The first two are security fixes: one closed a shell-injection path in a log-processing utility, the other stopped a database password leaking into config output.
97 merged · 7 open · synced hourly from GitHub
| Project | Contribution | Status |
|---|---|---|
| ZcashFoundation/zebra | Stopped zebrad-log-filter executing log text as shell (PR #11050) | ● Merged |
| ZcashFoundation/zebra | Kept the Elasticsearch password out of the config dump (PR #11051) | ● Merged |
| ZcashFoundation/zebra | Fixed six book instructions that fail or misinform (PR #10956) | ● Merged |
| zcash/librustzcash | Reconciled AGENTS.md with the README dependency diagram (PR #2624) | ● Merged |
| ZecHub/zechub | zcashd deprecation note in the Raspberry Pi 4 full-node guide (PR #1882) | ● Merged |
| ZecHub/zechub-wiki | Fixed the hackathon project list falling back to stale data (PR #652) | ● Merged |
| ethereum/ethereum-org-website | Clarified wording in the proof-of-stake developer docs (PR #12972) | ● Merged |
| ZcashFoundation/zebra | Refreshed book content overtaken by releases and refactors (PR #11216) | ● Merged |
| jinolabs-xyz/planc-studio | Hero, careers, cookie consent, and Studio OG cards (PR #8) | ● Merged |
| Giri-Aayush/copynpaste | Remove em dashes from the keys and MCP page copy (PR #61) | ● Merged |
| Giri-Aayush/copynpaste | Fix the account dropdown clipping, and rebuild the MCP page into two altitudes (PR #59) | ● Merged |
| Giri-Aayush/copynpaste | Fix three real findings from the MCP stress test (PR #58) | ● Merged |
| Giri-Aayush/copynpaste | Reach the site Worker through a service binding, not its URL (PR #54) | ● Merged |
| Giri-Aayush/copynpaste | Namespace the MCP cached key by API host (PR #55) | ● Merged |
| Giri-Aayush/copynpaste | Open the pricing modal from the keys page instead of redirecting home (PR #60) | ● Merged |
| Giri-Aayush/copynpaste | Give the MCP server a front door: /mcp, and a way in from every surface (PR #57) | ● Merged |
| Giri-Aayush/copynpaste | Add a Humanize toggle that fixes em dashes and filler, with no AI provider (PR #49) | ● Merged |
| Giri-Aayush/copynpaste | Account-bound hashed API keys, a payment-gated MCP free tier, and a standalone MCP Worker (PR #53) | ● Merged |
| jinolabs-xyz/Leads-dashboard | Record that a customer was emailed only when one actually was (#112) (PR #135) | ● Merged |
| jinolabs-xyz/Leads-dashboard | The lead panel on a phone: the title column was zero pixels wide (PR #134) | ● Merged |
| jinolabs-xyz/Leads-dashboard | Nothing deletes a row, and the phone can read a lead card (PR #133) | ● Merged |
| jinolabs-xyz/Leads-dashboard | The proxy shipped as functions/, which that deploy command never compiles (PR #132) | ● Merged |
| jinolabs-xyz/Leads-dashboard | The session cookie was third-party, so browsers were dropping it (PR #131) | ● Merged |
| jinolabs-xyz/Leads-dashboard | A follow-up date cannot hold "call me Tuesday at 4" (PR #130) | ● Merged |
| jinolabs-xyz/Leads-dashboard | The local harness could not create a first account either (PR #129) | ● Merged |
| jinolabs-xyz/Leads-dashboard | Make getting in possible without a shell (PR #128) | ● Merged |
| jinolabs-xyz/Leads-dashboard | A Team screen, because there was no way to add a person from the UI at all (PR #127) | ● Merged |
| jinolabs-xyz/Leads-dashboard | The bundle check failed because the string was there (PR #126) | ● Merged |
| jinolabs-xyz/Leads-dashboard | Stop the deploy verification failing a deploy that worked (PR #125) | ● Merged |
| jinolabs-xyz/Leads-dashboard | Let a human deploy without an account, deliberately and only by hand (PR #124) | ● Merged |
| jinolabs-xyz/Leads-dashboard | Set the secret the way wrangler will actually accept (PR #122) | ● Merged |
| jinolabs-xyz/Leads-dashboard | Put the two production preconditions where the credential actually is (PR #121) | ● Merged |
| jinolabs-xyz/Leads-dashboard | Fix the frontend and triage half of the review findings (PR #120) | ● Merged |
| jinolabs-xyz/Leads-dashboard | Fix eight defects an adversarial review found in the mail path (PR #119) | ● Merged |
| jinolabs-xyz/Leads-dashboard | Write down how the mailer and the triage screen are turned on, and deploy them (PR #118) | ● Merged |
| jinolabs-xyz/Leads-dashboard | Capture a lead in four fields and a paste, not twenty-one inputs (PR #117) | ● Merged |
| jinolabs-xyz/Leads-dashboard | Follow-up triage: one queue, one key per lead — and equal access, asserted (PR #116) | ● Merged |
| jinolabs-xyz/Leads-dashboard | Tier 3: mail that stays attached to its lead, so the queue stops lying (PR #115) | ● Merged |
| jinolabs-xyz/Leads-dashboard | Tier 2: forward an email, get a lead (PR #114) | ● Merged |
| jinolabs-xyz/Leads-dashboard | Tier 1: a morning digest that cannot send itself twice (PR #113) | ● Merged |
| jinolabs-xyz/Leads-dashboard | An outbound channel this repository does not have to name a provider for (PR #110) | ● Merged |
| jinolabs-xyz/Leads-dashboard | Let the trail record a delivery, and keep it unforgeable (PR #109) | ● Merged |
| Entropy-LLP/bharattruck | fix(app): add security response headers, clear all bt-app dependency advisories (PR #152) | ● Merged |
| Entropy-LLP/bharattruck | fix(db): 0033 enable RLS on the freight reference tables (confirmed exploitable) (PR #151) | ● Merged |
| Entropy-LLP/bharattruck | fix(booking,fleet,auth,app): close review C-1/C-2 remainders, S-7 actor+formats, S-6/S-2 UX (PR #150) | ● Merged |
| Entropy-LLP/bharattruck | fix(pricing,fleet,app): drop pilot platform fee, gate truck capacity, add read-only consolidation hint (PR #149) | ● Merged |
| Entropy-LLP/bharattruck | feat(db): 0030 one-live-trip-per-driver index, 0031 fleet GSTIN/PAN format checks (PR #147) | ● Merged |
| Entropy-LLP/bharattruck | fix(fleet): validate GSTIN and PAN by format, not by length (review S-7) (PR #146) | ● Merged |
| Entropy-LLP/bharattruck | fix(auctions): pin the action column on My bids (review S-6, corrected scope) (PR #145) | ● Merged |
| Entropy-LLP/bharattruck | fix(post): name the stale quote, and stop offering past pickup dates (review S-1/S-2) (PR #144) | ● Merged |
| Entropy-LLP/bharattruck | fix(dispatch): one driver, one live trip on the three solo paths (review C-2) (PR #140) | ● Merged |
| Entropy-LLP/bharattruck | fix(marketplace): nobody bids on the load they posted (review C-1) (PR #139) | ● Merged |
| Entropy-LLP/bharattruck | docs(pricing): engine P0–P4 status + P5 data dependency (PR #143) | ● Merged |
| Entropy-LLP/bharattruck | feat(pricing): justify-a-price (Mode B) — reverse breakdown for a self-named bid (P4) (PR #142) | ● Merged |
| Entropy-LLP/bharattruck | feat(pricing): quote↔floor↔market reconciliation + bt-app breakdown (P3) (PR #141) | ● Merged |
| Entropy-LLP/bharattruck | feat(pricing): FR8-calibrated market rate layer, directional (P2) (PR #138) | ● Merged |
| Entropy-LLP/bharattruck | feat(pricing): real road distance from tracking, haversine fallback (P1) (PR #137) | ● Merged |
| Entropy-LLP/bharattruck | feat(pricing): real CV-Parc cost engine — operating-cost floor from seeded norms (P0) (PR #136) | ● Merged |
| Entropy-LLP/bharattruck | fix(infra): remove unauth ledger stub + complete gateway/compose wiring (review F28/F30/F31) (PR #135) | ● Merged |
| Entropy-LLP/bharattruck | fix(auth): harden OTP/enumeration/OAuth/claim-link/KYC surfaces (review F9-F13) (PR #134) | ● Merged |
| Entropy-LLP/bharattruck | fix(bt-app): align api.ts types with the real fleet-service wire (review F4/F5/F6) (PR #133) | ● Merged |
| Entropy-LLP/bharattruck | fix(bt-app): correct three CTA/guard gaps in the unified app (review F1/F2/F3) (PR #132) | ● Merged |
| Entropy-LLP/bharattruck | fix(tracking): scope live position to the booking + guard empty numeric env (review F26/F27) (PR #131) | ● Merged |
| Entropy-LLP/bharattruck | fix(fleet): allow re-crewing an accepted booking before departure (review F25) (PR #130) | ● Merged |
| Entropy-LLP/bharattruck | fix(fleet): normalize driver-invite phone + escape email ILIKE wildcards (review F23/F24) (PR #129) | ● Merged |
| Entropy-LLP/bharattruck | fix(booking): ops can void a bad delivery assertion + reassign is in-flight-only (review F14/F17) (PR #128) | ● Merged |
| Entropy-LLP/bharattruck | fix(booking): instant-accept honours target driver + closes the auction (review F15/F16) (PR #127) | ● Merged |
| Entropy-LLP/bharattruck | fix(booking): scope single-read to the board + mask consignee commercials (review F18/F19) (PR #126) | ● Merged |
| Entropy-LLP/bharattruck | fix(auth): reject single-purpose tokens as full sessions (review F8) (PR #125) | ● Merged |
| Entropy-LLP/bharattruck | fix(review): #123 follow-ups — e-way expiry gate, employed-driver own-load prices, GSTIN consistency + hardening (PR #124) | ● Merged |
| Entropy-LLP/bharattruck | fix: non-payment FB fixes (assign release, docs gate, GSTIN, session partition, de-role) (PR #123) | ● Merged |
| Entropy-LLP/bharattruck | fix(booking): let one-truck fleets bid (gate on carry, not operate) (PR #122) | ● Merged |
| Entropy-LLP/bharattruck | fix(auth): password-reset link follows the deployed domain, not localhost (PR #121) | ● Merged |
| Entropy-LLP/bharattruck | feat: dual-channel driver invites (email OR phone) + distributor truck/driver picker (PR #120) | ● Merged |
| Entropy-LLP/bharattruck | feat(bt-app): driver→owner + fleet-driver invite-accept (the missing persona-transition UIs) (PR #119) | ● Merged |
| Entropy-LLP/bharattruck | feat(bt-app): one-phrase ⓘ tooltips replace on-page prose + fleet-owner onboarding bootstrap (PR #118) | ● Merged |
| Entropy-LLP/bharattruck | refactor(fleet): de-role the driver-side invite gates (D-27, §10.3) (PR #117) | ● Merged |
| Entropy-LLP/bharattruck | feat(bt-app): record payment — close the trip completed → paid through the UI (D-7) (PR #116) | ● Merged |
| Entropy-LLP/bharattruck | feat(bt-app): completeness rings lead with the primary persona (D-32/D-33) (PR #115) | ● Merged |
| Entropy-LLP/bharattruck | feat(bt-app): full auth surface — register + persona picker, email verify, forgot/reset, Google (PR #114) | ● Merged |
| Entropy-LLP/bharattruck | chore(seed): API-driven demo-persona seed (Shipper/Driver/Fleet owner/Distributor) (PR #113) | ● Merged |
| Entropy-LLP/bharattruck | refactor(bt-app): drop verbose UI explanations, add a small ⓘ for terms (founder feedback) (PR #112) | ● Merged |
| Entropy-LLP/bharattruck | feat(bt-app): D-33 persona-completeness ring on settings (Phase 4) (PR #111) | ● Merged |
| Entropy-LLP/bharattruck | feat(bt-app): emergence CTAs — the growth-loop nudge on home (Phase 4, D-32/33) (PR #110) | ● Merged |
| Entropy-LLP/bharattruck | refactor(fleet): de-role authorization — authorize on fleet-owner profile, not JWT role (D-27) (PR #109) | ● Merged |
| Entropy-LLP/bharattruck | feat(bt-app): e-way bill record + status — completes the documents trio (Phase 4c) (PR #108) | ● Merged |
| Entropy-LLP/bharattruck | feat(bt-app): shipper documents — load-detail doc view + shipper invoice issue (Phase 4b) (PR #107) | ● Merged |
| Entropy-LLP/bharattruck | feat(bt-app): freight documents — LR/invoice/e-way surface + carrier LR issue (Phase 4) (PR #106) | ● Merged |
| Entropy-LLP/bharattruck | feat(bt-app): POD evidence capture — camera photo, assert-delivery, discrepancy (Phase 3b) (PR #105) | ● Merged |
| Entropy-LLP/bharattruck | fix(bt-app): let the driver enter the delivery OTP to close the trip (PR #104) | ● Merged |
| Entropy-LLP/bharattruck | feat(bt-app): graft the drive surfaces — My Trips, Navigate, POD (Phase 3) (PR #103) | ● Merged |
| Entropy-LLP/bharattruck | feat(bt-app): graft the ship surfaces — Post a Load, My Loads, load detail (Phase 2) (PR #102) | ● Merged |
| Entropy-LLP/bharattruck | fix(gateway): add bt-app to the CORS origin allowlist (PR #101) | ● Merged |
| Entropy-LLP/bharattruck | fix(ci): classify bt-app as an app, not a backend service (PR #100) | ● Merged |
| Entropy-LLP/bharattruck | feat(bt-app): unified-app foundation — capability-gated shell + home feed (PR #99) | ● Merged |
| Entropy-LLP/bharattruck | feat(booking): GET /me/feed — the unified capability-aware action feed (PR #97) | ● Merged |
| Entropy-LLP/bharattruck | feat(auth): profile-creation, persona completeness, and consignee claim endpoints (PR #98) | ● Merged |
| tachyon-zcash/ragu | Element::batch_invert for the proof-carrying-data framework (PR #813) | ○ Closed |
| zcash/developers | Removed remaining ZenHub references (PR #88) | ○ Open |
| ZecHub/zechub-wiki | Show desktop nav and article chrome from 1280px (PR #803) | ○ Open |
| ZecHub/zechub-wiki | Replace blurry ZecHub title-bar banners with live HTML heroes (PR #802) | ○ Open |
| Giri-Aayush/copynpaste | Strip layout-escaping styles from pasted HTML so long pastes stay in the box (PR #69) | ○ Open |
| Entropy-LLP/bharattruck | docs(bible): §6.4 points at the seed script instead of restating passwords (PR #148) | ○ Open |
| Giri-Aayush/Catalyst | rebrand: Catalyst → Torbit in prose, add api.torbit.xyz (PR #97) | ○ Open |
| Giri-Aayush/frontend | rebrand: Catalyst → Torbit in prose, add app.torbit.xyz (PR #17) | ○ Open |