Changelog

What shipped, when. RSS and email subscribe below.

launch

Securie opens managed access

Public OSS can start on the capped verification path. Private repos use managed plans with proof runs, tested repairs, deploy gates, and evidence. Initial focus: TypeScript + Next.js + Supabase + Vercel.

feature

Security review requests open

Request a review at /scan. Securie routes each repo to the right path: capped public OSS verification or a managed private plan. Initial coverage includes Supabase RLS, leaked secrets, and broken auth (BOLA/IDOR).

research

Vibe Leak Index published

Live dataset of publicly-reachable AI-built app security posture. 14.3% ship with an exposed credential; 11.2% have Supabase RLS disabled. Full methodology at /research/vibe-leak-index.

content

CVE library + leak playbooks

Plain-English CVE pages and vendor-specific leak playbooks went live. Six CVEs and six key-rotation playbooks at /vuln and /leak respectively. More added weekly.

feature

GitHub App and Vercel Integration live

One-click install. The GitHub App watches every pull request; the Vercel Integration gates every deploy. Public OSS can use the capped verification path.