FixVibe

// docs / changelog

變更紀錄

FixVibe 掃描引擎更新:新的覆蓋範圍、安全性改進和準確性改進。最新條目優先。

September 26, 2026

  • 改進Clearer evidence for security header checks. Header checks now capture the response context needed to recheck a supported deployed fix. Unavailable, changed, or blocked responses do not count as proof that an issue is fixed. It also recognizes invalid MIME-sniffing protection values more accurately.
  • 新增Known-vulnerability checks, September 2026. 16 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.

2026年9月9日

  • 新增Shai-Hulud. GitHub 儲存庫掃描現在可以發現與 2026 年 9 月 npm 攻擊活動再次出現相關的有力證據,且無需下載或執行套件。

2026年9月7日

  • 修正掃描更可靠。修正了掃描傳回大型壓縮回應的網站時發生的卡住問題。
  • 改進掃描更可靠。 大型掃描現在可以安全恢復,不會遺失已發現的問題。

2026-08-04

  • 新增Known-vulnerability checks, August 2026. 7 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.

2026年7月21日

  • 新增Next.js WebSocket SSRF 依賴性諮詢檢查。 GitHub 儲存庫掃描現在可以標記與 CVE-2026-44578 / GHSA-c4j6-fc7j-m34r 相關的 Next.js 清單和鎖定檔案證據。調查結果仍然基於版本,聲明 Vercel 託管的部署不受影響,並且從不發送 WebSocket 升級、探測內部目標或要求即時 SSRF 確認。
  • 新增Known-vulnerability checks, July 2026. 43 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.

2026年7月13日

  • 新增Injective Labs npm wallet-key stealer advisory check. Repo scans now flag package manifests and lockfiles resolving @injectivelabs/sdk-ts 1.20.21 or related @injectivelabs 1.20.21 packages tied to the compromised SDK. Findings stay version-based: FixVibe does not install packages, execute dependency code, derive wallets, contact exfiltration infrastructure, or claim key theft.
  • 新增React Server Components CVE-2026-23864 advisory check. Repo scans now report npm manifest and lockfile evidence for react-server-dom-webpack, react-server-dom-parcel, or react-server-dom-turbopack versions affected by GHSA-83fc-fqcc-2hmg as version-based advisory context; they do not send crafted RSC requests, probe Server Function endpoints, crash-test services, or claim live denial-of-service confirmation.

2026-07-02

  • 修正Legal-link false positives reduced. Privacy and terms links that are visible after client-side rendering now count correctly, so SPA footers are not reported as missing when users can see those links.

2026年6月30日

  • 新增codfish semantic-release GitHub Action compromise check. Repo scans can now flag workflow YAML references to codfish/semantic-release-action refs associated with the June 2026 compromise, reporting source/config evidence only. The check does not run GitHub Actions, read CI secrets, inspect runners, or claim credential theft.
  • 新增Known-vulnerability checks, June 2026. 67 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.

June 18, 2026

  • 新增Mastra easy-day-js advisory check. GitHub repo scans flag easy-day-js manifest and lockfile evidence tied to the June 2026 Mastra npm incident. The finding stays limited to repository dependency evidence and does not verify stale npm owners, run package scripts, inspect hosts, or assert credential theft.

June 14, 2026

  • 修正DOM XSS fragment probe stability fix. Verified active scans now skip the DOM fragment probe cleanly when browser automation is unavailable at startup, so reports no longer show internal browser-context errors for that check.
  • 改進Expanded Red Hat npm worm coverage. GitHub repo scans now include additional Wiz-reported @redhat-cloud-services package versions for the Miasma campaign, while still reporting repository dependency evidence without installing packages, executing lifecycle scripts, or claiming credential theft.
  • 新增Known npm typosquat package check. GitHub repo scans can now flag package manifests and lockfiles that resolve Microsoft-reported vpmdhaj npm typosquat package versions, reporting version-based advisory evidence without installing packages, executing lifecycle scripts, fetching tarballs, contacting attacker infrastructure, or claiming credential theft.
  • 新增Codex Remote UI token-stealing npm package check. GitHub repo scans can now flag package manifests and lockfiles that resolve codexui-android 0.1.82 or newer, reporting version-based advisory evidence without installing the package, executing it, reading Codex auth files, contacting exfiltration infrastructure, or claiming token theft.
  • 新增Claude Code GitHub Action workflow repo check. GitHub repo scans can now flag Claude Code Action workflows with mutable action refs, broad workflow token permissions, or risky access override inputs, reporting workflow YAML evidence without running Actions, executing Claude Code, reading CI secrets, or claiming prompt-injection exploitation.
  • 新增Node-gyp / Phantom Gyp npm worm repo check. GitHub repo scans can now flag package manifests or lockfiles that resolve known malicious npm package versions from the binding.gyp supply-chain campaign, or flag matching binding.gyp source evidence, without running npm install, executing node-gyp, downloading tarballs, or claiming credential theft.

June 11, 2026

  • 新增TanStack ArkType adapter malware dependency check. GitHub repo scans can now flag package manifests and lockfiles that resolve @tanstack/arktype-adapter to malicious versions 1.166.12 or 1.166.15 from CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx, reporting version-based advisory evidence without running npm install, executing lifecycle scripts, downloading tarballs, or claiming credential theft.
  • 新增Red Hat npm worm dependency advisory check. GitHub repo scans can now flag package manifests and lockfiles that resolve known compromised @redhat-cloud-services npm versions associated with the credential-stealing worm campaign, reporting dependency evidence without executing install scripts or claiming credential theft.

May 27, 2026

  • 新增Known-vulnerability checks, May 2026. 33 new or refined checks for published vulnerabilities in open-source packages and self-hosted software, across repository and URL scans.

May 25, 2026

  • 修正Active scan reliability and SSTI accuracy fix. Active scans now safely store response-derived evidence that contains unsupported control characters, and SSTI reporting requires stronger target-specific template-evaluation evidence instead of common page or static-asset content.

16 May 2026

  • 新增Active scans via REST API and MCP. 現在可以從REST 和MCP 針對已從儀表板明確授權的已驗證網域觸發主動掃描。授權可隨時撤銷。
  • 新增Safer authorization levels for active scans. 網域授權現在可以區分更安全的自動主動檢查和更深入的主動測試,因此團隊可以為每個網域自動執行正確等級的驗證。
  • 新增First-use webhook for API/MCP active scans. 首次針對新授權的網域執行 API/MCP-triggered 主動掃描時,Webhook 可以通知團隊。
  • 改進Improved Referrer-Policy findings. Missing or weak Referrer-Policy results now separate URL-referrer leakage from broad information exposure, show document-response evidence, and include generic plus static-host remediation guidance.
  • 改進Improved Permissions-Policy findings. Missing or weak Permissions-Policy results now show feature-level evidence, separate broad feature allowlists from missing hardening, and include generic plus static-host remediation guidance for common hosts, proxies, and app servers.
  • 改進Improved clickjacking header prompts. Missing X-Frame-Options findings now point agents to CSP frame-ancestors as the modern protection, add Vercel/static SPA header guidance, and verify x-frame-options with CSP.
  • 改進CSP header evidence and fix prompts improved. Missing-CSP 報告現在包括更清晰的託管和回應上下文以及更安全的框架感知修復指南。
  • 修正Vercel path-probe false positives reduced. FixVibe 現在需要更強大的特定應用程式的證據,然後才能報告部署中重寫未知路由到應用程式 shell 的公開框架工件。
  • 修正合規類發現不再帶有誤導性的 CWE 標籤。先前 legal-compliance 檢查會把「缺少隱私政策」與「缺少服務條款」標示為 CWE-359(PII 暴露),但這並不能描述實際的落差。這些發現現在不再附帶 CWE — 它們是合規事項,而非可分類的安全弱點。

2026 年 5 月 15 日

  • 新增Repository secret leak check. GitHub repo scans can now flag hardcoded provider keys and other secrets committed to source, with evidence masked and the standard FixVibe rotation prompt included.
  • 新增Vercel deployment protection check. 被動掃描現在可以標記公開 *.vercel.app 產生的部署 URL,這些 URL 無需 Vercel 部署 Pro 保護即可回應,而現有標頭檢查將繼續審核 CSP、HSTS 和瀏覽器強化。

2026 年 5 月 14 日

  • 改進Firebase rules detection improved. BaaS 掃描現在可以檢測更多Firebase 應用程式形狀,並使用唯讀證據來識別有風險的公共資料暴露。

2026 年 5 月 13 日

  • 新增Repo Supabase RLS migration check. GitHub 儲存庫掃描現在可以標記 Supabase SQL 遷移,這些遷移會建立公用表而沒有符合的 ALTER TABLE ... ENABLE ROW LEVEL SECURITY 語句。
  • 新增Supabase Storage posture check. 被動掃描現在可以審查公共Supabase 儲存桶和匿名物件清單暴露以及現有的RLS 和金鑰檢查。
  • 新增AI-generated code guardrail check. GitHub 儲存庫掃描現在可以標記圍繞程式碼掃描、秘密掃描、依賴項更新和 AI-agent 指令缺少的安全自動化。

2026 年 5 月 12 日

  • 新增Repo web-app risk checklist. GitHub 回購掃描現在可以標記高可信度OWASP-風格的代碼風險,例如原始SQL插值、不安全HTML接收器、憑證通配符CORS、禁用TLS驗證和弱JWT秘密後備。
  • 新增Next.js middleware-bypass check. 對已驗證網域的主動掃描現在可以在報告之前確認受中間件保護的路由上的 CVE-2025-29927 暴露情況,並且報告包括用於修復的標準 FixVibe AI 修復提示。

2026 年 5 月 9 日

  • 安全Cross-origin scope hardening. 主動掃描和用戶端資產檢查現在保留在授權的目標範圍內,並避免跨跨來源重定向攜帶客戶提供的憑證。
  • 修正Supabase RLS check is now strictly read-only. Supabase 姿勢檢查現在避免寫入嘗試並專注於安全暴露訊號。驗證域主動測試仍然是更深入確認的邊界。
  • 改進Security-header findings 只套用於 root HTML responses。 204、JSON API、file download 或 404 上缺少 CSP、Permissions-Policy、X-Frame-Options 或 Referrer-Policy,不再產生 finding。HSTS 與 X-Content-Type-Options 仍會跨所有 responses 評分。
  • 改進Auth-flow and rate-limit checks now require stronger evidence. FixVibe 現在僅當應用程式行為明確支持該發現時才報告這些問題,從而減少來自通用錯誤頁面和不受支援的方法的噪音。
  • 改進File-upload findings tier by exploitability evidence. 文件上傳報告現在將低置信度接受訊號與有風險服務行為的更有力證據分開,從而減少對良性上傳處理程序的過度嚴重性。

2026 年 5 月 7 日

  • 修正Threat-intel listing accuracy improved. FixVibe 現在可以區分真正的阻止清單證據和解析器診斷,因此威脅情報調查結果不會過度報告基礎設施端查找回應。
  • 新增GitHub repo scans。 連接 repo 後,FixVibe 會檢查原始碼中是否有 leaked Supabase service keys、Firebase admin tokens、risky workflow files 與 outdated dependencies,而且完全不需要載入你部署的網站。請見 掃描類型。
  • 新增針對高風險 JavaScript 的 SAST checks。 Repo scans 現在會標記 new Function() 與 setTimeout("string");在餵入不受信任輸入時,兩者都等同於 eval()。
  • 修正Vercel / Cloudflare sites 上的 false「exposed file」findings。 裸 403 Forbidden responses 不再被報告為「file exists」;大多數 edge providers 對看起來可疑的 paths 都會回傳 403,不論檔案是否存在。現在必須有正向 HTTP signal 才會標記。
  • 修正Repo-code false positives reduced. Repo 掃描現在可以避免在註釋、文件、測試幫助程序和明顯僅伺服器上下文中標記安全術語,以進行多個高信號代碼檢查。
  • 修正localStorage 中的 Supabase anon key 不再被報告為 JWT-in-storage finding;anon key 是公開預期的 client token。瀏覽器 storage 中真正的 service-role tokens 現在會是 critical,且標題更清楚。
  • 修正CSP weakness detection improved. Content-Security-Policy 檢查現在可以捕捉更寬鬆的來源策略,同時將證據和補救措施集中在有效的瀏覽器策略上。
  • 修正Reflected-XSS check tightened. 主動掃描現在需要更強的反射證據才能報告可執行上下文風險,從而減少頁面上不相關標記的誤報。
  • 修正Domain verification 會正確處理 apex ↔ www redirects,並更清楚說明 TXT-record Host 欄位應填入哪個值。

格式

每個項目都有標籤,方便你快速瀏覽:

  • 新增 新的 check、surface 或 feature。
  • 改進 既有行為變得更好:更準確、更快、更清楚。
  • 修正 我們已發布、後來修掉的 bug。
  • 安全 強化、漏洞修正或合規變更。

發現有東西壞了但這裡沒記錄?請 email support@fixvibe.app。

變更紀錄 — Docs · FixVibe