Skip to content
Navigation Menu
Sign in
Appearance settings
Platform
AI CODE CREATION
GitHub Copilot
Write better code with AI
GitHub Copilot app
Direct agents from issue to merge
MCP Registry
Integrate external tools
DEVELOPER WORKFLOWS
Actions
Automate any workflow
Codespaces
Instant dev environments
Issues
Plan and track work
Code Review
Manage code changes
Code Quality
Enforce quality at merge
APPLICATION SECURITY
GitHub Advanced Security
Find and fix vulnerabilities
Code security
Secure your code as you build
Secret protection
Stop leaks before they start
EXPLORE
Why GitHub
Documentation
Blog
Changelog
Marketplace
View all features
Solutions
BY COMPANY SIZE
Enterprises
Small and medium teams
Startups
Nonprofits
BY USE CASE
App Modernization
DevSecOps
DevOps
CI/CD
View all use cases
BY INDUSTRY
Healthcare
Financial services
Manufacturing
Government
View all industries
View all solutions
Resources
EXPLORE BY TOPIC
AI
Software Development
DevOps
Security
View all topics
EXPLORE BY TYPE
Customer stories
Events & webinars
Ebooks & reports
Business insights
GitHub Skills
SUPPORT & SERVICES
Documentation
Customer support
Community forum
Trust center
Partners
View all resources
Open Source
COMMUNITY
GitHub Sponsors
Fund open source developers
PROGRAMS
Security Lab
Maintainer Community
GitHub Stars
Archive Program
REPOSITORIES
Topics
Trending
Collections
Enterprise
ENTERPRISE SOLUTIONS
Enterprise platform
AI-powered developer platform
AVAILABLE ADD-ONS
GitHub Advanced Security
Enterprise-grade security features
Copilot for Business
Enterprise-grade AI features
Premium Support
Enterprise-grade 24/7 support
Pricing
Search
/
Sign in
Sign up
Appearance settings
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
nithiink
yapcode
Repository navigation
Code
Issues
20
(20)
Pull requests
25
(25)
Actions
Projects
Security and quality
Insights
More
items
All pull requests
New pull request
Search pull requests
is
:
pr
state
:
open
is:pr state:open
Clear filter
Search
Pull requests
Open
25
(25)
Closed
41
(41)
Author
Label
Projects
Milestones
Reviews
Assignee
Sort by
Newest
descending
More items
Comfortable display density
Compact display density
fix(security): restrict Origin allowlist to exact frontend origins in tokenless loopback mode
#89
·
nithiink
opened
Oct 6, 2026
Owner
·
·
1
fix(security): close CSRF / DNS-rebinding / prompt-injection paths to the command backend
#87
·
nithiink
opened
Oct 4, 2026
Owner
·
·
1
fix(security): close tokenless cross-origin paths to the command-executing backend
#85
·
nithiink
opened
Oct 3, 2026
Owner
·
·
1
fix(security): defeat DNS rebinding by pinning request Host to local addresses
#83
·
nithiink
opened
Oct 2, 2026
Owner
·
·
1
fix(security): block DNS-rebinding CSRF at the proxy with an absolute Host allowlist
#81
·
nithiink
opened
Sep 30, 2026
Owner
·
·
1
fix(security): don't trust arbitrary localhost/LAN origins in tokenless mode
#79
·
nithiink
opened
Sep 29, 2026
Owner
·
·
1
fix(security): close CSRF/SSRF gaps in tokenless mode (daily review 2026-09-28)
#77
·
nithiink
opened
Sep 28, 2026
Owner
·
·
1
fix(security): block DNS rebinding on /api proxy via Host allowlist
#75
·
nithiink
opened
Sep 27, 2026
Owner
·
·
1
fix(security): strict Origin allowlist for in-app auth in tokenless mode
#73
·
nithiink
opened
Sep 26, 2026
Owner
·
·
1
fix(security): scope Origin allowlist to exact frontend in tokenless mode; redact auth token from access logs
#71
·
nithiink
opened
Sep 25, 2026
Owner
·
·
1
fix(security): pin HTTP Host header to defeat DNS rebinding
#69
·
nithiink
opened
Sep 24, 2026
Owner
·
·
1
fix(security): scope broad LAN Origin allowlist to token mode
#67
·
nithiink
opened
Sep 23, 2026
Owner
·
·
1
fix(security): add Host allowlist to /api proxy to block DNS-rebinding CSRF
#65
·
nithiink
opened
Sep 22, 2026
Owner
·
·
1
fix(security): restrict Origin auth-gate to exact frontend origins in tokenless mode
#63
·
nithiink
opened
Sep 21, 2026
Owner
·
·
1
fix(security): gate broad LAN/any-port Origin regex on token (tokenless loopback CSRF/drive-by)
#61
·
nithiink
opened
Sep 19, 2026
Owner
·
·
1
fix(security): clickjacking headers, prompt-injection authority, WebFetch egress gate
#59
·
nithiink
opened
Sep 18, 2026
Owner
·
·
1
Feat/yuri phase 7
#57
·
techbot11
opened
Sep 5, 2026
·
·
fix(security): validate Host header to defeat DNS rebinding (daily review 2026-07-31)
#56
·
nithiink
opened
Jul 31, 2026
Owner
·
·
1
Bump next from 16.2.6 to 16.2.11 in /frontend in the npm_and_yarn group across 1 directory
dependencies
javascript
#54
·
dependabot[bot]
opened
Jul 28, 2026
Bot
·
·
fix(security): fail closed on plan-approval declines; add frontend security headers
#53
·
nithiink
opened
Jul 21, 2026
Owner
·
·
README: prominent 'Watch the full demo' button under the preview
#51
·
nithiink
opened
Jul 6, 2026
Owner
·
·
security: validate tool_use_id path component; drop --reload in network mode
#50
·
nithiink
opened
Jun 22, 2026
Owner
·
·
1
fix: stop set_mode from freezing the voice agent on a busy session
#48
·
nithiink
opened
Jun 16, 2026
Owner
·
·
fix(ui): gate voice orb on a true ready signal, not start() returning (#38)
#47
·
nithiink
opened
Jun 16, 2026
Owner
·
·
1
Fix stale UI prompt after a permission/question is answered in the CLI
#44
·
nithiink
opened
Jun 15, 2026
Owner
·
·
You can’t perform that action at this time.