// docs / changelog
更新日志
FixVibe 扫描引擎更新:新的覆盖范围、安全性改进和准确性改进。最新条目优先。
September 26, 2026
- 改进Clearer evidence for security header checks. Header checks now capture the response context needed to recheck a supported deployed fix. Unavailable, changed, or blocked responses do not count as proof that an issue is fixed. It also recognizes invalid MIME-sniffing protection values more accurately.
- 新增Known-vulnerability checks, September 2026. 16 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
2026年9月9日
- 新增Shai-Hulud. GitHub 仓库扫描现在可以发现与 2026 年 9 月 npm 攻击活动再次出现相关的有力证据,且无需下载或执行软件包。
2026年9月7日
- 修复扫描更加可靠。修复了扫描返回大型压缩响应的网站时出现的卡住问题。
- 改进扫描更加可靠。 大型扫描现在可以安全恢复,不会丢失已发现的问题。
2026-08-04
- 新增Known-vulnerability checks, August 2026. 7 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
2026年7月21日
- 新增Next.js WebSocket SSRF 依赖性咨询检查。 GitHub 存储库扫描现在可以标记 Next.js manifest 和lockfile 与 CVE-2026-44578 / GHSA-c4j6-fc7j-m34r 相关的证据。调查结果仍然基于版本,声明 Vercel 托管的部署不受影响,并且永远不会发送 WebSocket 升级、探测内部目标或要求实时 SSRF 确认。
- 新增Known-vulnerability checks, July 2026. 43 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
2026年7月13日
- 新增Injective Labs npm wallet-key stealer advisory check. Repo scans now flag package manifests and lockfiles resolving @injectivelabs/sdk-ts 1.20.21 or related @injectivelabs 1.20.21 packages tied to the compromised SDK. Findings stay version-based: FixVibe does not install packages, execute dependency code, derive wallets, contact exfiltration infrastructure, or claim key theft.
- 新增React Server Components CVE-2026-23864 advisory check. Repo scans now report npm manifest and lockfile evidence for react-server-dom-webpack, react-server-dom-parcel, or react-server-dom-turbopack versions affected by GHSA-83fc-fqcc-2hmg as version-based advisory context; they do not send crafted RSC requests, probe Server Function endpoints, crash-test services, or claim live denial-of-service confirmation.
2026-07-02
- 修复Legal-link false positives reduced. Privacy and terms links that are visible after client-side rendering now count correctly, so SPA footers are not reported as missing when users can see those links.
2026年6月30日
- 新增codfish semantic-release GitHub Action compromise check. Repo scans can now flag workflow YAML references to codfish/semantic-release-action refs associated with the June 2026 compromise, reporting source/config evidence only. The check does not run GitHub Actions, read CI secrets, inspect runners, or claim credential theft.
- 新增Known-vulnerability checks, June 2026. 67 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
June 18, 2026
- 新增Mastra easy-day-js advisory check. GitHub repo scans flag easy-day-js manifest and lockfile evidence tied to the June 2026 Mastra npm incident. The finding stays limited to repository dependency evidence and does not verify stale npm owners, run package scripts, inspect hosts, or assert credential theft.
June 14, 2026
- 修复DOM XSS fragment probe stability fix. Verified active scans now skip the DOM fragment probe cleanly when browser automation is unavailable at startup, so reports no longer show internal browser-context errors for that check.
- 改进Expanded Red Hat npm worm coverage. GitHub repo scans now include additional Wiz-reported @redhat-cloud-services package versions for the Miasma campaign, while still reporting repository dependency evidence without installing packages, executing lifecycle scripts, or claiming credential theft.
- 新增Known npm typosquat package check. GitHub repo scans can now flag package manifests and lockfiles that resolve Microsoft-reported vpmdhaj npm typosquat package versions, reporting version-based advisory evidence without installing packages, executing lifecycle scripts, fetching tarballs, contacting attacker infrastructure, or claiming credential theft.
- 新增Codex Remote UI token-stealing npm package check. GitHub repo scans can now flag package manifests and lockfiles that resolve codexui-android 0.1.82 or newer, reporting version-based advisory evidence without installing the package, executing it, reading Codex auth files, contacting exfiltration infrastructure, or claiming token theft.
- 新增Claude Code GitHub Action workflow repo check. GitHub repo scans can now flag Claude Code Action workflows with mutable action refs, broad workflow token permissions, or risky access override inputs, reporting workflow YAML evidence without running Actions, executing Claude Code, reading CI secrets, or claiming prompt-injection exploitation.
- 新增Node-gyp / Phantom Gyp npm worm repo check. GitHub repo scans can now flag package manifests or lockfiles that resolve known malicious npm package versions from the binding.gyp supply-chain campaign, or flag matching binding.gyp source evidence, without running npm install, executing node-gyp, downloading tarballs, or claiming credential theft.
June 11, 2026
- 新增TanStack ArkType adapter malware dependency check. GitHub repo scans can now flag package manifests and lockfiles that resolve @tanstack/arktype-adapter to malicious versions 1.166.12 or 1.166.15 from CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx, reporting version-based advisory evidence without running npm install, executing lifecycle scripts, downloading tarballs, or claiming credential theft.
- 新增Red Hat npm worm dependency advisory check. GitHub repo scans can now flag package manifests and lockfiles that resolve known compromised @redhat-cloud-services npm versions associated with the credential-stealing worm campaign, reporting dependency evidence without executing install scripts or claiming credential theft.
May 27, 2026
- 新增Known-vulnerability checks, May 2026. 33 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.
May 25, 2026
- 修复Active scan reliability and SSTI accuracy fix. Active scans now safely store response-derived evidence that contains unsupported control characters, and SSTI reporting requires stronger target-specific template-evaluation evidence instead of common page or static-asset content.
16 May 2026
- 新增Active scans via REST API and MCP. 现在可以从REST 和MCP 针对已从仪表板明确授权的已验证域触发主动扫描。授权可随时撤销。
- 新增Safer authorization levels for active scans. 域授权现在可以区分更安全的自动主动检查和更深入的主动测试,因此团队可以为每个域自动执行正确级别的验证。
- 新增First-use webhook for API/MCP active scans. 首次针对新授权的域运行 API/MCP-triggered 主动扫描时,Webhook 可以通知团队。
- 改进Improved Referrer-Policy findings. Missing or weak
Referrer-Policyresults now separate URL-referrer leakage from broad information exposure, show document-response evidence, and include generic plus static-host remediation guidance. - 改进Improved Permissions-Policy findings. Missing or weak
Permissions-Policyresults now show feature-level evidence, separate broad feature allowlists from missing hardening, and include generic plus static-host remediation guidance for common hosts, proxies, and app servers. - 改进Improved clickjacking header prompts. Missing
X-Frame-Optionsfindings now point agents to CSPframe-ancestorsas the modern protection, add Vercel/static SPA header guidance, and verifyx-frame-optionswith CSP. - 改进CSP header evidence and fix prompts improved. Missing-CSP 报告现在包括更清晰的托管和响应上下文以及更安全的框架感知修复指南。
- 修复Vercel path-probe false positives reduced. FixVibe 现在需要更强大的特定于应用程序的证据,然后才能报告部署中重写未知路由到应用程序 shell 的公开框架工件。
- 修复合规类发现不再带有误导性的 CWE 标签。此前 legal-compliance 检查会把"缺少隐私政策"和"缺少服务条款"标为
CWE-359(PII 暴露),但这并不能描述真正的差距。这些发现现在不再附带 CWE — 它们是合规事项,而非可分类的安全弱点。
2026 年 5 月 15 日
- 新增Repository secret leak check. GitHub repo scans can now flag hardcoded provider keys and other secrets committed to source, with evidence masked and the standard FixVibe rotation prompt included.
- 新增Vercel deployment protection check. 被动扫描现在可以标记公共
*.vercel.app生成的部署 URL,这些 URL 无需 Vercel 部署 Pro 保护即可响应,而现有标头检查将继续审核 CSP、HSTS 和浏览器强化。
2026 年 5 月 14 日
- 改进Firebase rules detection improved. BaaS 扫描现在可以检测更多Firebase 应用程序形状,并使用只读证据来识别有风险的公共数据暴露。
2026 年 5 月 13 日
- 新增Repo Supabase RLS migration check. GitHub 存储库扫描现在可以标记 Supabase SQL 迁移,这些迁移创建公共表而没有匹配的
ALTER TABLE ... ENABLE ROW LEVEL SECURITY语句。 - 新增Supabase Storage posture check. 被动扫描现在可以审查公共Supabase 存储桶和匿名对象列表暴露以及现有的RLS 和密钥检查。
- 新增AI-generated code guardrail check. GitHub 存储库扫描现在可以标记围绕代码扫描、秘密扫描、依赖项更新和 AI-agent 指令缺少的安全自动化。
2026 年 5 月 12 日
- 新增Repo web-app risk checklist. GitHub 回购扫描现在可以标记高可信度OWASP-风格的代码风险,例如原始SQL插值、不安全HTML接收器、凭证通配符CORS、禁用TLS验证和弱JWT秘密后备。
- 新增Next.js middleware-bypass check. 对已验证域的主动扫描现在可以在报告之前确认受中间件保护的路由上的 CVE-2025-29927 暴露情况,并且报告包括用于修复的标准 FixVibe AI 修复提示。
2026年5月9日
- 安全Cross-origin scope hardening. 主动扫描和客户端资产检查现在保留在授权的目标范围内,并避免跨跨源重定向携带客户提供的凭据。
- 修复Supabase RLS check is now strictly read-only. Supabase 姿势检查现在避免写入尝试并专注于安全暴露信号。验证域主动测试仍然是更深入确认的边界。
- 改进安全 header 发现项只适用于根 HTML 响应。在 204、JSON API、文件下载或 404 上缺失 CSP、Permissions-Policy、X-Frame-Options 或 Referrer-Policy 不再产生发现项。HSTS 和 X-Content-Type-Options 仍会跨所有响应评分。
- 改进Auth-flow and rate-limit checks now require stronger evidence. FixVibe 现在仅当应用程序行为明确支持该发现时才报告这些问题,从而减少来自通用错误页面和不受支持的方法的噪音。
- 改进File-upload findings tier by exploitability evidence. 文件上传报告现在将低置信度接受信号与有风险服务行为的更有力证据分开,从而减少对良性上传处理程序的过度严重性。
2026年5月7日
- 修复Threat-intel listing accuracy improved. FixVibe 现在可以区分真正的阻止列表证据和解析器诊断,因此威胁情报调查结果不会过度报告基础设施端查找响应。
- 新增GitHub 仓库扫描。连接 repo 后,FixVibe 会检查源码中泄露的 Supabase service keys、Firebase admin tokens、风险 workflow files 和过时依赖;整个过程无需加载你已部署的网站。参见 扫描类型。
- 新增针对高风险 JavaScript 的 SAST 检查。仓库扫描现在会标记
new Function()和setTimeout("string");当输入不可信时,二者都等价于eval()。 - 修复Vercel / Cloudflare 站点上的误报“exposed file”发现项。裸
403 Forbidden响应不再被报告为“file exists”;大多数边缘服务商无论文件是否存在,都会对可疑路径返回 403。现在我们要求有正向 HTTP 信号才会标记。 - 修复Repo-code false positives reduced. Repo 扫描现在可以避免在注释、文档、测试帮助程序和明显仅服务器上下文中标记安全术语,以进行多个高信号代码检查。
- 修复localStorage 中的 Supabase anon key 不再报告为 JWT-in-storage 发现项;anon key 本来就是公开给客户端使用的 token。浏览器存储中的真实 service-role tokens 现在会被标为 critical,标题也更清楚。
- 修复CSP weakness detection improved. Content-Security-Policy 检查现在可以捕获更宽松的源策略,同时将证据和补救措施集中在有效的浏览器策略上。
- 修复Reflected-XSS check tightened. 主动扫描现在需要更强的反射证据才能报告可执行上下文风险,从而减少页面上不相关标记的误报。
- 修复域名验证现在能正确处理 apex ↔ www 重定向,并且更清楚地说明 TXT-record Host 字段应该填哪个值。
格式
每个条目都有标签,方便你快速浏览:
- 新增 新的检查、surface 或功能。
- 改进 现有行为变得更好:更准确、更快、更清楚。
- 修复 我们发布过、随后修掉的 bug。
- 安全 加固、漏洞修复或合规变更。
发现这里没记录的破坏性变化?发邮件到 support@fixvibe.app。
