pullrequests Search Results · language:Dune language:TypeScript language:HTML language:JavaScript language:TypeScript
Filter by
202M results
What
Removes the (.labels | map(.name) | contains([ spec-hold ]) | not) jq filter clause from the cron pipeline scripts.
Why
The 2026-06-09 policy change made spec-hold a non-blocking state (no human ...
Session 8 — Bounty Report Drafts (Jun 10, 2026)
What s in this PR
1 new HackerOne submission draft + TRIAGE.md updated with full session 8 assessment.
New Draft: Moneybird DOM XSS
File: bounty-pool/pending/2026-06-10-moneybird-xss-homepage.md ...
Description
PR #534 was merged with a build-breaking bug: Zod schemas and constants were defined inline inside the use server
actions file (actions.ts). Next.js enforces that use server files can only ...
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
| --- | --- | --- | --- | --- | --- |
| prettier (source) | 3.8.3 → 3.8.4 | age | adoption | passing ...
dependencies
Bumps brace-expansion from 1.1.11 to 1.1.15. details summary Release notes /summary p em Sourced from a href=
https://github.com/juliangruber/brace-expansion/releases brace-expansion s releases /a . /em ...
dependencies
javascript
Change the partitioned /nested queue example to match what we see in the field most often
Comment-only cleanup — the long header blocks (10-20 lines) in the actions, pages, utils, constants and the
browser-context spec were trimmed to a few to-the-point lines. No code/behaviour change.
Files: ...
Summary
Round 3: fixes from a full project audit (security + quality), post v3.9.5.
Security
- Sanitize auto-update release notes (UpdateModal.tsx): releaseNotes was injected via dangerouslySetInnerHTML ...
Re-do of Dependabot PR #41 on a normal (non-Dependabot) branch so the CI test_libraries job runs with repository
secrets.
#41 s only failing check was test_libraries, and every failure was Error: baseUrl ...