2026-03-25 - 2026-04-25
Overview
1 Release published by 1 user
Published
v0.2.0
v0.2.0 — AI-Native Security & Compliance Platform
8 Pull requests merged by 1 user
Merged
#55 fix: CVE notifications during scan + help chat doc loading + Dockerfile
Merged
#53 feat: hourly CVE alerting with notification bell and API
Merged
#52 feat: add E2E test suite with nightly CI, fix dashboard Dockerfile
Merged
#51 feat: add floating help chat widget, remove settings page
Merged
#50 fix: cascade-delete DAST targets, pentests, and downstream data on repo delete
Merged
#49 feat: refine all LLM system prompts for precision and reduced false positives
Merged
#48 feat: deduplicate code review findings across LLM passes
Merged
#47 fix: check Gitea API response status and fallback for PR reviews
23 Issues created by 1 user
Opened
#54 [medium] semgrep: Service 'mailserver' is running with a writable root filesystem. This may allow malicious applications to download and run additional payloads, or modify container files. If an application inside a container has to save something temp…
Opened
#56 Webhook auth bypass when webhook_secret is None
Opened
#58 JWKS cache never expires — key rotation requires restart
Opened
#57 JWT audience validation disabled — cross-app token reuse
Opened
#59 No request body size limit on API and webhook servers
Opened
#60 Health endpoint does not verify database connectivity
Opened
#63 Graph endpoints load full node/edge collections without pagination
Opened
#61 Scheduled scans run sequentially — one slow repo blocks all others
Opened
#62 CVE monitor loads entire SBOM collection into memory
Opened
#65 No graceful shutdown — in-progress scans left in running state
Opened
#64 sort_by query parameter is a NoSQL injection vector
Opened
#66 get_attack_chain has no pagination — long sessions return unbounded data
Opened
#67 license_summary and SBOM export fetch entire dataset without limits
Opened
#68 Webhook server port is hardcoded to 3002
Opened
#69 Email notification channel for CVE alerts
Opened
#70 Webhook delivery tracking and retry
Opened
#71 Audit logging for security-sensitive operations
Opened
#74 CI/CD pipeline gates — block deploys on critical findings
Opened
#72 SOC2 and ISO 27001 compliance control mappings
Opened
#73 Policy-as-Code: custom compliance rules via YAML
Opened
#75 Executive compliance posture reports
Opened
#76 File splitting refactor — no file over 250 lines
Opened
#77 Migrate secrets management to Infisical, remove Coolify env vars
1 Unresolved Conversation
Open
#23
feat: add user login and data processing endpoint