Pull Request Explorer
| Title | Author | Size | AI | Cycle Time | Review | Merged |
|---|---|---|---|---|---|---|
| fix: remove visitor token from visitors.info endpoint | dionisio-bot | S | No | 1.1h | 0.0h | May 16, 2026 |
SummaryBug FixRemove visitor token from visitors.info endpoint Eliminates sensitive visitor token exposure, enhancing privacy and security for live chat users. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
Cubic AI
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| fix: remove visitor token from visitors.info endpoint | dionisio-bot | S | No | 0.8h | 0.0h | May 16, 2026 |
SummaryBug FixRemove visitor token from visitors.info endpoint Fixes security issue by removing visitor token from the visitors.info API, ensuring sensitive data is no longer exposed. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
Cubic AI
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| fix: remove visitor token from visitors.info endpoint | dionisio-bot | S | No | 0.9h | 0.0h | May 16, 2026 |
SummaryBug FixRemove visitor token from visitors.info endpoint Fixes security issue by removing visitor token from the visitors.info endpoint, ensuring sensitive data is not exposed. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
Cubic AI
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| fix: remove visitor token from visitors.info endpoint | dionisio-bot | S | No | 0.9h | 0.0h | May 16, 2026 |
SummaryBug FixRemove visitor token from visitors.info endpoint Fixes a security issue by removing the visitor token from the visitors.info endpoint, preventing sensitive data exposure. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
Cubic AI
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| fix: remove visitor token from visitors.info endpoint | dionisio-bot | S | No | 0.9h | 0.0h | May 16, 2026 |
SummaryBug FixRemove visitor token from visitors.info endpoint Fixes security issue by removing visitor token from the visitors.info endpoint, ensuring sensitive data is no longer exposed. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
Cubic AI
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| fix: clean up login tokens in users.deactivateidle | dionisio-bot | M | No | 9.1h | 0.1h | May 16, 2026 |
SummaryBug FixClean up login tokens on user deactivation Ensures stale login tokens are removed when users are deactivated, improving security and preventing unauthorized access. Health Assessment
Medium
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
Cubic AI
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| chore(deps): bump `@opentelemetry`-related packages | dionisio-bot | XL | No | 6.5h | 0.0h | May 16, 2026 |
SummaryChorechore(deps): bump @opentelemetry packages Updates OpenTelemetry dependencies to latest versions, ensuring compatibility and security fixes. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
Cubic AI
Confidence:
0.95
Tech Stack
Languages:
Javascript
|
||||||
| refactor(client): inject stream/list functions into userStatuses | ggazzo | S | AI | 6.6h | 0.1h | May 16, 2026 |
SummaryRefactorRefactor user status dependency injection Decouples user status logic from the SDK, enabling Storybook and unit tests without SDK mocks and improving testability. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit, Cubic AI
Confidence:
0.95
Tech Stack
Languages:
Typescript
Frameworks:
React
|
||||||
| chore(deps): bump protobufjs | dionisio-bot | S | No | 0.9h | 0.0h | May 15, 2026 |
SummaryChoreBump protobufjs dependency Updates protobufjs to a newer version, ensuring compatibility and security. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
Cubic AI
Confidence:
0.95
Tech Stack
Languages:
Javascript
|
||||||
| chore(deps): bump sanitize-html | dionisio-bot | S | No | 0.9h | 0.0h | May 15, 2026 |
SummaryChoreBump sanitize-html dependency Updates the sanitize-html package to a newer version, improving security and compatibility. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
Cubic AI
Confidence:
0.95
Tech Stack |
||||||
| chore(deps): bump @babel-related packages | dionisio-bot | L | No | 0.8h | 0.0h | May 15, 2026 |
SummaryChoreBump @babel-related packages Updates Babel dependencies to latest versions, ensuring compatibility and security. Health Assessment
Medium
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
Cubic AI
Confidence:
0.95
Tech Stack |
||||||
| chore(deps): bump path-to-regexp, esbuild, and tar-fs | dionisio-bot | L | No | 0.8h | 0.0h | May 15, 2026 |
SummaryChoreBump dependencies path-to-regexp, esbuild, tar-fs Updates critical Node dependencies to newer versions, ensuring compatibility and security fixes. Health Assessment
Medium
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
Cubic AI
Confidence:
0.95
Tech Stack
Languages:
Javascript
|
||||||
| fix: clean up login tokens in users.deactivateidle | dionisio-bot | M | No | 2.1h | 0.1h | May 15, 2026 |
SummaryBug FixClean up login tokens on user deactivation Ensures idle users have their login tokens properly cleared, improving security and preventing stale sessions. Health Assessment
Medium
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
Cubic AI
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| fix: clean up login tokens in users.deactivateidle | dionisio-bot | M | No | 1.5h | 0.1h | May 15, 2026 |
SummaryBug FixClean up login tokens on user deactivation Ensures idle users have their login tokens properly cleared, improving security and resource cleanup. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
Cubic AI
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| fix: clean up login tokens in users.deactivateidle | dionisio-bot | M | No | 2.1h | 0.1h | May 15, 2026 |
SummaryBug FixClean up login tokens on user deactivation Fixes stale login tokens when users are deactivated, improving security and preventing unauthorized access. Health Assessment
Medium
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
Cubic AI
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| fix: clean up login tokens in users.deactivateidle | dionisio-bot | M | No | 2.0h | 0.1h | May 15, 2026 |
SummaryBug FixFix login token cleanup in users.deactivateidle Backport of fix to clean up login tokens when deactivating idle users, improving security and reducing potential issues. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
Cubic AI
Confidence:
0.90
Tech Stack
Languages:
Typescript
Frameworks:
Meteor
|
||||||
| fix: clean up login tokens in users.deactivateidle | dionisio-bot | M | No | 1.3h | 0.0h | May 15, 2026 |
SummaryBug FixClean up login tokens on user deactivation Ensures that login tokens are properly invalidated when a user is deactivated, enhancing security and preventing potential unauthorized access. Health Assessment
Medium
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
Cubic AI
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| refactor(client): centralize DDP wire codec behind sdk/ddpProtocol | ggazzo | M | AI | 93.2h | 62.0h | May 15, 2026 |
SummaryChoreCentralize DDP wire codec in SDK Consolidates DDP parsing/serialization into a single module, reducing Meteor dependencies and simplifying future EJSON swaps. Health Assessment
Medium
Low
Medium
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit, Cubic AI
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| fix: clean up login tokens in users.deactivateidle | dionisio-bot | M | No | 1.6h | 0.1h | May 15, 2026 |
SummaryBug FixClean up login tokens on user deactivation Ensures idle users have their login tokens properly cleared, improving security and resource cleanup. Health Assessment
Medium
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
Cubic AI
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| refactor(client): use SDK storage helper in AuthenticationProvider.getLoginToken | ggazzo | M | AI | 90.9h | 46.2h | May 15, 2026 |
SummaryChoreRefactor AuthenticationProvider to use SDK storage helper Improves authentication handling by replacing direct localStorage access with SDK helper, ensuring consistent token storage and cleaner logout behavior. Health Assessment
Medium
Low
Medium
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript
Frameworks:
React
|
||||||
| fix: add permission check to the `autotransate.translateMessage` endpoint | dionisio-bot | M | No | 17.7h | - | May 15, 2026 |
SummaryBug FixAdd permission check to autotranslate endpoint Ensures only authorized users can invoke the autotranslate API, improving security and compliance. Health Assessment
Medium
Low
Low
AI Details
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| fix: ensures the translateMessage Meteor method validates access and type | dionisio-bot | M | No | 18.0h | 14.1h | May 15, 2026 |
SummaryBug FixFix translateMessage method validation Ensures the translateMessage Meteor method validates access and type, preventing unauthorized usage and type errors. Health Assessment
Medium
Low
Low
AI Details
Usage:
AI Assisted
Category:
Review AI
Tools:
Cubic AI
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| chore(deps): bump rharkor/caching-for-turbo from 2.4.0 to 2.4.1 | dependabot | S | No | 29.7h | - | May 15, 2026 |
SummaryCI/CDBump caching-for-turbo dependency to 2.4.1 Updates a CI workflow dependency to the latest patch, improving security and compatibility. Health Assessment
Small
Low
Low
AI DetailsTech Stack
Languages:
Yaml
Frameworks:
Github-Actions
|
||||||
| fix: add permission check to the `autotransate.translateMessage` endpoint | dionisio-bot | M | No | 14.6h | - | May 15, 2026 |
SummaryBug FixAdd permission check to autotranslate endpoint Ensures only authorized users can invoke the autotranslate API, improving security and compliance. Health Assessment
Small
Low
Low
AI DetailsTech Stack
Languages:
Typescript
|
||||||
| fix: ensures the translateMessage Meteor method validates access and type | dionisio-bot | M | No | 14.2h | - | May 15, 2026 |
SummaryBug FixFix translateMessage method validation Ensures the translateMessage Meteor method validates access and type, improving security and reliability of auto-translation. Health Assessment
Medium
Low
Low
AI Details
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| fix: add permission check to the `autotransate.translateMessage` endpoint | dionisio-bot | M | No | 13.4h | - | May 15, 2026 |
SummaryBug FixAdd permission check to autotranslate endpoint Ensures only authorized users can invoke the autotranslate API, improving security and compliance. Health Assessment
Small
Low
Low
AI Details
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| fix: add permission check to the `autotransate.translateMessage` endpoint | dionisio-bot | M | No | 9.2h | - | May 15, 2026 |
SummaryBug FixAdd permission check to autotranslate endpoint Ensures only authorized users can invoke the autotranslate API, improving security and compliance. Health Assessment
Small
Low
Low
AI Details
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| fix: add permission check to the `autotransate.translateMessage` endpoint | dionisio-bot | M | No | 9.3h | - | May 15, 2026 |
SummaryBug FixAdd permission check to autotranslate endpoint Ensures only authorized users can invoke the autotranslate API, improving security and compliance. Health Assessment
Small
Low
Low
AI Details
Confidence:
0.75
Tech Stack
Languages:
Typescript
|
||||||
| fix: add permission check to the `autotransate.translateMessage` endpoint | dionisio-bot | M | No | 8.5h | - | May 15, 2026 |
SummaryBug FixAdd permission check to autotranslate endpoint Ensures only authorized users can invoke the autotranslate API, improving security. Health Assessment
Medium
Low
Low
AI DetailsTech Stack
Languages:
Typescript
|
||||||
| fix: ensures the translateMessage Meteor method validates access and type | dionisio-bot | M | No | 8.7h | - | May 15, 2026 |
SummaryBug FixFix translateMessage method validation Ensures translation method validates access and type, preventing unauthorized usage and type errors. Health Assessment
Medium
Low
Low
AI Details
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| chore(deps): bump sanitize-html | julio-rocketchat | S | AI | 7.9h | 2.1h | May 15, 2026 |
SummaryChoreBump sanitize-html dependency Updates the sanitize-html package to a newer version, improving security and compatibility across the Rocket.Chat codebase. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack |
||||||
| fix: incorrect timestamp timezone conversion and relative time preview | abhinavkrin | M | AI | 200.2h | 2.2h | May 15, 2026 |
SummaryBug FixFix timestamp timezone conversion and preview Corrects timezone conversion errors and ensures relative time preview updates accurately, improving user experience for timestamp features. Health Assessment
Medium
Medium
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript
Frameworks:
React
|
||||||
| fix: add permission check to the `autotransate.translateMessage` endpoint | dionisio-bot | M | No | 2.4h | - | May 14, 2026 |
SummaryBug FixAdd permission check to autotranslate endpoint Ensures only authorized users can trigger auto-translation, improving security and compliance. Health Assessment
Medium
Low
Low
AI Details
Confidence:
0.80
Tech Stack
Languages:
Typescript
|
||||||
| fix: ensures the translateMessage Meteor method validates access and type | dionisio-bot | M | No | 1.7h | - | May 14, 2026 |
SummaryBug FixFix translateMessage method validation Ensures translateMessage method validates access and type, preventing potential security or data integrity issues. Health Assessment
Medium
Low
Low
AI Details
Confidence:
0.75
Tech Stack
Languages:
Typescript
|
||||||
| fix: `abacAttributes` reactivity | KevLehman | M | AI | 50.6h | 1.7h | May 14, 2026 |
SummaryBug FixFix ABAC attributes reactivity Improves client-side reactivity for ABAC service, ensuring room actions propagate correctly. This resolves a bug where certain room actions were not reaching clients. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript, Javascript
|
||||||
| fix: ensures the translateMessage Meteor method validates access and type | dionisio-bot | M | No | 1.9h | - | May 14, 2026 |
SummaryBug FixFix translateMessage method validation Ensures the translateMessage method validates user access and message type, preventing unauthorized translations and reducing runtime errors. Health Assessment
Small
Low
Low
AI Details
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| fix: ensures the translateMessage Meteor method validates access and type | dionisio-bot | M | No | 2.0h | - | May 14, 2026 |
SummaryBug FixFix translateMessage method validation Ensures the translateMessage Meteor method validates access and type, preventing unauthorized usage and type errors, improving security and reliability. Health Assessment
Medium
Low
Low
AI Details
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| fix: ensures the translateMessage Meteor method validates access and type | dionisio-bot | M | No | 3.2h | - | May 14, 2026 |
SummaryBug FixFix translateMessage method validation Ensures the translateMessage Meteor method validates access and type, preventing unauthorized usage and type errors. Health Assessment
Small
Low
Low
AI Details
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| fix: hide 'Delete all closed chats' button when user lacks `remove-closed-livechat-rooms` permission | MartinSchoeler | M | AI | 55.4h | 28.6h | May 14, 2026 |
SummaryBug FixHide Delete All Closed Chats button for unauthorized users Ensures the 'Delete all closed chats' option is only visible to users with the appropriate permission, improving UI consistency and preventing unauthorized actions. Health Assessment
Medium
Low
Medium
AI Details
Usage:
AI Assisted
Category:
Both AI
Tools:
Cursor, CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript
Frameworks:
React
|
||||||
| refactor(client): drop the Settings.watch method | ggazzo | S | AI | 53.3h | 53.1h | May 14, 2026 |
SummaryChoreRefactor client: drop Settings.watch method Updates settings access to use non-reactive reads, removing the deprecated reactive getter and improving stability for end users. Health Assessment
Small
Low
Medium
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript
Frameworks:
React
|
||||||
| refactor(client): switch settings.watch to settings.peek where reactivity is dead | ggazzo | S | AI | 53.6h | 53.4h | May 14, 2026 |
SummaryRefactorRefactor client settings access for performance Replaces reactive settings.watch calls with non‑reactive settings.peek in client code, eliminating unnecessary Tracker subscriptions and ensuring UI updates correctly without changing user behavior. Health Assessment
Medium
Low
Medium
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript
Frameworks:
React
|
||||||
| refactor(client): centralize __meteor_runtime_config__ access | ggazzo | M | AI | 66.8h | 0.1h | May 14, 2026 |
SummaryChoreCentralize Meteor runtime config access Simplifies client URL handling, reduces duplication, and improves maintainability across the application. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript
Frameworks:
React
|
||||||
| fix: ensures the translateMessage Meteor method validates access and type | julio-rocketchat | M | AI | 2.8h | 0.1h | May 14, 2026 |
SummaryBug FixFix translateMessage method validation Ensures server‑side validation for message translation, preventing unauthorized translations and providing clearer errors. Health Assessment
Medium
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| refactor(client): factor out hasPermission / hasRole into pure factory | ggazzo | L | AI | 49.5h | 0.1h | May 14, 2026 |
SummaryRefactorRefactor authorization helpers into pure factory Centralizes permission logic, improves testability, and ensures consistent authorization across client and non-React callers without changing behavior. Health Assessment
Medium
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript
Frameworks:
React
|
||||||
| fix: users.presence ignoring comma-separated IDs after OpenAPI migration | dionisio-bot | M | No | 1.2h | 0.4h | May 14, 2026 |
SummaryBug FixFix presence ignoring comma-separated IDs Ensures the presence feature correctly handles multiple user IDs, maintaining accurate real-time status for users. Health Assessment
Small
Low
Low
AI Details
Confidence:
0.80
Tech Stack
Languages:
Typescript
|
||||||
| perf(client): narrow AuthorizationProvider's User snapshot to .roles | ggazzo | S | AI | 0.3h | 0.1h | May 14, 2026 |
SummaryRefactorOptimize AuthorizationProvider reactivity Reduces unnecessary UI re-renders by narrowing user snapshot to roles, improving client performance. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript
Frameworks:
React
|
||||||
| perf(client): stop subscribing AuthorizationProvider to Subscriptions globally | ggazzo | S | AI | 0.4h | 0.1h | May 14, 2026 |
SummaryRefactorStop global subscription in AuthorizationProvider Reduces unnecessary re-renders by limiting subscription to relevant data, improving performance for permission-gated components. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript
Frameworks:
React
|
||||||
| refactor(core-typings): remove `_updatedAt` from `IInstanceStatus` | tassoevan | S | AI | 21.8h | 21.8h | May 14, 2026 |
SummaryRefactorRemove _updatedAt from Instance Status Simplifies instance status type definitions and removes the updated timestamp from the Instances modal, improving clarity and reducing unnecessary data. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript
Frameworks:
React
|
||||||
| fix: users.presence ignoring comma-separated IDs after OpenAPI migration | ricardogarim | M | AI | 17.5h | 1.2h | May 14, 2026 |
SummaryBug FixFix users.presence ignoring comma-separated IDs after OpenAPI migration Corrects the users.presence endpoint to properly handle multiple comma-separated user IDs, restoring accurate presence status for mobile users. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack
Languages:
Typescript
|
||||||
| chore(deps): bump protobufjs | yasnagat | S | AI | 5.2h | 5.2h | May 14, 2026 |
SummaryChoreBump protobufjs dependency to address CVEs Updates protobufjs to the latest patch to fix security vulnerabilities, ensuring safer message handling. Health Assessment
Small
Low
Low
AI Details
Usage:
AI Reviewed
Category:
Review AI
Tools:
CodeRabbit
Confidence:
0.95
Tech Stack |
||||||