-
Notifications
You must be signed in to change notification settings - Fork 121
All issues
Issue creation is restricted in this repository
Issues
is:issue state:open
is:issue state:open
Search results
[Bug] TTS service Dockerfile base images are unpinned, inconsistent with the API image's digest-pinned supply-chain hygiene
backendBackend service issuesBackend service issuespriority:lowLow priorityLow prioritysecuritySecurity vulnerabilities and hardeningSecurity vulnerabilities and hardeningStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programttsText-to-Speech serviceText-to-Speech serviceStatus: Open.#1220 In solutions-plug/predictIQ;[Bug] TTS service sends no HTTP security headers (no helmet or equivalent middleware)
backendBackend service issuesBackend service issuesjavascriptPull requests that update javascript codePull requests that update javascript codepriority:mediumMedium priorityMedium prioritysecuritySecurity vulnerabilities and hardeningSecurity vulnerabilities and hardeningStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programttsText-to-Speech serviceText-to-Speech serviceStatus: Open.#1219 In solutions-plug/predictIQ;[Bug] .semgrep.yml's missing-auth-check rule likely never fires due to an unbound metavariable
infrastructureTerraform, AWS, and deployment infrastructureTerraform, AWS, and deployment infrastructurepriority:lowLow priorityLow prioritysecuritySecurity vulnerabilities and hardeningSecurity vulnerabilities and hardeningStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programStatus: Open.#1218 In solutions-plug/predictIQ;[Bug] Gitleaks allowlist regexes for localhost/127.0.0.1 are overly broad and can mask real leaked credentials
infrastructureTerraform, AWS, and deployment infrastructureTerraform, AWS, and deployment infrastructurepriority:mediumMedium priorityMedium prioritysecuritySecurity vulnerabilities and hardeningSecurity vulnerabilities and hardeningStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programStatus: Open.#1217 In solutions-plug/predictIQ;[Bug] docker-compose.tracing.yml pins its observability stack images to the mutable :latest tag
infrastructureTerraform, AWS, and deployment infrastructureTerraform, AWS, and deployment infrastructurepriority:lowLow priorityLow priorityreliabilityResilience, recovery, and uptimeResilience, recovery, and uptimeStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programStatus: Open.#1216 In solutions-plug/predictIQ;[Bug] No CI job across any workflow sets timeout-minutes, risking runaway jobs holding shared resources
infrastructureTerraform, AWS, and deployment infrastructureTerraform, AWS, and deployment infrastructurepriority:mediumMedium priorityMedium priorityreliabilityResilience, recovery, and uptimeResilience, recovery, and uptimeStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programStatus: Open.#1215 In solutions-plug/predictIQ;[Bug] ROLLBACK.md documents the wrong S3 bucket/key names for Terraform state recovery
infrastructureTerraform, AWS, and deployment infrastructureTerraform, AWS, and deployment infrastructurepriority:mediumMedium priorityMedium priorityreliabilityResilience, recovery, and uptimeResilience, recovery, and uptimeStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programStatus: Open.#1214 In solutions-plug/predictIQ;[Bug] release.yml pushes the CHANGELOG directly to main from CI, bypassing branch protection and review
infrastructureTerraform, AWS, and deployment infrastructureTerraform, AWS, and deployment infrastructurepriority:mediumMedium priorityMedium prioritysecuritySecurity vulnerabilities and hardeningSecurity vulnerabilities and hardeningStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programStatus: Open.#1213 In solutions-plug/predictIQ;[Bug] Third-party GitHub Actions across all workflows are pinned to mutable version tags, not commit SHAs
infrastructureTerraform, AWS, and deployment infrastructureTerraform, AWS, and deployment infrastructurepriority:mediumMedium priorityMedium prioritysecuritySecurity vulnerabilities and hardeningSecurity vulnerabilities and hardeningStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programStatus: Open.#1212 In solutions-plug/predictIQ;[Bug] Unmaintained/archived third-party GitHub Actions are used for critical release and deployment build steps
infrastructureTerraform, AWS, and deployment infrastructureTerraform, AWS, and deployment infrastructurepriority:mediumMedium priorityMedium prioritysecuritySecurity vulnerabilities and hardeningSecurity vulnerabilities and hardeningStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programStatus: Open.#1211 In solutions-plug/predictIQ;[Bug] Rust dependency audit only fails CI on 'critical' severity advisories, silently allowing 'high' severity through
infrastructureTerraform, AWS, and deployment infrastructureTerraform, AWS, and deployment infrastructurepriority:mediumMedium priorityMedium priorityreliabilityResilience, recovery, and uptimeResilience, recovery, and uptimeStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programStatus: Open.#1210 In solutions-plug/predictIQ;[Bug] main.tf uses timestamp() in provider default_tags, causing a perpetual non-idempotent diff on every plan
infrastructureTerraform, AWS, and deployment infrastructureTerraform, AWS, and deployment infrastructurereliabilityResilience, recovery, and uptimeResilience, recovery, and uptimeStellar WaveIssues in the Stellar wave programIssues in the Stellar wave programStatus: Open.#1209 In solutions-plug/predictIQ;