Skip to content
Navigation Menu
Sign in
Appearance settings
Platform
AI CODE CREATION
GitHub Copilot
Write better code with AI
GitHub Copilot app
Direct agents from issue to merge
MCP Registry
Integrate external tools
DEVELOPER WORKFLOWS
Actions
Automate any workflow
Codespaces
Instant dev environments
Issues
Plan and track work
Code Review
Manage code changes
Code Quality
Enforce quality at merge
APPLICATION SECURITY
GitHub Advanced Security
Find and fix vulnerabilities
Code security
Secure your code as you build
Secret protection
Stop leaks before they start
EXPLORE
Why GitHub
Documentation
Blog
Changelog
Marketplace
View all features
Solutions
BY COMPANY SIZE
Enterprises
Small and medium teams
Startups
Nonprofits
BY USE CASE
App Modernization
DevSecOps
DevOps
CI/CD
View all use cases
BY INDUSTRY
Healthcare
Financial services
Manufacturing
Government
View all industries
View all solutions
Resources
EXPLORE BY TOPIC
AI
Software Development
DevOps
Security
View all topics
EXPLORE BY TYPE
Customer stories
Events & webinars
Ebooks & reports
Business insights
GitHub Skills
SUPPORT & SERVICES
Documentation
Customer support
Community forum
Trust center
Partners
View all resources
Open Source
COMMUNITY
GitHub Sponsors
Fund open source developers
PROGRAMS
Security Lab
Maintainer Community
GitHub Stars
Archive Program
REPOSITORIES
Topics
Trending
Collections
Enterprise
ENTERPRISE SOLUTIONS
Enterprise platform
AI-powered developer platform
AVAILABLE ADD-ONS
GitHub Advanced Security
Enterprise-grade security features
Copilot for Business
Enterprise-grade AI features
Premium Support
Enterprise-grade 24/7 support
Pricing
Search
/
Sign in
Sign up
Appearance settings
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
cativo23
nova-id
Repository navigation
Code
Issues
41
(41)
Pull requests
Actions
Projects
Security and quality
Insights
More
items
Issues
Change the issues type filter
Issues
New issue
Search issues
is
:
issue
state
:
open
is:issue state:open
Clear filter
Search
Issues
Open
41
(41)
Closed
Author
Labels
Projects
Milestones
Assignees
Newest
Comfortable display density
Compact display density
[low] start-*.sh unsafe 'export $(cat .env | xargs)' env load
area: config
priority: low
type: bug
cativo23/nova-id#117
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 8 — Cleanup, dead code & scripts hygiene
[low] useAuditLog composable never invoked
area: frontend
priority: low
type: bug
cativo23/nova-id#116
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 8 — Cleanup, dead code & scripts hygiene
[low] Dead isAuthenticated state; nav visibility is path-only
area: frontend
priority: low
type: bug
cativo23/nova-id#115
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 8 — Cleanup, dead code & scripts hygiene
[low] Dead roleOptions + hardcoded hidden traits.role input (escalation landmine)
area: frontend
priority: low
security
type: security
cativo23/nova-id#114
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 8 — Cleanup, dead code & scripts hygiene
[low] Challenge-token DTOs inconsistently length-bounded
area: api
area: oauth
priority: low
type: bug
cativo23/nova-id#113
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 8 — Cleanup, dead code & scripts hygiene
[low] AuthModule exported guard is dead; AppModule builds a second instance
area: api
priority: low
type: bug
cativo23/nova-id#112
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 8 — Cleanup, dead code & scripts hygiene
[medium] make setup-permissions points to nonexistent script
area: config
priority: medium
type: bug
cativo23/nova-id#111
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 8 — Cleanup, dead code & scripts hygiene
[medium] generate-env.sh omits DEMO_DB_PASSWORD -> empty password
area: config
priority: medium
type: bug
cativo23/nova-id#110
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 8 — Cleanup, dead code & scripts hygiene
[high] .env.production.example missing audit-role vars + stale superuser note
area: config
priority: high
type: bug
cativo23/nova-id#109
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 8 — Cleanup, dead code & scripts hygiene
[low] Role DTOs accept any string as userId (no UUID validation)
area: api
priority: low
type: bug
cativo23/nova-id#108
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 7 — demo-api service
[low] LoggingInterceptor crashes on undefined/non-serializable body
area: api
priority: low
type: bug
cativo23/nova-id#107
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 7 — demo-api service
[medium] User emails stored cleartext in logs, readable by app_admin
area: api
priority: medium
security
type: security
cativo23/nova-id#106
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 7 — demo-api service
[medium] demo-api audit write failures swallowed -> reports success on failed audit
area: api
priority: medium
security
type: security
cativo23/nova-id#105
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 7 — demo-api service
[medium] Log rotation overwrites previous rotated file -> history lost
area: api
priority: medium
type: bug
cativo23/nova-id#104
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 7 — demo-api service
[high] Two LogsService singletons -> role grant/revoke never appears in /logs
area: api
priority: high
type: bug
cativo23/nova-id#103
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 7 — demo-api service
[gray] Overly broad invalid_grant swallowing hides genuine callback failures
area: frontend
area: oauth
priority: low
question
type: bug
cativo23/nova-id#102
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 6 — Frontend flows & OIDC hardening
[gray] 'View permissions' row action always shows the admin's own permissions
area: frontend
priority: medium
question
type: bug
cativo23/nova-id#101
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 6 — Frontend flows & OIDC hardening
[low] Verification 'Continue' href bypasses safeRedirect()
area: frontend
priority: low
security
type: security
cativo23/nova-id#100
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 6 — Frontend flows & OIDC hardening
[medium] Nonce replay check skipped when id_token omits nonce
area: frontend
area: oauth
priority: medium
security
type: security
cativo23/nova-id#99
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 6 — Frontend flows & OIDC hardening
[medium] ID token signature never cryptographically verified
area: frontend
area: oauth
priority: medium
security
type: security
cativo23/nova-id#98
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 6 — Frontend flows & OIDC hardening
[high] Admin permission cache fetched once, never invalidated -> revoked admin keeps access
area: frontend
area: keto
priority: high
security
type: security
cativo23/nova-id#97
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 6 — Frontend flows & OIDC hardening
[high] Post-success redirect to nonexistent /dashboard route -> blank page
area: frontend
priority: high
type: bug
cativo23/nova-id#96
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 6 — Frontend flows & OIDC hardening
[high] /logs unreachable — Bearer token never attached, gateway always 401s
area: frontend
area: oauth
priority: high
type: bug
cativo23/nova-id#95
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 6 — Frontend flows & OIDC hardening
[low] updateIdentity/setIdentityState read-then-replace -> lost updates
area: api
priority: low
type: bug
cativo23/nova-id#94
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 5 — Audit trail integrity
[medium] Winston file logger: no rotation, no PHI/secret redaction
area: api
priority: medium
security
type: security
cativo23/nova-id#93
·
Filter by author
cativo23
opened
on Jul 7, 2026
·
Wave 5 — Audit trail integrity
Previous
1
2
Next
You can’t perform that action at this time.