Commits
Note: To verify signed commits locally, download the allowed signers file and run: git -c gpg.format=ssh -c gpg.ssh.allowedSignersFile=allowed_signers verify-commit <hash>
- hide useless git error
- fix: empty repo setup url
- fix: show flash messages for cache purge and file delete failures
- add ci doc
- ci: variable form for manual runs, setup as first step, header layout
- ci: export the commit with git archive instead of cloning in the container
- ci: steps array, image copies, step flags, and bounded caches
- ci: upload the repo instead of bind-mounting it from the host
- bun 1.4 upgrade, major simplification/refactor
- update runtime, fix lock bug
- harden low-severity review findings across git, CI, and auth
- security: fix git arg injection and harden CI, transport, and uploads
- small ui fixes
- add LICENSE.md
- style fixes of repo danger zone
- escape jsx strings
- CSP fixes
- default scanned repo to private
- security: harden cookies + CSRF for reverse-proxy deployments
- security: fix authz, DOS, and concurrency findings from review