Pull Request Explorer
| Title | Author | Size | AI | Cycle Time | Review | Merged |
|---|---|---|---|---|---|---|
| chore(client): bump resolution pins to fix 72 Dependabot alerts | subrata71 | L | AI | 28.7h | 0.1h | Jun 02, 2026 |
SummaryChoreBump dependency resolution pins to fix 72 alerts This PR updates Yarn resolution overrides to address 72 open Dependabot security alerts across 19 npm packages, reducing vulnerability risk and ensuring application stability. No application code changes were made, making it a low‑impact maintenance update. Health Assessment
Medium
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack |
||||||
| fix(client): replace innerHTML and dangerouslySetInnerHTML with safe alternatives | subrata71 | L | AI | 279.7h | 0.1h | Jun 02, 2026 |
SummaryBug FixReplace unsafe DOM manipulation with safe alternatives Fixes XSS vulnerabilities in client UI, improving security and user trust. Health Assessment
Medium
High
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript, Javascript
Frameworks:
React
|
||||||
| chore: modified test-pw command to avoid failures | sondermanish | S | AI | 2.2h | 0.1h | May 29, 2026 |
SummaryCI/CDModify test-pw command to avoid failures Ensures the test workflow runs reliably by normalizing image names and environment arguments, reducing flaky test failures. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Yaml
Frameworks:
Github-Actions
|
||||||
| 28/05/2026 Promotion | btsgh | XL | No | 0.2h | 0.1h | May 28, 2026 |
SummaryHealth AssessmentAI Details
Confidence:
0.95
Tech Stack
Languages:
Typescript, Javascript, Shell, Yaml
Frameworks:
Github-Actions, Docker
|
||||||
| chore(docker): use single xcaddy-built Caddy binary | wyattwalter | S | AI | 335.9h | 2.4h | May 27, 2026 |
SummaryChoreUse single xcaddy-built Caddy binary Reduces maintenance overhead and improves security by eliminating the need for a separate vanilla Caddy binary, ensuring compatibility with restricted security profiles. Health Assessment
Small
Low
Low
AI Details
Usage:
Authored by AI
Category:
Both AI
Tools:
Claude, CodeRabbit
Confidence:
0.95
Tech Stack
Frameworks:
Docker
|
||||||
| fix(security): apply full non-routable IP-class filter on WebClient (GHSA-v49v-673j-g4vj, GHSA-m23h-pvf3-2m7p) | wyattwalter | M | AI | 18.6h | 0.1h | May 27, 2026 |
SummaryBug FixFix security: block non‑routable IP classes on WebClient Strengthens outbound request validation by blocking additional non‑routable IP address classes, preventing potential security vulnerabilities in Docker deployments. Ensures only legitimate external hosts are reachable, reducing attack surface. Health Assessment
Small
Low
Low
AI Details
Usage:
Authored by AI
Category:
Both AI
Tools:
Claude, CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Java
|
||||||
| fix(docker): build MongoDB database tools from source with patched x/crypto and x/net | subrata71 | S | AI | 0.9h | 0.1h | May 27, 2026 |
SummaryBug FixBuild MongoDB tools from source with patched dependencies Eliminates critical CVEs by compiling MongoDB database tools with updated Go crypto and net libraries, ensuring secure and reliable database tooling in Docker images. This change improves security posture and build consistency for Appsmith deployments. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Frameworks:
Docker
|
||||||
| docs(security): direct vulnerability reports to GitHub security advisories | wyattwalter | XS | AI | 1.0h | 0.0h | May 26, 2026 |
SummaryDocsDirect vulnerability reports to GitHub advisories Updates security documentation to route vulnerability reports to GitHub's private reporting form, improving incident handling. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Assisted
Category:
Both AI
Tools:
Claude, CodeRabbit
Confidence:
0.95
Tech Stack |
||||||
| fix(security): bind Caddy admin to local socket (GHSA-8jvv-gwqg-6vjc) | wyattwalter | S | AI | 1.9h | 0.1h | May 26, 2026 |
SummaryBug FixBind Caddy admin to local Unix socket Security fix: Caddy admin endpoint now uses a Unix socket, reducing exposure and isolating Prometheus metrics on port 2019. Health Assessment
Small
Low
Low
AI Details
Usage:
Authored by AI
Category:
Both AI
Tools:
Claude, CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Javascript
|
||||||
| fix(security): add path traversal validation to widget save path (GHSA-r553-q33m-v7pf) | subrata71 | M | AI | 125.0h | 0.1h | May 26, 2026 |
SummaryBug FixAdd path traversal validation to widget save path Fixes a security vulnerability by validating widget names to prevent path traversal during Git serialization, ensuring user-controlled names cannot write files outside the repository. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Both AI
Tools:
CodeRabbit, Copilot
Confidence:
0.95
Tech Stack
Languages:
Java
|
||||||
| fix(security): remove unused supervisord admin port (GHSA-v49v-673j-g4vj) | wyattwalter | S | AI | 116.5h | 116.5h | May 26, 2026 |
SummaryBug FixRemove unused supervisord admin port Eliminates an unused supervisor HTTP interface, reducing the attack surface and simplifying container configuration. Health Assessment
Small
Medium
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Javascript
|
||||||
| fix(test): resolve flaky DSCrudAndBindings_Spec after-hook cleanup failure | subrata71 | XS | No | 114.5h | 0.1h | May 25, 2026 |
SummaryTestFix flaky Cypress spec after-hook cleanup Resolved deterministic failure in Cypress test by ensuring correct workspace selection and merging interdependent tests, improving CI stability. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| fix(husky): stage server files from worktree root in pre-commit hook | wyattwalter | S | AI | 24.0h | 4.4h | May 22, 2026 |
SummaryBug FixFix husky pre-commit hook staging issue The pre-commit hook now stages server files correctly when committing from linked worktrees, preventing duplicate orphan entries. This improves developer workflow and reduces potential build failures. Health Assessment
Small
Low
Low
AI Details
Usage:
Authored by AI
Category:
Both AI
Tools:
Claude, CodeRabbit
Confidence:
0.95
Tech Stack |
||||||
| fix(ci): add non-root USER to cypress snapshot Dockerfile | subrata71 | XS | AI | 89.4h | 54.4h | May 22, 2026 |
SummaryChoreAdd non-root user to Cypress Dockerfile Improves security and reduces image size for Cypress test containers by switching to a non-root user and cleaning up package lists. Health Assessment
Small
Low
High
AI Details
Usage:
AI Assisted
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Frameworks:
Docker
|
||||||
| fix(security): enforce MANAGE_PAGES permission in dependencyMap update (GHSA-q4p7-j55w-5mjm) | subrata71 | S | AI | 21.5h | 15.3h | May 20, 2026 |
SummaryBug FixEnforce MANAGE_PAGES permission in dependencyMap update Fixes a high‑severity authorization flaw that let any authenticated user alter other workspaces’ page dependency maps. This protects user data and ensures proper access control. Health Assessment
Small
Medium
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Java
|
||||||
| feat(diagnostics): add memory-analysis.sh for sizing diagnostics | wyattwalter | XL | AI | 142.7h | 0.1h | May 20, 2026 |
SummaryFeatureAdd memory-analysis script for diagnostics Provides a single-page memory diagnostic to help support teams quickly assess container memory usage, improving troubleshooting and reducing downtime. Health Assessment
X-Large
Medium
Medium
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Shell
|
||||||
| fix(helm): allow numeric cpu in resources.requests | wyattwalter | S | AI | 41.2h | 0.1h | May 20, 2026 |
SummaryBug FixAllow numeric CPU values in Helm chart Helm chart updated to accept numeric CPU values for resource requests, improving deployment flexibility. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Both AI
Tools:
Claude, CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Yaml
Frameworks:
Helm
|
||||||
| 10/05/26 Promotion | btsgh | XL | No | 0.2h | 0.1h | May 20, 2026 |
SummaryBug FixFix security, validation, and restore issues for promotion This PR addresses critical security vulnerability CVE-2026-42198, improves validation of Git repo URLs and user invitation origins, and ensures Redis credentials are preserved during restore, enhancing system stability and security for the upcoming release. Health Assessment
X-Large
High
Low
AI Details
Confidence:
0.95
Tech Stack
Languages:
Typescript, Java
|
||||||
| fix(server): validate origin before persisting invited users (APP-15239) | subrata71 | M | AI | 23.1h | 0.1h | May 20, 2026 |
SummaryBug FixValidate origin before persisting invited users Ensures that user invitations are fully validated before any database writes, preventing partial or orphaned invitations and improving security and user experience. This fix stops users from being added to workspaces when the origin header is invalid, reducing potential security risks. Health AssessmentAI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Java
|
||||||
| fix: preserve Redis credentials during appsmithctl restore | wyattwalter | S | AI | 15.6h | 0.1h | May 20, 2026 |
SummaryBug FixFix Redis credential leakage during restore Ensures Redis credentials are not leaked in backups and restores use target instance credentials, preventing authentication failures. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| fix(security): upgrade postgresql-jdbc to 42.7.11 to remediate CVE-2026-42198 | subrata71 | S | AI | 119.7h | 95.6h | May 19, 2026 |
SummaryBug FixUpgrade PostgreSQL JDBC to address CVE-2026-42198 This PR updates the PostgreSQL JDBC driver to version 42.7.11, fixing a high‑severity denial‑of‑service vulnerability that could allow attackers to exhaust server CPU resources. The change also adjusts interval formatting to remain compatible with the new driver behavior. Health Assessment
Small
Medium
High
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript, Java
|
||||||
| fix: added validation of git repo url | sondermanish | S | AI | 71.0h | 2.2h | May 18, 2026 |
SummaryBug FixAdd validation for Git repository URLs Improves validation of Git repository URLs to reject invalid configurations containing directory path references, enhancing security and preventing misconfigurations. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Java
|
||||||
| perf: bulk action import caching | sondermanish | XL | AI | 37.2h | 0.1h | May 15, 2026 |
SummaryChoreImprove bulk action import performance Enhances import pipeline by caching bulk actions, reducing latency and resource usage. This change improves user experience during large data imports. Health Assessment
X-Large
Medium
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Java
|
||||||
| 14/05/2026 - Promotion | btsgh | XL | No | 1.2h | 1.1h | May 14, 2026 |
SummaryCI/CDUpgrade MongoDB and enhance CI/CD pipelines This PR upgrades embedded MongoDB to 7.0, updates Helm chart values, and adds new CI workflows for Playwright and Helm releases, improving security and build reliability. Health AssessmentAI Details
Usage:
AI Assisted
Category:
Code AI
Tools:
Cursor
Confidence:
0.95
Tech Stack
Languages:
Javascript, Typescript, Yaml
Frameworks:
Github-Actions
|
||||||
| fix(security): Unauthenticated Access to Full OpenAPI Documentation (GHSA-v6jh-fx3m-7xhw) | subrata71 | S | AI | 23.4h | 0.1h | May 13, 2026 |
SummaryBug FixFix security: block unauthenticated OpenAPI docs Prevents unauthenticated users from viewing full API schema, mitigating information disclosure. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Java
Frameworks:
Spring
|
||||||
| perf: removed extra entry from db argument | sondermanish | S | AI | 0.4h | 0.1h | May 13, 2026 |
SummaryRefactorRemove redundant DB argument entry Optimizes import handling by eliminating an unnecessary database argument, improving performance and consistency across git‑connected repositories. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Java
|
||||||
| chore(helm): upgrade bundled Redis from 7.0.15 to 7.4.9 | wyattwalter | XS | AI | 26.8h | 0.0h | May 12, 2026 |
SummaryChoreUpgrade bundled Redis to 7.4.9 Bumps the default Redis image tag to address accumulated CVEs, improving security for deployments. Health Assessment
Small
Low
Low
AI Details
Usage:
Authored by AI
Category:
Both AI
Tools:
Claude, CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Yaml
|
||||||
| fix(security): Path Traversal (GHSA-m4hv-9p7g-56vm) | subrata71 | M | AI | 46.3h | 0.1h | May 12, 2026 |
SummaryBug FixFix path traversal in git file operations Prevents authenticated users from reading arbitrary files via crafted git repositories, mitigating a high‑severity vulnerability. Health Assessment
Small
Medium
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Java
|
||||||
| fix(security): upgrade arangodb-java-driver to 7.25.0 to remediate CVE-2025-52999 | subrata71 | L | AI | 70.6h | 0.1h | May 12, 2026 |
SummaryBug FixUpgrade ArangoDB driver to remediate CVE-2025-52999 Remediates a high‑severity JSON DoS vulnerability by upgrading the ArangoDB Java driver and updating plugin code, ensuring secure data handling and stable connectivity. This change eliminates the vulnerable shaded Jackson core and improves error handling for unreachable hosts. Health Assessment
Medium
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Java
|
||||||
| chore: made discard changes async after ref creation | sondermanish | L | AI | 89.8h | 0.1h | May 12, 2026 |
SummaryChoreMake discard changes async after ref creation Improves performance by running discard operations asynchronously, reducing wait times for users after branch creation. Health Assessment
Large
Medium
Medium
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Java
|
||||||
| chore: playwright infra setup | sondermanish | XL | AI | 0.0h | - | May 12, 2026 |
SummaryChorePlaywright infra setup Establishes Playwright-based end‑to‑end testing infrastructure, enhancing test reliability and accelerating feature delivery. Health Assessment
Large
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript, Javascript
Frameworks:
Playwright
|
||||||
| ci: skip apt-get update in Chrome install | wyattwalter | S | AI | 47.6h | 0.1h | May 08, 2026 |
SummaryCI/CDci: skip apt-get update in Chrome install Optimizes CI by removing apt-get update during Chrome installation, reducing build times and avoiding mirror hangs on Azure runners. Health Assessment
Small
Low
Low
AI Details
Usage:
Authored by AI
Category:
Both AI
Tools:
Claude, CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Yaml
Frameworks:
Github-Actions
|
||||||
| chore(helm): generate values.schema.json from values.yaml | wyattwalter | XL | AI | 50.0h | 27.3h | May 08, 2026 |
SummaryCI/CDGenerate Helm values schema from values.yaml Auto‑generates a full Helm values schema to improve validation and reduce deployment errors. Adds CI checks and a release channel to streamline chart publishing. Health Assessment
X-Large
High
Medium
AI Details
Usage:
AI Reviewed
Category:
Both AI
Tools:
CodeRabbit, Claude
Confidence:
0.95
Tech Stack
Languages:
Yaml, Json
|
||||||
| 08/05/2026 - Promotion | btsgh | XL | No | 0.1h | 0.1h | May 08, 2026 |
SummaryChorePromotion PR for Appsmith Updates and fixes for Appsmith, including security patches and feature enhancements Health Assessment
Large
Medium
Low
AI Details
Confidence:
0.80
Tech Stack
Languages:
Javascript, Typescript
Frameworks:
React
|
||||||
| feat(client): docs link tooltip on Appsmith Base URL setting + trailing-slash normalization | subrata71 | M | AI | 15.3h | 0.1h | May 07, 2026 |
SummaryFeatureAdd docs tooltip and normalize base URL Provides a help‑link tooltip for the Base URL setting and removes trailing slashes to prevent broken URLs in email templates and links. Health Assessment
Medium
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript, Java
Frameworks:
React
|
||||||
| fix: replace generic "Response not valid" with actionable error messages for better observability | subrata71 | L | AI | 133.7h | 0.1h | May 06, 2026 |
SummaryBug FixReplace generic error with actionable messages Provides specific error messages and structured logging for action execution failures, improving observability and reducing noise for operators. Health Assessment
Large
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript, Java
|
||||||
| fix(security): fail closed when APPSMITH_BASE_URL unset for token-bearing emails (GHSA-j9gf-vw2f-9hrw) | subrata71 | XL | No | 155.8h | 0.2h | May 06, 2026 |
SummaryBug FixFix security issue with APPSMITH_BASE_URL Fail closed when APPSMITH_BASE_URL is unset for token-bearing emails, adding a non-dismissible banner for instance super-users Health Assessment
Large
Medium
Low
AI DetailsTech Stack
Languages:
Javascript, Typescript, Java
Frameworks:
React
|
||||||