Skip to content

pullrequests Search Results · language:Dune language:Python language:JavaScript language:CSS language:JavaScript is:public

Filter by

156M results  (2 s)

156M results

Pull Request..

Summary - add user docs for claim boundaries, false-green runtime states, and self-verification - link the new trust docs from docs/README.md and docs/user/README.md - add a Trust Surfaces section ...

This PR contains the following updates: | Package | Type | Update | Change | | --- | --- | --- | --- | | ghcr.io/astral-sh/uv | final | patch | 0.11.19 → 0.11.20 | Release Notes details summary astral-sh/uv ...

改进内容 1. eval() → AST-restricted evaluator (vnpy/alpha/dataset/utility.py) calculate_by_expression() previously passed user expression strings directly to eval(), which can be exploited via attribute ...

🤖 AI Security Remediation 🟢 Auto-merge eligible — will merge after CI passes. 📊 Analysis - Severity: MEDIUM - Confidence: 85% - Auto-fix allowed: True 📝 Summary The application uses the subprocess ...
ai-remediation
severity-medium

Bumps actions/setup-node from 4 to 6. details summary Release notes /summary p em Sourced from a href= https://github.com/actions/setup-node/releases actions/setup-node s releases /a . /em /p blockquote ...
dependencies
security

背景 承接 RIO/唐小轻接入后,用户在前端发现几个口径问题,延伸出一条 伪爆贴(synthetic)必须是全局最高优先级、不止看板、连飞轮都不能污染 的修复线。本 PR 把这一串收口。 改动 1. 伪爆贴(synthetic)= 全局最高优先级 ⭐(核心) 原则:笔记状态「关注」(人工刷的假指标)或 RIO opt-in(状态标爆但无曝光)= 指标不可信 → 不管 tier 怎么来的都不算爆款,看板/飞轮一律剔除。 ...

| | | | :-- | :-- | | Related Issue(s) | | | Has Unit Tests (y/n) | | | Documentation Included (y/n) | | Change Description - Update to latest dict - Load Fw type aliases from dict - Fix all ...