pullrequests Search Results · language:Dune language:Python language:Python language:JavaScript language:JavaScript language:Java
Filter by
182M results
This PR contains the following updates:
| Package | Change | Age | Confidence |
| --- | --- | --- | --- |
| turbo (source) | 2.9.14 → 2.9.18 | age | confidence |
Release Notes
details summary vercel/turborepo ...
Audit report
No fixable problems found (7 unfixable, 25 only fixable manually using --force)
3. to review
dependencies
TL;DR
The script tag at line 18 loads react-cache from unpkg.com without a Subresource Integrity (SRI) hash. A compromised
CDN, BGP hijack, or man-in-the-middle attack could serve malicious JavaScript. ...
🤖 AI Security Remediation
🟢 Auto-merge eligible — will merge after CI passes.
📊 Analysis
- Severity: MEDIUM
- Confidence: 85%
- Auto-fix allowed: True
📝 Summary
The application uses the subprocess ...
ai-remediation
severity-medium
The recursive serve path carried the 5 holiday features frozen from the last history row → future holidays invisible.
They re deterministic functions of the forecast date, exactly like the calendar features ...
Builds on the sleep-until-window scheduling (already on main) to make the autofill reliable despite GitHub s flaky
scheduler, and adds a substantial test pass on the previously-untested internals. Review ...
See Commits and Changes for more details.
Created by img src= https://prod.download/pull-18h-svg valign= bottom / pull[bot] (v2.0.0-alpha.4)
Can you help keep this open source service alive? 💖 Please ...
⤵️ pull
Summary
- Re-plans #1233 against the current base. After #1657 consolidated section 3 s repeated build the missing gate; do
not rely on memory framing into one canonical lead bullet, the issue s ...
See Commits and Changes for more details.
Created by img src= https://prod.download/pull-18h-svg valign= bottom / pull[bot] (v2.0.0-alpha.4)
Can you help keep this open source service alive? 💖 Please ...
⤵️ pull
Closes #252
Generated with Claude Code