while keeping evidence and remediation focused on the effective browser policy.
- FIXEDReflected-XSS check tightened. Active scans now require stronger reflection evidence before reporting executable-context risk, reducing false positives from unrelated markup on the page.
- FIXEDDomain verification handles apex ↔ www redirects correctly and is clearer about which value goes in the TXT-record Host field.
Format
Each entry is tagged so you can skim:
- NEW A new check, surface, or feature.
- IMPROVED Existing behaviour got better — more accurate, faster, clearer.
- FIXED A bug we shipped and then squashed.
- SECURITY Hardening, vulnerability fixes, or compliance changes.
Spot something that broke and isn't logged here? Email support@fixvibe.app.
