-
Notifications
You must be signed in to change notification settings - Fork 715
Pull requests: SecureBananaLabs/bug-bounty
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
fix: strip password from user listing response
#8320
opened Jun 23, 2026 by
RanuK12
Loading…
4 tasks done
fix: add input validation and length limit to search endpoint
#8315
opened Jun 23, 2026 by
1982liuyi
Loading…
fix: SBL security #8207 - reject inverted job budget ranges in validation
#8263
opened Jun 23, 2026 by
gtx20060124-bot
Loading…
fix: validate refresh token instead of ignoring it (Closes #1775)
#8262
opened Jun 23, 2026 by
gtx20060124-bot
Loading…
fix: SBL security #8237 - restrict CORS to allowed origins via CORS_ORIGIN env var
#8261
opened Jun 23, 2026 by
gtx20060124-bot
Loading…
fix: enforce authentication on payment endpoint (Closes #2757)
#8260
opened Jun 23, 2026 by
gtx20060124-bot
Loading…
fix: enforce authentication on job creation endpoint (Closes #1776)
#8259
opened Jun 23, 2026 by
gtx20060124-bot
Loading…
2
fix: security hardening - CORS, input validation, ID injection prevention
#8258
opened Jun 22, 2026 by
gtx20060124-bot
Loading…
Gaotax2006 [ DevEx ] discover test files with glob pattern (#8195)
#8257
opened Jun 22, 2026 by
gtx20060124-bot
Loading…
Gaotax2006 [ DevEx ] expose runtime JS entrypoint for @freelanceflow/ui (#8199)
#8256
opened Jun 22, 2026 by
gtx20060124-bot
Loading…
Gaotax2006 [ DevEx ] log actual ephemeral port on startup (#8197)
#8255
opened Jun 22, 2026 by
gtx20060124-bot
Loading…
Gaotax2006 [ Security ] reject inverted budget ranges in create and partial-update (#8207)
#8254
opened Jun 22, 2026 by
gtx20060124-bot
Loading…
Gaotax2006 [ Security ] validate notification schema and preserve server-owned defaults (#8209)
#8253
opened Jun 22, 2026 by
gtx20060124-bot
Loading…
Gaotax2006 [ Security ] return 400 for malformed JSON, 413 for oversized (#8191)
#8251
opened Jun 22, 2026 by
gtx20060124-bot
Loading…
Gaotax2006 [ Security ] add 10MB upload file size limit (#8193)
#8250
opened Jun 22, 2026 by
gtx20060124-bot
Loading…
Previous Next
ProTip!
no:milestone will show everything without a milestone.