FixVibe

// docs / changelog

Changelog

FixVibe स्कैन-इंजन अपडेट: नया कवरेज, सुरक्षा सुधार और सटीकता में सुधार। सबसे पहले नवीनतम प्रविष्टियाँ।

September 26, 2026

  • सुधराClearer evidence for security header checks. Header checks now capture the response context needed to recheck a supported deployed fix. Unavailable, changed, or blocked responses do not count as proof that an issue is fixed. It also recognizes invalid MIME-sniffing protection values more accurately.
  • नयाKnown-vulnerability checks, September 2026. 16 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.

9 सितंबर 2026

  • नयाShai-Hulud. GitHub रिपॉज़िटरी स्कैन अब पैकेज डाउनलोड या चलाए बिना सितंबर 2026 के npm अभियान की वापसी से जुड़े मज़बूत साक्ष्य पहचानते हैं।

7 सितंबर 2026

  • ठीक कियाज़्यादा भरोसेमंद स्कैन। बड़े कंप्रेस किए गए रिस्पॉन्स लौटाने वाली साइटों को स्कैन करते समय अटकने की समस्या ठीक की गई।
  • सुधराज़्यादा भरोसेमंद स्कैन। बड़े स्कैन अब पाए गए निष्कर्षों को खोए बिना सुरक्षित रूप से फिर शुरू हो सकते हैं।

2026-08-04

  • नयाKnown-vulnerability checks, August 2026. 7 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.

21 जुलाई 2026

  • नयाNext.js WebSocket SSRF निर्भरता सलाहकार जाँच. GitHub रेपो स्कैन अब फ़्लैग कर सकते हैं Next.js मैनिफ़ेस्ट और लॉकफ़ाइल साक्ष्य संबद्ध हैं CVE-2026-44578 / GHSA-c4j6-fc7j-m34r. निष्कर्ष संस्करण-आधारित रहते हैं, ऐसा बताएं Vercel-होस्ट की गई तैनाती प्रभावित नहीं होती है, और कभी नहीं भेजती है WebSocket अपग्रेड करें, आंतरिक गंतव्यों की जांच करें, या लाइव दावा करें SSRF पुष्टि.
  • नयाKnown-vulnerability checks, July 2026. 43 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.

13 जुलाई 2026

  • नयाInjective Labs npm wallet-key stealer advisory check. Repo scans now flag package manifests and lockfiles resolving @injectivelabs/sdk-ts 1.20.21 or related @injectivelabs 1.20.21 packages tied to the compromised SDK. Findings stay version-based: FixVibe does not install packages, execute dependency code, derive wallets, contact exfiltration infrastructure, or claim key theft.
  • नयाReact Server Components CVE-2026-23864 advisory check. Repo scans now report npm manifest and lockfile evidence for react-server-dom-webpack, react-server-dom-parcel, or react-server-dom-turbopack versions affected by GHSA-83fc-fqcc-2hmg as version-based advisory context; they do not send crafted RSC requests, probe Server Function endpoints, crash-test services, or claim live denial-of-service confirmation.

2026-07-02

  • ठीक कियाLegal-link false positives reduced. Privacy and terms links that are visible after client-side rendering now count correctly, so SPA footers are not reported as missing when users can see those links.

30 जून 2026

  • नयाcodfish semantic-release GitHub Action compromise check. Repo scans can now flag workflow YAML references to codfish/semantic-release-action refs associated with the June 2026 compromise, reporting source/config evidence only. The check does not run GitHub Actions, read CI secrets, inspect runners, or claim credential theft.
  • नयाKnown-vulnerability checks, June 2026. 67 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.

June 18, 2026

  • नयाMastra easy-day-js advisory check. GitHub repo scans flag easy-day-js manifest and lockfile evidence tied to the June 2026 Mastra npm incident. The finding stays limited to repository dependency evidence and does not verify stale npm owners, run package scripts, inspect hosts, or assert credential theft.

June 14, 2026

  • ठीक कियाDOM XSS fragment probe stability fix. Verified active scans now skip the DOM fragment probe cleanly when browser automation is unavailable at startup, so reports no longer show internal browser-context errors for that check.
  • सुधराExpanded Red Hat npm worm coverage. GitHub repo scans now include additional Wiz-reported @redhat-cloud-services package versions for the Miasma campaign, while still reporting repository dependency evidence without installing packages, executing lifecycle scripts, or claiming credential theft.
  • नयाKnown npm typosquat package check. GitHub repo scans can now flag package manifests and lockfiles that resolve Microsoft-reported vpmdhaj npm typosquat package versions, reporting version-based advisory evidence without installing packages, executing lifecycle scripts, fetching tarballs, contacting attacker infrastructure, or claiming credential theft.
  • नयाCodex Remote UI token-stealing npm package check. GitHub repo scans can now flag package manifests and lockfiles that resolve codexui-android 0.1.82 or newer, reporting version-based advisory evidence without installing the package, executing it, reading Codex auth files, contacting exfiltration infrastructure, or claiming token theft.
  • नयाClaude Code GitHub Action workflow repo check. GitHub repo scans can now flag Claude Code Action workflows with mutable action refs, broad workflow token permissions, or risky access override inputs, reporting workflow YAML evidence without running Actions, executing Claude Code, reading CI secrets, or claiming prompt-injection exploitation.
  • नयाNode-gyp / Phantom Gyp npm worm repo check. GitHub repo scans can now flag package manifests or lockfiles that resolve known malicious npm package versions from the binding.gyp supply-chain campaign, or flag matching binding.gyp source evidence, without running npm install, executing node-gyp, downloading tarballs, or claiming credential theft.

June 11, 2026

  • नयाTanStack ArkType adapter malware dependency check. GitHub repo scans can now flag package manifests and lockfiles that resolve @tanstack/arktype-adapter to malicious versions 1.166.12 or 1.166.15 from CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx, reporting version-based advisory evidence without running npm install, executing lifecycle scripts, downloading tarballs, or claiming credential theft.
  • नयाRed Hat npm worm dependency advisory check. GitHub repo scans can now flag package manifests and lockfiles that resolve known compromised @redhat-cloud-services npm versions associated with the credential-stealing worm campaign, reporting dependency evidence without executing install scripts or claiming credential theft.

May 27, 2026

  • नयाKnown-vulnerability checks, May 2026. 33 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.

May 25, 2026

  • ठीक कियाActive scan reliability and SSTI accuracy fix. Active scans now safely store response-derived evidence that contains unsupported control characters, and SSTI reporting requires stronger target-specific template-evaluation evidence instead of common page or static-asset content.

16 May 2026

  • नयाActive scans via REST API and MCP. सक्रिय स्कैन अब सत्यापित डोमेन के विरुद्ध REST और MCP से ट्रिगर किया जा सकता है जिन्हें डैशबोर्ड से स्पष्ट रूप से अधिकृत किया गया है। प्राधिकरण किसी भी समय रद्द किया जा सकता है।
  • नयाSafer authorization levels for active scans. डोमेन प्राधिकरण अब सुरक्षित स्वचालित सक्रिय जांच को गहन सक्रिय परीक्षण से अलग करता है, ताकि टीमें प्रत्येक डोमेन के लिए सत्यापन के सही स्तर को स्वचालित कर सकें।
  • नयाFirst-use webhook for API/MCP active scans. एक वेबहुक पहली बार किसी नए अधिकृत डोमेन के विरुद्ध API/MCP-triggered सक्रिय स्कैन चलाने पर टीमों को सूचित कर सकता है।
  • सुधराImproved Referrer-Policy findings. Missing or weak Referrer-Policy results now separate URL-referrer leakage from broad information exposure, show document-response evidence, and include generic plus static-host remediation guidance.
  • सुधराImproved Permissions-Policy findings. Missing or weak Permissions-Policy results now show feature-level evidence, separate broad feature allowlists from missing hardening, and include generic plus static-host remediation guidance for common hosts, proxies, and app servers.
  • सुधराImproved clickjacking header prompts. Missing X-Frame-Options findings now point agents to CSP frame-ancestors as the modern protection, add Vercel/static SPA header guidance, and verify x-frame-options with CSP.
  • सुधराCSP header evidence and fix prompts improved. गुम-CSP रिपोर्ट में अब स्पष्ट होस्टिंग और प्रतिक्रिया संदर्भ के साथ-साथ सुरक्षित रूपरेखा-जागरूक उपचार मार्गदर्शन शामिल है।
  • ठीक कियाVercel path-probe false positives reduced. FixVibe को अब ऐप शेल में अज्ञात मार्गों को फिर से लिखने वाले परिनियोजन पर उजागर फ़्रेमवर्क कलाकृतियों की रिपोर्ट करने से पहले मजबूत एप्लिकेशन-विशिष्ट साक्ष्य की आवश्यकता है।
  • ठीक कियाअनुपालन निष्कर्ष अब भ्रामक CWE टैग नहीं रखते। पहले legal-compliance check "लापता प्राइवेसी पॉलिसी" और "लापता टर्म्स" निष्कर्षों को CWE-359 (PII एक्सपोज़र) से टैग करता था, जो वास्तविक खामी का वर्णन नहीं करता। ये निष्कर्ष अब बिना CWE के जारी होते हैं — वे अनुपालन आइटम हैं, वर्गीकृत सुरक्षा कमजोरियाँ नहीं।

15 मई 2026

  • नयाRepository secret leak check. GitHub repo scans can now flag hardcoded provider keys and other secrets committed to source, with evidence masked and the standard FixVibe rotation prompt included.
  • नयाVercel deployment protection check. निष्क्रिय स्कैन अब सार्वजनिक *.vercel.app जेनरेट किए गए परिनियोजन यूआरएल को चिह्नित कर सकते हैं जो Vercel परिनियोजन Proटेक्शन के बिना प्रतिक्रिया देते हैं, जबकि मौजूदा हेडर जांच CSP, HSTS और ब्राउज़र हार्डनिंग का ऑडिट जारी रखती है।

14 मई 2026

  • सुधराFirebase rules detection improved. BaaS स्कैन अब अधिक Firebase ऐप आकृतियों का पता लगाता है और जोखिम भरे सार्वजनिक डेटा एक्सपोज़र की पहचान करने के लिए केवल पढ़ने योग्य साक्ष्य का उपयोग करता है।

13 मई 2026

  • नयाRepo Supabase RLS migration check. GitHub रेपो स्कैन अब Supabase SQL माइग्रेशन को चिह्नित कर सकता है जो मिलान वाले ALTER TABLE ... ENABLE ROW LEVEL SECURITY कथन के बिना सार्वजनिक तालिकाएँ बनाता है।
  • नयाSupabase Storage posture check. निष्क्रिय स्कैन अब मौजूदा RLS और कुंजी जांच के साथ-साथ सार्वजनिक Supabase स्टोरेज बकेट और अनाम ऑब्जेक्ट-लिस्टिंग एक्सपोज़र की समीक्षा कर सकते हैं।
  • नयाAI-generated code guardrail check. GitHub रेपो स्कैन अब कोड स्कैनिंग, गुप्त स्कैनिंग, निर्भरता अपडेट और AI-एजेंट निर्देशों के आसपास लापता सुरक्षा स्वचालन को चिह्नित कर सकता है।

12 मई 2026

  • नयाRepo web-app risk checklist. GitHub रेपो स्कैन अब कच्चे SQL इंटरपोलेशन, असुरक्षित HTML सिंक, क्रेडेंशियल वाइल्डकार्ड CORS, अक्षम TLS सत्यापन, और कमजोर JWT गुप्त फ़ॉलबैक जैसे उच्च-विश्वसनीय OWASP- स्टाइल कोड जोखिमों को चिह्नित कर सकते हैं।
  • नयाNext.js middleware-bypass check. सत्यापित डोमेन के लिए सक्रिय स्कैन अब रिपोर्ट करने से पहले मिडलवेयर-संरक्षित मार्गों पर CVE-2025-29927 एक्सपोज़र की पुष्टि कर सकते हैं, और रिपोर्ट में सुधार के लिए मानक FixVibe AI फिक्स प्रॉम्प्ट शामिल है।

9 मई 2026

  • सुरक्षाCross-origin scope hardening. सक्रिय स्कैन और क्लाइंट-एसेट जांच अब अधिकृत लक्ष्य दायरे में रहते हैं और क्रॉस-ऑरिजिन रीडायरेक्ट में ग्राहक द्वारा प्रदान किए गए क्रेडेंशियल्स को ले जाने से बचते हैं।
  • ठीक कियाSupabase RLS check is now strictly read-only. Supabase मुद्रा जांच अब लिखने के प्रयासों से बचें और सुरक्षित एक्सपोज़र संकेतों पर ध्यान केंद्रित करें। सत्यापित-डोमेन सक्रिय परीक्षण गहन पुष्टि की सीमा बनी हुई है।
  • सुधराSecurity-header findings केवल root HTML responses पर apply होती हैं। 204, JSON API, file download, या 404 पर missing CSP, Permissions-Policy, X-Frame-Options, या Referrer-Policy अब finding produce नहीं करता। HSTS और X-Content-Type-Options अभी भी सभी responses पर grade होते हैं।
  • सुधराAuth-flow and rate-limit checks now require stronger evidence. FixVibe अब इन मुद्दों की रिपोर्ट तभी करता है जब एप्लिकेशन व्यवहार स्पष्ट रूप से खोज का समर्थन करता है, सामान्य त्रुटि पृष्ठों और असमर्थित तरीकों से शोर को कम करता है।
  • सुधराFile-upload findings tier by exploitability evidence. फ़ाइल-अपलोड रिपोर्टें अब कम-आत्मविश्वास वाले स्वीकृति संकेतों को जोखिम भरे सेवा व्यवहार के मजबूत साक्ष्य से अलग करती हैं, जिससे सौम्य अपलोड हैंडलर पर अति-गंभीरता कम हो जाती है।

7 मई 2026

  • ठीक कियाThreat-intel listing accuracy improved. FixVibe अब वास्तविक ब्लॉकलिस्ट साक्ष्य को रिज़ॉल्वर डायग्नोस्टिक्स से अलग करता है ताकि खतरे-बुद्धि निष्कर्ष बुनियादी ढांचे-साइड लुकअप प्रतिक्रियाओं पर अधिक रिपोर्ट न करें।
  • नयाGitHub repo scans. Repo connect करें और FixVibe source को leaked Supabase service keys, Firebase admin tokens, risky workflow files, और outdated dependencies के लिए check करता है — deployed site load किए बिना। स्कैन प्रकार देखें।
  • नयाRisky JavaScript के लिए SAST checks. Repo scans अब new Function() और setTimeout("string") flag करते हैं — untrusted input मिलने पर दोनों eval() के बराबर हैं।
  • ठीक कियाVercel / Cloudflare sites पर false “exposed file” findings. Bare 403 Forbidden responses अब “file exists” के रूप में report नहीं होते — ज्यादातर edge providers suspicious-looking paths पर file हो या न हो, 403 return करते हैं। Flag करने से पहले अब हम positive HTTP signal require करते हैं।
  • ठीक कियाRepo-code false positives reduced. रेपो स्कैन अब टिप्पणियों, दस्तावेज़ीकरण, परीक्षण सहायकों और कई उच्च-सिग्नल कोड जांचों के लिए स्पष्ट रूप से केवल सर्वर संदर्भों में सुरक्षा शर्तों को फ़्लैग करने से बचता है।
  • ठीक कियाlocalStorage में Supabase anon key अब JWT-in-storage finding के रूप में report नहीं होती — anon key publicly-intended client token है। Browser storage में real service-role tokens अब clearer title के साथ critical हैं।
  • ठीक कियाCSP weakness detection improved. Content-Security-Policy चेक अब साक्ष्य और उपचार को प्रभावी ब्राउज़र नीति पर केंद्रित रखते हुए अधिक अनुमेय स्रोत नीतियों को पकड़ते हैं।
  • ठीक कियाReflected-XSS check tightened. सक्रिय स्कैन को अब निष्पादन योग्य-संदर्भ जोखिम की रिपोर्ट करने से पहले मजबूत प्रतिबिंब साक्ष्य की आवश्यकता होती है, जिससे पृष्ठ पर असंबंधित मार्कअप से झूठी सकारात्मकता कम हो जाती है।
  • ठीक कियाDomain verification apex ↔ www redirects correctly handle करता है और TXT-record Host field में कौन सा value डालना है, यह ज्यादा clear बताता है।

Format

हर entry tagged है ताकि आप skim कर सकें:

  • नया नई check, surface, या feature।
  • सुधरा Existing behaviour बेहतर हुआ — ज्यादा accurate, fast, clear।
  • ठीक किया एक bug जिसे हमने ship किया और फिर ठीक किया।
  • सुरक्षा Hardening, vulnerability fixes, या compliance changes।

कुछ ऐसा दिखा जो टूटा है और यहाँ logged नहीं? support@fixvibe.app पर email करें।

Changelog — Docs · FixVibe