-
Notifications
You must be signed in to change notification settings - Fork 421
Pull requests: SecureBananaLabs/bug-bounty
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
fix: resolve freelancer profiles from mock data by username
#3368
opened Jun 1, 2026 by
AlvaroWhiteRD
Loading…
fix: reject inverted budget ranges in createJobSchema
#3367
opened Jun 1, 2026 by
AlvaroWhiteRD
Loading…
fix: count malformed json requests in rate limiter
🙋 Bounty claim
#3366
opened Jun 1, 2026 by
vicentsmith470-web
Loading…
fix: make @freelanceflow/ui package entrypoint directly importable
#3364
opened Jun 1, 2026 by
biocai
Loading…
Return 400 responses for API validation errors
🙋 Bounty claim
#3362
opened Jun 1, 2026 by
18166714330cl-maker
Loading…
fix: registerUser token subject mismatch bug (closes #3354)
#3355
opened Jun 1, 2026 by
patchninja-my
Loading…
fix(lhf-004): add input validation to payment endpoint
#3353
opened Jun 1, 2026 by
patchninja-my
Loading…
fix(lhf-001): remove hardcoded JWT secret fallback
#3351
opened Jun 1, 2026 by
patchninja-my
Loading…
feat: automated low-hanging-fruit bug scanner (fixes #3349)
#3350
opened Jun 1, 2026 by
patchninja-my
Loading…
Add server-owned timestamps to created reviews
🙋 Bounty claim
#3346
opened Jun 1, 2026 by
LikeACloud7
Loading…
Expose DB workspace package entrypoint
🙋 Bounty claim
#3343
opened Jun 1, 2026 by
shaiananvari8
Loading…
Use canonical role casing for login tokens
🙋 Bounty claim
#3340
opened Jun 1, 2026 by
LikeACloud7
Loading…
fix: keep new notifications unread on creation
🙋 Bounty claim
#3339
opened Jun 1, 2026 by
Barroso0
Loading…
fix(auth): sign refresh token with uppercase CLIENT UserRole casing
#3336
opened Jun 1, 2026 by
git67-aaa
Loading…
fix: require authentication for /api/payments routes (#2757)
#3333
opened Jun 1, 2026 by
gordonzhaomwrf-a11y
Loading…
fix: enforce authentication on job creation endpoint
#3332
opened Jun 1, 2026 by
cyrillical00
Loading…
Payment endpoint lacks authentication — unauthenticated payment creation
#3331
opened Jun 1, 2026 by
cyrillical00
Loading…
Job creation endpoint lacks authentication — anyone can post jobs
#3329
opened Jun 1, 2026 by
cyrillical00
Loading…
Upload endpoint lacks authentication — unauthenticated file uploads allowed
#3330
opened Jun 1, 2026 by
cyrillical00
Loading…
Previous Next
ProTip!
Adding no:label will show everything without a label.