-
-
Notifications
You must be signed in to change notification settings - Fork 84
Pull requests: OWASP/cornucopia
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Fix DoS vulnerability in play_card API by adding rate limiting
#2629
opened Mar 14, 2026 by
xovishnukosuri
Loading…
5 tasks
Fix Vote schema empty changeset validation
#2628
opened Mar 14, 2026 by
xovishnukosuri
Loading…
3 tasks
Fix: Reject HTML/JS in player and game name changesets
#2627
opened Mar 14, 2026 by
xovishnukosuri
Loading…
2 of 5 tasks
Fix: prevent joining games already in progress
#2626
opened Mar 14, 2026 by
xovishnukosuri
Loading…
4 tasks
Fix: authorization check in toggle_vote to prevent cross-game voting
#2625
opened Mar 14, 2026 by
xovishnukosuri
Loading…
2 tasks done
enforce pnpm usage and prevent npm installs
#2624
opened Mar 13, 2026 by
Gurkiratcodemaster
Loading…
Fix AttributeError vulnerabilities in convert.py
#2622
opened Mar 13, 2026 by
khushal-winner
Loading…
Bump @types/node from 25.4.0 to 25.5.0 in /cornucopia.owasp.org
dependencies
Pull requests that update a dependency file
javascript
Pull requests that update Javascript code
#2619
opened Mar 13, 2026 by
dependabot
bot
Loading…
Bump @sveltejs/kit from 2.54.0 to 2.55.0 in /cornucopia.owasp.org
dependencies
Pull requests that update a dependency file
javascript
Pull requests that update Javascript code
#2618
opened Mar 13, 2026 by
dependabot
bot
Loading…
Bump black from 25.1.0 to 26.3.1
dependencies
Pull requests that update a dependency file
python
Pull requests that update Python code
#2617
opened Mar 13, 2026 by
dependabot
bot
Loading…
Fix: remove hardcoded version in card route loader and use DeckServic…
#2616
opened Mar 12, 2026 by
kavya-seth-vns
Loading…
build(deps): bump the npm_and_yarn group across 1 directory with 2 updates
dependencies
Pull requests that update a dependency file
javascript
Pull requests that update Javascript code
#2611
opened Mar 12, 2026 by
dependabot
bot
Loading…
fix: guard against AttributeError on None values in convert.py
#2599
opened Mar 11, 2026 by
pranitaurlam
Loading…
3 tasks
Fix voting security: block voting before game starts and after game ends
#2591
opened Mar 10, 2026 by
khushal-winner
Loading…
feat: Implement atomic operations and rate limiting
#2566
opened Mar 8, 2026 by
khushal-winner
Loading…
Critical security fix: Prevent self-voting authorization bypass
#2564
opened Mar 8, 2026 by
khushal-winner
Loading…
fix: use rounds_played directly in handle_info for finished games
#2558
opened Mar 7, 2026 by
immortal71
Loading…
fix(scripts): return None from get_docx_document on missing template
#2546
opened Mar 7, 2026 by
immortal71
Loading…
feat: redirect players to game page when game ends
#2544
opened Mar 6, 2026 by
khushal-winner
Loading…
Fix: Make placeholder cards non-draggable and prevent table-to-hand c…
#2532
opened Mar 5, 2026 by
khushal-winner
Loading…
fix: prevent joining and spectating games already in progress
#2531
opened Mar 5, 2026 by
Mysterio-17
Loading…
Previous Next
ProTip!
Adding no:label will show everything without a label.