pullrequests Search Results · language:Dune language:JavaScript language:Java language:JavaScript language:Python language:Python
Filter by
183M results
Closes #330
Summary
Lowers the bar for when the model is told to call create_update_todos as its first action when enable_todos=true. Two
lines in mcp_prompt.jinja2, both gated by {% if enable_todos ...
enhancement
🤖 AI Security Remediation
🟢 Auto-merge eligible — will merge after CI passes.
📊 Analysis
- Severity: LOW
- Confidence: 95%
- Auto-fix allowed: True
📝 Summary
The application uses the subprocess ...
ai-remediation
severity-low
- Expand play area to use the full center+right dashboard width
- Move active definition directly below the full-width header
- Remove redundant level text from header title (level stays in badge) ...
🚨 Severity: MEDIUM (Security Enhancement) 💡 Vulnerability: Lack of Content Security Policy (CSP) 🎯 Impact: Without a
CSP, the application is more vulnerable to Cross-Site Scripting (XSS) and other data ...
Problem (IO-21)
Scam / unrealistically-low buy orders (placed far below an item s value) made materials look almost free, corrupting
profitability and make-vs-buy decisions in both the Chain and Basics ...
Bumps the npm_and_yarn group with 1 update in the /plugins/arcanon directory: js-yaml.
Updates js-yaml from 4.1.1 to 4.2.0 details summary Changelog /summary p em Sourced from a href=
https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md ...
dependencies
javascript
Description
The mobile search input in the Navbar lost focus after typing the first character because the parent component
re-rendered on every setSearchQuery call. Extracted the mobile search overlay ...
bug
enhancement
frontend
gssoc
gssoc26
nsoc
NSoC'26
pending-review
Summary
- Detect Hermes channel_skill_bindings and mark those skills as channel-bound/high-blast-radius.
- Protect channel-bound skills from unattended autorun writes by default.
- Enforce a 12k ...
Description:
The embedded Plugin Page runs inside a sandboxed iframe without allow-modals , so window.confirm() calls are silently
blocked by the browser. This caused all batch operations (approve/reject/delete) ...