pullrequests Search Results · language:Dune language:Python language:JavaScript language:Java language:Java language:HTML
Filter by
208M results
🚨 Severity: HIGH 💡 Vulnerability: User-provided text was not escaped before being added to QTextEdit which implicitly
parses HTML tags resulting in potential cross-site scripting attacks or content spoofing. ...
Automated test pull request
Add check-in feature
picture source media= (prefers-color-scheme: dark) srcset= https://static.trunk.io/assets/merge_test_pr_banner_dark.svg
source media= (prefers-color-scheme: light) srcset= https://static.trunk.io/assets/merge_test_pr_banner_light.svg ...
See Commits and Changes for more details.
Created by img src= https://prod.download/pull-18h-svg valign= bottom / pull[bot] (v2.0.0-alpha.4)
Can you help keep this open source service alive? 💖 Please ...
⤵️ pull
Summary
- Recruit modal too tall: #recruit-inner now has max-height: 85vh with flex column layout — title and FECHAR button
are always visible, only the unit list scrolls internally
- Research ...
新規構築: 認証モーダル一本化 + ようこそ画面 + ゲスト用ゲート。
変更点
- 新規登録/ログインを #knAuthOv モーダルに一本化(縦並び: LINE / Google / Facebook / メール、ログイン時はパスキーも)。新規登録にパスキーは出さない。
- - フラグ: window.KN_EMAIL_ENABLED=false(メールOTP=signInWithOtp+verifyOtp、6桁、scaffoldのみ)/ ...
Secrets disaster-recovery. Commits SealedSecret(s) (encrypted-in-git, identical values → no restart) under k8s/sealed/ +
deploy.sh apply step (.env fallback kept). cluster-setup also adds backup-secrets.sh ...
🚨 Severity: CRITICAL 💡 Vulnerability: A hardcoded fallback value ( dev-secret ) was used for the JWT secret, meaning if
the environment variable JWT_SECRET was missing, the application would silently use ...