pullrequests Search Results · language:Dune language:Python language:JavaScript language:CSS language:JavaScript is:public
Filter by
156M results
Pull Request..
Summary
- add user docs for claim boundaries, false-green runtime states, and self-verification
- link the new trust docs from docs/README.md and docs/user/README.md
- add a Trust Surfaces section ...
This PR contains the following updates:
| Package | Type | Update | Change |
| --- | --- | --- | --- |
| ghcr.io/astral-sh/uv | final | patch | 0.11.19 → 0.11.20 |
Release Notes
details summary astral-sh/uv ...
改进内容
1. eval() → AST-restricted evaluator (vnpy/alpha/dataset/utility.py)
calculate_by_expression() previously passed user expression strings directly to eval(), which can be exploited via
attribute ...
🤖 AI Security Remediation
🟢 Auto-merge eligible — will merge after CI passes.
📊 Analysis
- Severity: MEDIUM
- Confidence: 85%
- Auto-fix allowed: True
📝 Summary
The application uses the subprocess ...
ai-remediation
severity-medium
Bumps actions/setup-node from 4 to 6. details summary Release notes /summary p em Sourced from a href=
https://github.com/actions/setup-node/releases actions/setup-node s releases /a . /em /p blockquote ...
dependencies
security
背景
承接 RIO/唐小轻接入后,用户在前端发现几个口径问题,延伸出一条 伪爆贴(synthetic)必须是全局最高优先级、不止看板、连飞轮都不能污染 的修复线。本 PR 把这一串收口。
改动
1. 伪爆贴(synthetic)= 全局最高优先级 ⭐(核心)
原则:笔记状态「关注」(人工刷的假指标)或 RIO opt-in(状态标爆但无曝光)= 指标不可信 → 不管 tier 怎么来的都不算爆款,看板/飞轮一律剔除。 ...
| | |
| :-- | :-- |
| Related Issue(s) | |
| Has Unit Tests (y/n) | |
| Documentation Included (y/n) | |
Change Description
- Update to latest dict
- Load Fw type aliases from dict
- Fix all ...