pullrequests Search Results · language:Dune language:JavaScript language:JavaScript language:TypeScript language:Python
Filter by
231M results
Summary
- Total alerts found (via pip-audit + npm audit): 11 packages with CVEs
- Fixed: 4 | Skipped: 7
Alert Details
FIXED
1 — aiohttp (Python) · 8 CVEs · Medium/High
- Package: aiohttp==3.14.0 ...
Bumps starlette from 0.45.3 to 1.3.1. details summary Release notes /summary p em Sourced from a href=
https://github.com/Kludex/starlette/releases starlette s releases /a . /em /p blockquote h2 Version ...
dependencies
python:uv
Bumps @angular/common from 19.2.20 to 20.3.25. details summary Release notes /summary p em Sourced from a href=
https://github.com/angular/angular/releases @angular/common s releases /a . /em /p blockquote ...
dependencies
javascript
Hardens the dependency tree and fixes correctness/security findings, with no functional changes to the app.
Dependencies / advisories
- Clear all critical + 3 high npm advisories (low-risk subset) ...
baseURL did two unrelated jobs. It was the stable identity of the auth server (OAuth/OIDC issuer, JWT iss/aud,
social-login redirect_uri, Passkey relying-party id), and in its object form it was also a ...
core
credentials
database
devops
devtools
docs
enterprise
identity
oauth
organization
security
概要
Claude Code on the web 環境でのセッション起動時に、プロジェクト依存の自動インストールと Python パス設定を行うためのセットアップフックを追加しました。
変更内容
- .claude/hooks/session-start.sh (新規)
- Claude Code on the web 環境(CLAUDE_CODE_REMOTE=true)でのみ実行されるセットアップスクリプト ...
问题
pr-gate 的 npm audit --audit-level=high --omit=dev(生产依赖,high+critical)因新披露的 form-data CRLF 注入 high
CVE(GHSA-hmw2-7cc7-3qxx)开始挂红 → 阻塞所有新 PR(main 之前绿是漏洞还没披露)。
修复
npm audit fix --package-lock-only:受影响传递依赖按 ...
Summary
This PR improves the cost breakdown dashboard cards by extracting a reusable tooltip component, updating typography
scales, and enhancing card labels with contextual information.
Key Changes ...
Root cause
The looks_like_assembly check in _handle_oversize tests whether a FORMAT 5 sub-project is the final assembly step (which
the harness handles itself and should skip). The goal-text branch of ...