Niro v0.1.79
Summary
Third-party component coverage now includes offline dependency advisory scanning.
Changes
- Pentests inventory runtime dependencies and use a bundled vulnerability database to identify advisory candidates for live validation.
Security
- Dependency advisory matching runs offline inside the attack-tool sandbox.
Compatibility and upgrade
No action required.
Known issues
checksums.txtdoes not coverniro.mcpb.- Release artifacts have no detached signatures, provenance attestation, or SBOM.