// docs / changelog
변경 로그
FixVibe 스캔 엔진 업데이트: 새로운 적용 범위, 안전 개선 및 정확성 개선. 최신 항목이 먼저 표시됩니다.
September 26, 2026
- IMPROVEDClearer evidence for security header checks. Header checks now capture the response context needed to recheck a supported deployed fix. Unavailable, changed, or blocked responses do not count as proof that an issue is fixed. It also recognizes invalid MIME-sniffing protection values more accurately.
- NEWKnown-vulnerability checks, September 2026. 16 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
2026년 9월 9일
- NEWShai-Hulud. GitHub 저장소 스캔은 이제 패키지를 다운로드하거나 실행하지 않고도 2026년 9월 npm 캠페인 재등장과 관련된 강력한 증거를 탐지합니다.
2026년 9월 7일
- FIXED더 안정적인 스캔. 대용량 압축 응답을 반환하는 사이트를 스캔할 때 멈추는 문제를 수정했습니다.
- IMPROVED더 안정적인 스캔. 이제 대규모 스캔을 탐지 결과 손실 없이 안전하게 재개할 수 있습니다.
2026-08-04
- NEWKnown-vulnerability checks, August 2026. 7 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
2026년 7월 21일
- NEWNext.js WebSocket SSRF 종속성 자문 검사. 이제 GitHub 저장소 스캔에서 CVE-2026-44578 / GHSA-c4j6-fc7j-m34r과 관련된 Next.js 매니페스트 및 잠금 파일 증거에 플래그를 지정할 수 있습니다. 결과는 버전 기반으로 유지되며 Vercel에서 호스팅하는 배포는 영향을 받지 않으며 WebSocket 업그레이드를 보내거나 내부 대상을 조사하거나 실시간 SSRF 확인을 요청하지 않는다고 명시되어 있습니다.
- NEWKnown-vulnerability checks, July 2026. 43 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
2026년 7월 13일
- NEWInjective Labs npm wallet-key stealer advisory check. Repo scans now flag package manifests and lockfiles resolving @injectivelabs/sdk-ts 1.20.21 or related @injectivelabs 1.20.21 packages tied to the compromised SDK. Findings stay version-based: FixVibe does not install packages, execute dependency code, derive wallets, contact exfiltration infrastructure, or claim key theft.
- NEWReact Server Components CVE-2026-23864 advisory check. Repo scans now report npm manifest and lockfile evidence for react-server-dom-webpack, react-server-dom-parcel, or react-server-dom-turbopack versions affected by GHSA-83fc-fqcc-2hmg as version-based advisory context; they do not send crafted RSC requests, probe Server Function endpoints, crash-test services, or claim live denial-of-service confirmation.
2026-07-02
- FIXEDLegal-link false positives reduced. Privacy and terms links that are visible after client-side rendering now count correctly, so SPA footers are not reported as missing when users can see those links.
2026년 6월 30일
- NEWcodfish semantic-release GitHub Action compromise check. Repo scans can now flag workflow YAML references to codfish/semantic-release-action refs associated with the June 2026 compromise, reporting source/config evidence only. The check does not run GitHub Actions, read CI secrets, inspect runners, or claim credential theft.
- NEWKnown-vulnerability checks, June 2026. 67 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
June 18, 2026
- NEWMastra easy-day-js advisory check. GitHub repo scans flag easy-day-js manifest and lockfile evidence tied to the June 2026 Mastra npm incident. The finding stays limited to repository dependency evidence and does not verify stale npm owners, run package scripts, inspect hosts, or assert credential theft.
June 14, 2026
- FIXEDDOM XSS fragment probe stability fix. Verified active scans now skip the DOM fragment probe cleanly when browser automation is unavailable at startup, so reports no longer show internal browser-context errors for that check.
- IMPROVEDExpanded Red Hat npm worm coverage. GitHub repo scans now include additional Wiz-reported @redhat-cloud-services package versions for the Miasma campaign, while still reporting repository dependency evidence without installing packages, executing lifecycle scripts, or claiming credential theft.
- NEWKnown npm typosquat package check. GitHub repo scans can now flag package manifests and lockfiles that resolve Microsoft-reported vpmdhaj npm typosquat package versions, reporting version-based advisory evidence without installing packages, executing lifecycle scripts, fetching tarballs, contacting attacker infrastructure, or claiming credential theft.
- NEWCodex Remote UI token-stealing npm package check. GitHub repo scans can now flag package manifests and lockfiles that resolve codexui-android 0.1.82 or newer, reporting version-based advisory evidence without installing the package, executing it, reading Codex auth files, contacting exfiltration infrastructure, or claiming token theft.
- NEWClaude Code GitHub Action workflow repo check. GitHub repo scans can now flag Claude Code Action workflows with mutable action refs, broad workflow token permissions, or risky access override inputs, reporting workflow YAML evidence without running Actions, executing Claude Code, reading CI secrets, or claiming prompt-injection exploitation.
- NEWNode-gyp / Phantom Gyp npm worm repo check. GitHub repo scans can now flag package manifests or lockfiles that resolve known malicious npm package versions from the binding.gyp supply-chain campaign, or flag matching binding.gyp source evidence, without running npm install, executing node-gyp, downloading tarballs, or claiming credential theft.
June 11, 2026
- NEWTanStack ArkType adapter malware dependency check. GitHub repo scans can now flag package manifests and lockfiles that resolve @tanstack/arktype-adapter to malicious versions 1.166.12 or 1.166.15 from CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx, reporting version-based advisory evidence without running npm install, executing lifecycle scripts, downloading tarballs, or claiming credential theft.
- NEWRed Hat npm worm dependency advisory check. GitHub repo scans can now flag package manifests and lockfiles that resolve known compromised @redhat-cloud-services npm versions associated with the credential-stealing worm campaign, reporting dependency evidence without executing install scripts or claiming credential theft.
May 27, 2026
- NEWKnown-vulnerability checks, May 2026. 33 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
May 25, 2026
- FIXEDActive scan reliability and SSTI accuracy fix. Active scans now safely store response-derived evidence that contains unsupported control characters, and SSTI reporting requires stronger target-specific template-evaluation evidence instead of common page or static-asset content.
16 May 2026
- NEWActive scans via REST API and MCP. 이제 대시보드에서 명시적으로 승인된 확인된 도메인에 대해 REST 및 MCP에서 활성 검색을 트리거할 수 있습니다. 승인은 언제든지 취소할 수 있습니다.
- NEWSafer authorization levels for active scans. 도메인 승인은 이제 더 안전한 자동 활성 검사와 심층 활성 테스트를 구별하므로 팀은 각 도메인에 대해 적절한 수준의 확인을 자동화할 수 있습니다.
- NEWFirst-use webhook for API/MCP active scans. 웹후크는 새로 승인된 도메인에 대해 API/MCP-triggered 활성 스캔이 처음 실행될 때 팀에 알릴 수 있습니다.
- IMPROVEDImproved Referrer-Policy findings. Missing or weak
Referrer-Policyresults now separate URL-referrer leakage from broad information exposure, show document-response evidence, and include generic plus static-host remediation guidance. - IMPROVEDImproved Permissions-Policy findings. Missing or weak
Permissions-Policyresults now show feature-level evidence, separate broad feature allowlists from missing hardening, and include generic plus static-host remediation guidance for common hosts, proxies, and app servers. - IMPROVEDImproved clickjacking header prompts. Missing
X-Frame-Optionsfindings now point agents to CSPframe-ancestorsas the modern protection, add Vercel/static SPA header guidance, and verifyx-frame-optionswith CSP. - IMPROVEDCSP header evidence and fix prompts improved. Missing-CSP 보고서에는 이제 더 명확한 호스팅 및 응답 컨텍스트와 더 안전한 프레임워크 인식 수정 지침이 포함됩니다.
- FIXEDVercel path-probe false positives reduced. FixVibe은 이제 앱 셸에 알 수 없는 경로를 다시 작성하는 배포에서 노출된 프레임워크 아티팩트를 보고하기 전에 더 강력한 애플리케이션별 증거를 요구합니다.
- FIXED컴플라이언스 발견에 더 이상 잘못된 CWE 태그가 붙지 않습니다. 이전에는 legal-compliance 체크가 "개인정보처리방침 누락" 및 "이용약관 누락" 발견에
CWE-359(PII 노출)를 붙였으나, 이는 실제 갭을 설명하지 않습니다. 이러한 발견은 이제 CWE 없이 게시됩니다 — 분류 가능한 보안 취약점이 아니라 컴플라이언스 항목입니다.
2026년 5월 15일
- NEWRepository secret leak check. GitHub repo scans can now flag hardcoded provider keys and other secrets committed to source, with evidence masked and the standard FixVibe rotation prompt included.
- NEWVercel deployment protection check. 패시브 스캔은 이제 Vercel 배포 Protection 없이 응답하는 공개
*.vercel.app생성된 배포 URL에 플래그를 지정할 수 있으며, 기존 헤더 검사는 CSP, HSTS 및 브라우저 강화를 계속 감사합니다.
2026년 5월 14일
- IMPROVEDFirebase rules detection improved. BaaS 스캔은 이제 더 많은 Firebase 앱 형태를 감지하고 읽기 전용 증거를 사용하여 위험한 공개 데이터 노출을 식별합니다.
2026년 5월 13일
- NEWRepo Supabase RLS migration check. GitHub repo 스캔은 이제 일치하는
ALTER TABLE ... ENABLE ROW LEVEL SECURITY문 없이 공개 테이블을 생성하는 Supabase SQL 마이그레이션에 플래그를 지정할 수 있습니다. - NEWSupabase Storage posture check. 패시브 스캔은 이제 기존 RLS 및 키 검사와 함께 공개 Supabase 스토리지 버킷과 익명 개체 목록 노출을 검토할 수 있습니다.
- NEWAI-generated code guardrail check. GitHub repo 검색은 이제 코드 검색, 비밀 검색, 종속성 업데이트 및 AI-agent 지침과 관련된 보안 자동화 누락을 표시할 수 있습니다.
2026년 5월 12일
- NEWRepo web-app risk checklist. GitHub repo 스캔은 이제 원시 SQL 보간, 안전하지 않은 HTML 싱크, 자격 증명 와일드카드 CORS, 비활성화된 TLS 확인, 약한 JWT 비밀 폴백과 같은 신뢰도가 높은 OWASP- 스타일 코드 위험에 플래그를 지정할 수 있습니다.
- NEWNext.js middleware-bypass check. 확인된 도메인에 대한 활성 검색을 통해 이제 보고하기 전에 미들웨어로 보호되는 경로에서 CVE-2025-29927 노출을 확인할 수 있으며 보고서에는 수정을 위한 표준 FixVibe AI 수정 프롬프트가 포함됩니다.
2026년 5월 9일
- SECURITYCross-origin scope hardening. 활성 스캔 및 클라이언트 자산 검사는 이제 승인된 대상 범위 내에 유지되며 원본 간 리디렉션을 통해 고객이 제공한 자격 증명을 전달하지 않습니다.
- FIXEDSupabase RLS check is now strictly read-only. Supabase 자세 검사는 이제 쓰기 시도를 방지하고 안전한 노출 신호에 집중합니다. 검증된 도메인의 활성 테스트는 더 깊은 확인을 위한 경계로 남아 있습니다.
- IMPROVEDSecurity-header finding은 root HTML response에만 적용됩니다. 204, JSON API, file download, 404에 CSP, Permissions-Policy, X-Frame-Options, Referrer-Policy가 없다고 finding을 만들지 않습니다. HSTS와 X-Content-Type-Options는 여전히 모든 response에 대해 평가됩니다.
- IMPROVEDAuth-flow and rate-limit checks now require stronger evidence. FixVibe 이제 응용 프로그램 동작이 결과를 명확하게 지원하는 경우에만 이러한 문제를 보고하여 일반 오류 페이지 및 지원되지 않는 메서드에서 발생하는 노이즈를 줄입니다.
- IMPROVEDFile-upload findings tier by exploitability evidence. 파일 업로드 보고서는 이제 위험한 게재 행동에 대한 더 강력한 증거와 신뢰도가 낮은 승인 신호를 분리하여 양성 업로드 핸들러의 과도한 심각도를 줄입니다.
2026년 5월 7일
- FIXEDThreat-intel listing accuracy improved. FixVibe은 이제 실제 차단 목록 증거와 확인자 진단을 구별하므로 위협 인텔리전스 결과가 인프라 측 조회 응답에 대해 과도하게 보고되지 않습니다.
- NEWGitHub repo scan. Repo를 연결하면 FixVibe가 배포된 site를 load하지 않고도 source에서 leaked Supabase service key, Firebase admin token, 위험한 workflow file, outdated dependency를 검사합니다. 스캔 유형을 참고하세요.
- NEW위험한 JavaScript를 위한 SAST check. Repo scan은 이제
new Function()과setTimeout("string")을 flag합니다. 둘 다 untrusted input을 받으면eval()과 같습니다. - FIXEDVercel / Cloudflare site의 거짓 “exposed file” finding. Bare
403 Forbiddenresponse는 더 이상 “file exists”로 보고되지 않습니다. 대부분의 edge provider는 파일 존재 여부와 관계없이 suspicious path에 403을 반환합니다. 이제 flag하기 전에 positive HTTP signal을 요구합니다. - FIXEDRepo-code false positives reduced. Repo 스캔은 이제 주석, 문서, 테스트 도우미 및 여러 가지 신호가 높은 코드 검사에 대한 명확한 서버 전용 컨텍스트에서 보안 용어 플래그를 지정하지 않습니다.
- FIXEDlocalStorage 안의 Supabase anon key는 더 이상 JWT-in-storage finding으로 보고되지 않습니다. anon key는 client에 공개하도록 의도된 token입니다. Browser storage 안의 실제 service-role token은 더 명확한 title과 함께 critical입니다.
- FIXEDCSP weakness detection improved. Content-Security-Policy 검사는 이제 효과적인 브라우저 정책에 초점을 맞춘 증거와 교정을 유지하면서 더 허용적인 소스 정책을 포착합니다.
- FIXEDReflected-XSS check tightened. 이제 활성 스캔에서는 실행 가능 컨텍스트 위험을 보고하기 전에 더 강력한 반사 증거가 필요하므로 페이지의 관련 없는 마크업으로 인한 오탐이 줄어듭니다.
- FIXEDDomain verification은 apex ↔ www redirect를 올바르게 처리하며, TXT-record Host field에 어떤 값을 넣어야 하는지도 더 명확해졌습니다.
형식
각 entry에는 빠르게 훑어볼 수 있도록 tag가 붙습니다.
- NEW 새 check, surface 또는 feature.
- IMPROVED 기존 동작이 더 정확하거나, 빠르거나, 명확해졌습니다.
- FIXED 배포했던 bug를 수정했습니다.
- SECURITY Hardening, vulnerability fix 또는 compliance change.
망가졌는데 여기에 기록되지 않은 것이 있나요? support@fixvibe.app로 이메일을 보내주세요.
