pullrequests Search Results · language:Dune language:HTML language:JavaScript language:JavaScript language:JavaScript is:unmerged
Filter by
59.7M results
Bumps posthog-js from 1.386.6 to 1.386.8. details summary Release notes /summary p em Sourced from a href=
https://github.com/PostHog/posthog-js/releases posthog-js s releases /a . /em /p blockquote h2 ...
Problem
The current web maze lacks convincing bait files, making it less effective at engaging attackers.
Solution
Added new file templates to the MAZE_FILES array in core/traps.js, including docker-compose.yml, ...
Status: ✅ Opt-in cutover flag. No default flip. No Firestore Rules change. No deploy. No legacy bundle edit.
Manual PASS (recorded)
?oriexAuthBridge=1 probe, first load: Auth user YES · __oxUid == auth ...
💡 What: Added aria-hidden= true to the decorative typewriter spans ( , |) and simulated terminal prompt symbols ($). 🎯
Why: Assistive technologies and screen readers were reading aloud these purely decorative ...
Bumps axios from 1.17.0 to 1.18.0. details summary Release notes /summary p em Sourced from a href=
https://github.com/axios/axios/releases axios s releases /a . /em /p blockquote h2 v1.18.0 — June 13, ...
dependencies
javascript
Motivation
- Provide a simple REST API for managing usuarios, clientes, proyectos and elementos and a companion admin UI to
create/manipulate them.
- Enforce administrator-only actions for creating ...
codex
🚨 Severity: HIGH 💡 Vulnerability: Cross-Site Scripting (XSS) in frontend templates. 🎯 Impact: Malicious data in
localStorage (e.g., player names, buy-ins, chip counts/values) could execute arbitrary JavaScript ...
Summary
Adds Google Authenticator–style (TOTP) two-factor auth to the admin console so a leaked password alone can t get anyone
in. Applies to every admin and superadmin; opt-in per account, with an optional ...