FixVibe

// docs / changelog

変更履歴

FixVibe スキャン エンジンの更新: 新しい範囲、安全性の向上、精度の向上。最新のエントリが最初です。

September 26, 2026

  • 改善Clearer evidence for security header checks. Header checks now capture the response context needed to recheck a supported deployed fix. Unavailable, changed, or blocked responses do not count as proof that an issue is fixed. It also recognizes invalid MIME-sniffing protection values more accurately.
  • 新規Known-vulnerability checks, September 2026. 16 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.

2026年9月9日

  • 新規Shai-Hulud. GitHub リポジトリスキャンは、パッケージをダウンロードまたは実行せずに、2026 年 9 月の npm キャンペーン再発に関連する強い証拠を検出できるようになりました。

2026年9月7日

  • 修正スキャンの信頼性を向上。 大きな圧縮レスポンスを返すサイトのスキャンが停止する問題を修正しました。
  • 改善スキャンの信頼性を向上。 大規模なスキャンを、検出結果を失うことなく安全に再開できるようになりました。

2026-08-04

  • 新規Known-vulnerability checks, August 2026. 7 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.

2026年7月21日

  • 新規Next.js WebSocket SSRF 依存関係アドバイザリ チェック。 GitHub リポジトリ スキャンで、CVE-2026-44578 / GHSA-c4j6-fc7j-m34r に関連する Next.js マニフェストとロックファイルの証拠にフラグを立てることができるようになりました。調査結果はバージョンベースのままで、Vercel がホストする展開は影響を受けず、WebSocket アップグレードの送信、内部宛先の調査、ライブ SSRF 確認の要求は決して行われないと述べています。
  • 新規Known-vulnerability checks, July 2026. 43 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.

2026年7月13日

  • 新規Injective Labs npm wallet-key stealer advisory check. Repo scans now flag package manifests and lockfiles resolving @injectivelabs/sdk-ts 1.20.21 or related @injectivelabs 1.20.21 packages tied to the compromised SDK. Findings stay version-based: FixVibe does not install packages, execute dependency code, derive wallets, contact exfiltration infrastructure, or claim key theft.
  • 新規React Server Components CVE-2026-23864 advisory check. Repo scans now report npm manifest and lockfile evidence for react-server-dom-webpack, react-server-dom-parcel, or react-server-dom-turbopack versions affected by GHSA-83fc-fqcc-2hmg as version-based advisory context; they do not send crafted RSC requests, probe Server Function endpoints, crash-test services, or claim live denial-of-service confirmation.

2026-07-02

  • 修正Legal-link false positives reduced. Privacy and terms links that are visible after client-side rendering now count correctly, so SPA footers are not reported as missing when users can see those links.

2026年6月30日

  • 新規codfish semantic-release GitHub Action compromise check. Repo scans can now flag workflow YAML references to codfish/semantic-release-action refs associated with the June 2026 compromise, reporting source/config evidence only. The check does not run GitHub Actions, read CI secrets, inspect runners, or claim credential theft.
  • 新規Known-vulnerability checks, June 2026. 67 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.

June 18, 2026

  • 新規Mastra easy-day-js advisory check. GitHub repo scans flag easy-day-js manifest and lockfile evidence tied to the June 2026 Mastra npm incident. The finding stays limited to repository dependency evidence and does not verify stale npm owners, run package scripts, inspect hosts, or assert credential theft.

June 14, 2026

  • 修正DOM XSS fragment probe stability fix. Verified active scans now skip the DOM fragment probe cleanly when browser automation is unavailable at startup, so reports no longer show internal browser-context errors for that check.
  • 改善Expanded Red Hat npm worm coverage. GitHub repo scans now include additional Wiz-reported @redhat-cloud-services package versions for the Miasma campaign, while still reporting repository dependency evidence without installing packages, executing lifecycle scripts, or claiming credential theft.
  • 新規Known npm typosquat package check. GitHub repo scans can now flag package manifests and lockfiles that resolve Microsoft-reported vpmdhaj npm typosquat package versions, reporting version-based advisory evidence without installing packages, executing lifecycle scripts, fetching tarballs, contacting attacker infrastructure, or claiming credential theft.
  • 新規Codex Remote UI token-stealing npm package check. GitHub repo scans can now flag package manifests and lockfiles that resolve codexui-android 0.1.82 or newer, reporting version-based advisory evidence without installing the package, executing it, reading Codex auth files, contacting exfiltration infrastructure, or claiming token theft.
  • 新規Claude Code GitHub Action workflow repo check. GitHub repo scans can now flag Claude Code Action workflows with mutable action refs, broad workflow token permissions, or risky access override inputs, reporting workflow YAML evidence without running Actions, executing Claude Code, reading CI secrets, or claiming prompt-injection exploitation.
  • 新規Node-gyp / Phantom Gyp npm worm repo check. GitHub repo scans can now flag package manifests or lockfiles that resolve known malicious npm package versions from the binding.gyp supply-chain campaign, or flag matching binding.gyp source evidence, without running npm install, executing node-gyp, downloading tarballs, or claiming credential theft.

June 11, 2026

  • 新規TanStack ArkType adapter malware dependency check. GitHub repo scans can now flag package manifests and lockfiles that resolve @tanstack/arktype-adapter to malicious versions 1.166.12 or 1.166.15 from CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx, reporting version-based advisory evidence without running npm install, executing lifecycle scripts, downloading tarballs, or claiming credential theft.
  • 新規Red Hat npm worm dependency advisory check. GitHub repo scans can now flag package manifests and lockfiles that resolve known compromised @redhat-cloud-services npm versions associated with the credential-stealing worm campaign, reporting dependency evidence without executing install scripts or claiming credential theft.

May 27, 2026

  • 新規Known-vulnerability checks, May 2026. 33 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.

May 25, 2026

  • 修正Active scan reliability and SSTI accuracy fix. Active scans now safely store response-derived evidence that contains unsupported control characters, and SSTI reporting requires stronger target-specific template-evaluation evidence instead of common page or static-asset content.

16 May 2026

  • 新規Active scans via REST API and MCP. ダッシュボードから明示的に承認された検証済みドメインに対して、REST および MCP からアクティブ スキャンをトリガーできるようになりました。承認はいつでも取り消すことができます。
  • 新規Safer authorization levels for active scans. ドメイン認証により、より安全な自動アクティブ チェックとより詳細なアクティブ テストが区別されるようになり、チームはドメインごとに適切なレベルの検証を自動化できるようになりました。
  • 新規First-use webhook for API/MCP active scans. Webhook は、新しく承認されたドメインに対して API/MCP-triggered アクティブ スキャンが初めて実行されたときにチームに通知できます。
  • 改善Improved Referrer-Policy findings. Missing or weak Referrer-Policy results now separate URL-referrer leakage from broad information exposure, show document-response evidence, and include generic plus static-host remediation guidance.
  • 改善Improved Permissions-Policy findings. Missing or weak Permissions-Policy results now show feature-level evidence, separate broad feature allowlists from missing hardening, and include generic plus static-host remediation guidance for common hosts, proxies, and app servers.
  • 改善Improved clickjacking header prompts. Missing X-Frame-Options findings now point agents to CSP frame-ancestors as the modern protection, add Vercel/static SPA header guidance, and verify x-frame-options with CSP.
  • 改善CSP header evidence and fix prompts improved. Missing-CSP レポートには、より明確なホスティングと応答コンテキストに加えて、より安全なフレームワーク対応の修復ガイダンスが含まれるようになりました。
  • 修正Vercel path-probe false positives reduced. FixVibe では、未知のルートを App Shell に書き換えるデプロイメントで公開されたフレームワーク アーティファクトを報告する前に、アプリケーション固有のより強力な証拠が必要になりました。
  • 修正コンプライアンス系の検出に誤解を招く CWE タグがつかなくなりました。legal-compliance チェックは以前、「プライバシーポリシー不在」「利用規約不在」の検出に CWE-359(PII 公開)を付けていましたが、これは実際のギャップを記述しません。これらの検出は CWE なしで出力されます — 分類可能なセキュリティ脆弱性ではなく、コンプライアンス項目だからです。

2026 年 5 月 15 日

  • 新規Repository secret leak check. GitHub repo scans can now flag hardcoded provider keys and other secrets committed to source, with evidence masked and the standard FixVibe rotation prompt included.
  • 新規Vercel deployment protection check. パッシブ スキャンでは、Vercel デプロイメント Protection なしで応答するパブリック *.vercel.app 生成されたデプロイメント URL にフラグを立てることができるようになりました。一方、既存のヘッダー チェックは CSP、HSTS、ブラウザの強化を監査し続けます。

2026 年 5 月 14 日

  • 改善Firebase rules detection improved. BaaS スキャンでは、より多くの Firebase アプリ シェイプが検出され、読み取り専用の証拠を使用して、危険な公開データ漏洩を特定できるようになりました。

2026 年 5 月 13 日

  • 新規Repo Supabase RLS migration check. GitHub リポジトリ スキャンでは、一致する ALTER TABLE ... ENABLE ROW LEVEL SECURITY ステートメントのないパブリック テーブルを作成する Supabase SQL 移行にフラグを立てることができるようになりました。
  • 新規Supabase Storage posture check. パッシブ スキャンでは、既存の RLS およびキー チェックと並行して、パブリック Supabase ストレージ バケットと匿名オブジェクト リストの公開を確認できるようになりました。
  • 新規AI-generated code guardrail check. GitHub リポジトリ スキャンでは、コード スキャン、シークレット スキャン、依存関係の更新、および AI- エージェントの指示に関するセキュリティ自動化の欠落にフラグを立てることができるようになりました。

2026 年 5 月 12 日

  • 新規Repo web-app risk checklist. GitHub リポジトリ スキャンでは、生の SQL 補間、安全でない HTML シンク、資格情報のあるワイルドカード CORS、無効な TLS 検証、弱い JWT シークレット フォールバックなど、信頼性の高い OWASP- スタイルのコード リスクにフラグを立てることができるようになりました。
  • 新規Next.js middleware-bypass check. 検証済みドメインのアクティブ スキャンでは、ミドルウェアで保護されたルートで CVE-2025-29927 の露出を報告する前に確認できるようになり、レポートには修復のための標準の FixVibe AI 修正プロンプトが含まれます。

2026年5月9日

  • セキュリティCross-origin scope hardening. アクティブ スキャンとクライアント アセット チェックは、承認されたターゲット スコープ内に留まり、クロスオリジン リダイレクト間で顧客が提供した資格情報を伝達することを回避できるようになりました。
  • 修正Supabase RLS check is now strictly read-only. Supabase 姿勢チェックでは、書き込み試行が回避され、安全な露出信号に重点が置かれるようになりました。検証済みドメインのアクティブ テストは、より詳細な確認のための境界として残ります。
  • 改善セキュリティヘッダーの検出結果は、ルート HTML レスポンスにのみ適用されます。 204、JSON API、ファイルダウンロード、404 で CSP、Permissions-Policy、X-Frame-Options、Referrer-Policy が不足していても、検出結果は生成されなくなりました。HSTS と X-Content-Type-Options は引き続きすべてのレスポンスで評価されます。
  • 改善Auth-flow and rate-limit checks now require stronger evidence. FixVibe では、アプリケーションの動作が明らかにその結果をサポートしている場合にのみこれらの問題を報告するようになり、一般的なエラー ページやサポートされていないメソッドによるノイズが軽減されます。
  • 改善File-upload findings tier by exploitability evidence. ファイル アップロード レポートでは、信頼性の低い受け入れシグナルと、危険なサービス提供動作のより強力な証拠が分離されるようになり、無害なアップロード ハンドラーの過剰な重大度が軽減されます。

2026年5月7日

  • 修正Threat-intel listing accuracy improved. FixVibe は、実際のブロックリストの証拠とリゾルバー診断を区別するようになりました。これにより、脅威インテリジェンスの検出結果がインフラストラクチャ側の検索応答について過剰に報告されなくなります。
  • 新規GitHub リポジトリスキャン。 リポジトリを接続すると、FixVibe はデプロイ済みサイトを読み込まずに、漏えいした Supabase service key、Firebase admin token、危険な workflow file、古い依存関係をソースからチェックします。スキャンの種類 を参照してください。
  • 新規危険な JavaScript に対する SAST チェック。 リポジトリスキャンは new Function() と setTimeout("string") をフラグ付けするようになりました。どちらも信頼できない入力を与えると eval() と同等です。
  • 修正Vercel / Cloudflare サイトでの誤った「公開ファイル」検出。 裸の 403 Forbidden レスポンスは「ファイルが存在する」として報告されなくなりました。多くの edge provider は、そのファイルが存在するかどうかに関係なく、怪しく見えるパスに 403 を返します。現在はフラグ付け前に正の HTTP シグナルを要求しています。
  • 修正Repo-code false positives reduced. リポジトリ スキャンでは、コメント、ドキュメント、テスト ヘルパー、およびいくつかの高信号コード チェックの明らかにサーバーのみのコンテキストでセキュリティ用語のフラグ付けが回避されるようになりました。
  • 修正localStorage 内の Supabase anon key は、JWT-in-storage の検出結果として報告されなくなりました。anon key は公開を意図したクライアントトークンです。ブラウザストレージ内の本物の service-role token は、より明確なタイトルで critical になります。
  • 修正CSP weakness detection improved. Content-Security-Policy チェックは、有効なブラウザ ポリシーに焦点を当てた証拠と修復を維持しながら、より寛容なソース ポリシーを検出するようになりました。
  • 修正Reflected-XSS check tightened. アクティブ スキャンでは、実行可能コンテキストのリスクを報告する前に、より強力なリフレクション証拠が必要となるため、ページ上の無関係なマークアップによる誤検知が減少します。
  • 修正ドメイン検証は apex ↔ www リダイレクトを正しく扱うようになり、TXT レコードの Host フィールドに入れる値もより明確になりました。

形式

各エントリには、ざっと読めるようタグが付いています。

  • 新規 新しいチェック、対象範囲、または機能です。
  • 改善 既存の動作が改善されました。より正確に、速く、分かりやすくなっています。
  • 修正 出荷後に見つけて修正したバグです。
  • セキュリティ ハードニング、脆弱性修正、またはコンプライアンス変更です。

壊れているのにここに記録されていないものを見つけましたか? support@fixvibe.app までメールしてください。

変更履歴 — Docs · FixVibe