forked from microservices-patterns/ftgo-monolith
-
Notifications
You must be signed in to change notification settings - Fork 5
Pull requests: COG-GTM/ftgo-monolith
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
feature: extract Order domain into standalone ftgo-order-service with REST client
#340
opened Sep 14, 2026 by
devin-ai-integration
Bot
Loading…
Stop exposing courier live location over HTTP and add location retention purge
#333
opened Sep 9, 2026 by
WesternConcrete
Loading…
Fix: Unvalidated menu item prices on POST /restaurants allow negative-priced menu items and negative order totals
#330
opened Sep 6, 2026 by
WesternConcrete
Loading…
Fix: Spring Framework range requests denial of service (CVE-2018-15756)
#325
opened Sep 4, 2026 by
WesternConcrete
Loading…
Fix: Assembled monolith ships with no authentication or authorization layer over endpoints serving protected data
#324
opened Sep 3, 2026 by
WesternConcrete
Loading…
Fix: Build pinned to EOL Spring Boot 2.0.3.RELEASE with known CVEs
#323
opened Sep 3, 2026 by
WesternConcrete
Loading…
Fix: MySQL image is EOL and not digest-pinned; init script grants ALL PRIVILEGES WITH GRANT OPTION to a wildcard-host user
#322
opened Sep 3, 2026 by
WesternConcrete
Loading…
Fix: Unvalidated line-item quantities on POST /orders and POST /orders/{orderId}/revise allow negative or zero order totals
#321
opened Sep 3, 2026 by
WesternConcrete
Loading…
Fix: Consumer identity records enumerable by sequential ID via unauthenticated GET /consumers/{consumerId}
#320
opened Sep 3, 2026 by
WesternConcrete
Loading…
Fix: Apache Tomcat Improper Input Validation vulnerability
#319
opened Sep 3, 2026 by
WesternConcrete
Loading…
Fix: Missing authentication and authorization on order lifecycle state-transition endpoints
#318
opened Sep 2, 2026 by
WesternConcrete
Loading…
Fix: Unbounded query in /api/tracking endpoints enables memory-exhaustion denial of service
#317
opened Sep 1, 2026 by
WesternConcrete
Loading…
Fix: Relative Path Overwrite (RPO) in io.springfox:springfox-swagger-ui
#316
opened Aug 31, 2026 by
WesternConcrete
Loading…
Fix: Unauthenticated /api/tracking endpoints expose retained request telemetry including client IP addresses
#315
opened Aug 31, 2026 by
WesternConcrete
Loading…
Fix: Consumer PII transits and is logged in plaintext: TLS disabled on the production datasource and SQL statement logging enabled
#314
opened Aug 31, 2026 by
WesternConcrete
Loading…
Fix: Consumer PII sent to MySQL over an unencrypted connection and written to DEBUG SQL logs
#312
opened Aug 30, 2026 by
WesternConcrete
Loading…
Fix: Unauthenticated /api/tracking endpoints expose client IP addresses and request metadata
#311
opened Aug 30, 2026 by
WesternConcrete
Loading…
Fix: Unrestricted cluster access to the FTGO MySQL database
#308
opened Aug 29, 2026 by
WesternConcrete
Loading…
Previous Next
ProTip!
Exclude everything labeled
bug with -label:bug.