NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #3113 by repository stars
Last release 1 months ago
30 Aug 2026
Release timing varies
gaps range from 2 weeks to 6 months
Some releases are documented
notes for 11 of 33 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
88 releases · first in 2023
One column per quarter.
Psychic signature ( CVE-2022-21449 )
Six new automated checks, all auto-run when they apply to the token under test:
jwk header injectionjku header injectionx5c header injectionx5u header injectionNew flag --only-scans-above-threshold (default false). Skips any check whose max possible CVSS is below --severity-threshold before the scan runs. Since every check that then runs can reach the threshold.
Scan execution now runs on cerberauth/harnessx and reporting on cerberauth/reportx.
serve command removed. The HTTP server (api/ package, all vulnapi serve endpoints) was not properly designed and has been removed. vulnapi serve now just prints a deprecation notice and exits 0. The server is deprecated for now, pending a new implementation. Track progress / share ideas: #303Full Changelog: v0.9.0...v0.10.0
Fix URL typo in jwt-weak-secret vulnerability report by @MichaelMVS in #290
Full Changelog: v0.8.10...v0.9.0
Nothing published for this version
Nothing published for this version
chore(deps): update golangci/golangci-lint-action action to v8 by @renovate [bot] in #260
Full Changelog: v0.8.9...v0.8.10
Nothing published for this version
Nothing published for this version
feat: update dependencies by @emmanuelgautier in #257
Full Changelog: v0.8.8...v0.8.9
Nothing published for this version
Link scans to issues in reports
Full Changelog: v0.8.7...v0.8.8
Nothing published for this version
Add Healthcheck endpoints discovery scan by @emmanuelgautier in #241
Full Changelog: v0.8.6...v0.8.7
Nothing published for this version
Discover Well-Known paths and leaked files by @emmanuelgautier in #240
Full Changelog: v0.8.5...v0.8.6
Add HTTP Basic support by @emmanuelgautier in #231
Full Changelog: v0.8.4...v0.8.5
Nothing published for this version
Nothing published for this version
Refactor security schemes by @emmanuelgautier in #221
Full Changelog: v0.8.3...v0.8.4
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Add HTTP Misconfigurations scans by @emmanuelgautier in #208
Full Changelog: v0.8.2...v0.8.3
Nothing published for this version
Add golangci lint by @emmanuelgautier in #198
Full Changelog: v0.8.1...v0.8.2
Special thanks to @Maxouhell for providing valuable feedback and helping with the design of the file report.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →