Pull Request Explorer

Exploring 9 PRs. Want this for your team? Start Free Trial
Title Author Size AI Cycle Time Review Merged
test: Installation deduplication resolves a create onto the record holding the presented deviceToken mtrezza L No 27.2h 0.1h Sep 10, 2026

LLM analysis pending

This PR has not been analyzed yet.

test: Pages API is exempt from routeAllowList mtrezza M No 0.7h 0.4h Sep 09, 2026

LLM analysis pending

This PR has not been analyzed yet.

fix: Unauthenticated deletion of installation records via operator injection in device token deduplication (GHSA-cc6h-c8m4-hgrx) mtrezza L No 0.8h 0.1h Sep 09, 2026

LLM analysis pending

This PR has not been analyzed yet.

fix: Unauthenticated deletion of installation records via operator injection in device token deduplication (GHSA-cc6h-c8m4-hgrx) mtrezza L No 12.1h 0.1h Sep 09, 2026

LLM analysis pending

This PR has not been analyzed yet.

fix: LiveQuery discloses protected fields by resolving an incomplete subscriber identity (GHSA-9jpp-xhh6-75mf) mtrezza L No 0.7h 0.3h Sep 08, 2026

LLM analysis pending

This PR has not been analyzed yet.

fix: LiveQuery discloses protected fields by resolving an incomplete subscriber identity (GHSA-9jpp-xhh6-75mf) mtrezza L No 2.2h 0.1h Sep 08, 2026

LLM analysis pending

This PR has not been analyzed yet.

refactor: Bump yaml from 2.8.3 to 2.9.0 mtrezza S AI 325.6h 325.6h Aug 26, 2026

Summary

Chore

Bump yaml dependency to 2.9.0

Updates the yaml devDependency to address security fixes, ensuring CI tooling remains reliable.

Health Assessment

Small
Low
High
  • Long cycle time indicates delayed review; minimal code changes reduce risk.

AI Details

Usage: AI Assisted
Category: Review AI
Tools: CodeRabbit
Confidence: 0.95

Tech Stack

Languages: Javascript
fix: Account takeover via empty password in LDAP auth adapter (GHSA-863r-39r9-vfcf) mtrezza M No 6.7h 3.2h Aug 25, 2026

Summary

Bug Fix

Fix LDAP empty password account takeover

Adds tests and fixes LDAP auth to prevent account takeover via empty passwords, enhancing security.

Health Assessment

Medium
Low
Low
  • Quick fix with minimal changes and rapid review, indicating low complexity and high confidence in the patch.

AI Details

Tech Stack

Languages: Javascript
fix: Account takeover via empty password in LDAP auth adapter (GHSA-863r-39r9-vfcf) mtrezza M No 8.5h 0.3h Aug 25, 2026

Summary

Bug Fix

Fix LDAP auth empty password vulnerability

Removes account takeover risk by ensuring passwords are validated in LDAP authentication, enhancing security for Parse Server users.

Health Assessment

Medium
Low
Low
  • Fast cycle time with a single review and minimal rework, indicating a straightforward security fix with low complexity and risk.

AI Details

Usage: AI Reviewed
Category: Review AI
Tools: CodeRabbit
Confidence: 0.95

Tech Stack

Languages: Javascript

Get this analytics stack for your team

Connect GitHub and see cycle time, review bottlenecks, PR flow, and trend changes in minutes.

Connect Repos