Pull Request Explorer
Back to Repo| Title | Author | Size | AI | Cycle Time | Review | Merged |
|---|---|---|---|---|---|---|
| test: Installation deduplication resolves a create onto the record holding the presented deviceToken | mtrezza | L | No | 27.2h | 0.1h | Sep 10, 2026 |
|
LLM analysis pending This PR has not been analyzed yet. |
||||||
| test: Pages API is exempt from routeAllowList | mtrezza | M | No | 0.7h | 0.4h | Sep 09, 2026 |
|
LLM analysis pending This PR has not been analyzed yet. |
||||||
| fix: Unauthenticated deletion of installation records via operator injection in device token deduplication (GHSA-cc6h-c8m4-hgrx) | mtrezza | L | No | 0.8h | 0.1h | Sep 09, 2026 |
|
LLM analysis pending This PR has not been analyzed yet. |
||||||
| fix: Unauthenticated deletion of installation records via operator injection in device token deduplication (GHSA-cc6h-c8m4-hgrx) | mtrezza | L | No | 12.1h | 0.1h | Sep 09, 2026 |
|
LLM analysis pending This PR has not been analyzed yet. |
||||||
| fix: LiveQuery discloses protected fields by resolving an incomplete subscriber identity (GHSA-9jpp-xhh6-75mf) | mtrezza | L | No | 0.7h | 0.3h | Sep 08, 2026 |
|
LLM analysis pending This PR has not been analyzed yet. |
||||||
| fix: LiveQuery discloses protected fields by resolving an incomplete subscriber identity (GHSA-9jpp-xhh6-75mf) | mtrezza | L | No | 2.2h | 0.1h | Sep 08, 2026 |
|
LLM analysis pending This PR has not been analyzed yet. |
||||||
| refactor: Bump yaml from 2.8.3 to 2.9.0 | mtrezza | S | AI | 325.6h | 325.6h | Aug 26, 2026 |
SummaryChoreBump yaml dependency to 2.9.0 Updates the yaml devDependency to address security fixes, ensuring CI tooling remains reliable. Health Assessment
Small
Low
High
AI Details
Usage:
AI Assisted
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Javascript
|
||||||
| fix: Account takeover via empty password in LDAP auth adapter (GHSA-863r-39r9-vfcf) | mtrezza | M | No | 6.7h | 3.2h | Aug 25, 2026 |
SummaryBug FixFix LDAP empty password account takeover Adds tests and fixes LDAP auth to prevent account takeover via empty passwords, enhancing security. Health Assessment
Medium
Low
Low
AI DetailsTech Stack
Languages:
Javascript
|
||||||
| fix: Account takeover via empty password in LDAP auth adapter (GHSA-863r-39r9-vfcf) | mtrezza | M | No | 8.5h | 0.3h | Aug 25, 2026 |
SummaryBug FixFix LDAP auth empty password vulnerability Removes account takeover risk by ensuring passwords are validated in LDAP authentication, enhancing security for Parse Server users. Health Assessment
Medium
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Javascript
|
||||||