Skip to content
Navigation Menu
Sign in
Appearance settings
Platform
AI CODE CREATION
GitHub Copilot
Write better code with AI
GitHub Copilot app
Direct agents from issue to merge
MCP Registry
Integrate external tools
DEVELOPER WORKFLOWS
Actions
Automate any workflow
Codespaces
Instant dev environments
Issues
Plan and track work
Code Review
Manage code changes
Code Quality
Enforce quality at merge
APPLICATION SECURITY
GitHub Advanced Security
Find and fix vulnerabilities
Code security
Secure your code as you build
Secret protection
Stop leaks before they start
EXPLORE
Why GitHub
Documentation
Blog
Changelog
Marketplace
View all features
Solutions
BY COMPANY SIZE
Enterprises
Small and medium teams
Startups
Nonprofits
BY USE CASE
App Modernization
DevSecOps
DevOps
CI/CD
View all use cases
BY INDUSTRY
Healthcare
Financial services
Manufacturing
Government
View all industries
View all solutions
Resources
EXPLORE BY TOPIC
AI
Software Development
DevOps
Security
View all topics
EXPLORE BY TYPE
Customer stories
Events & webinars
Ebooks & reports
Business insights
GitHub Skills
SUPPORT & SERVICES
Documentation
Customer support
Community forum
Trust center
Partners
View all resources
Open Source
COMMUNITY
GitHub Sponsors
Fund open source developers
PROGRAMS
Security Lab
Maintainer Community
GitHub Stars
Archive Program
REPOSITORIES
Topics
Trending
Collections
Enterprise
ENTERPRISE SOLUTIONS
Enterprise platform
AI-powered developer platform
AVAILABLE ADD-ONS
GitHub Advanced Security
Enterprise-grade security features
Copilot for Business
Enterprise-grade AI features
Premium Support
Enterprise-grade 24/7 support
Pricing
Search
/
Sign in
Sign up
Appearance settings
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
Uh oh!
There was an error while loading.
Please reload this page
.
COG-GTM
/
nodejs-goof
Public
forked from
snyk-labs/nodejs-goof
Notifications
You must be signed in to change notification settings
Fork
3
Star
0
Code
Pull requests
255
Actions
Projects
Security and quality
0
Insights
Additional navigation options
Code
Pull requests
Actions
Projects
Security and quality
Insights
Actions: COG-GTM/nodejs-goof
Actions
All workflows
Workflows
snyk code manual test
snyk code manual test
snyk code test
snyk code test
snyk test
snyk test
Show more workflows...
Management
Caches
snyk code manual test
snyk code manual test
Actions
Loading...
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading.
Please reload this page
.
will be ignored since log searching is not yet available
Show workflow options
Create status badge
Create status badge
Loading
Uh oh!
There was an error while loading.
Please reload this page
.
snyk-code-manual.yml
will be ignored since log searching is not yet available
660 workflow runs
660 workflow runs
Event
Filter by Event
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching events.
Status
Filter by Status
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching statuses.
Branch
Filter by Branch
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching branches.
Actor
Filter by Actor
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching users.
fix(S5147): validate login credentials are strings before MongoDB query [SonarQube AZhSVLrd4wErqc9Ey1Y3]
snyk code manual test
#661:
Pull request
#286
synchronize by
devin-ai-integration
Bot
29s
devin/sonarqube-fix-AZhSVLrd4wErqc9Ey1Y3-1789463125
devin/sonarqube-fix-AZhSVLrd4wErqc9Ey1Y3-1789463125
29s
View #286
View workflow file
bug: S5147 NoSQL injection fix in loginHandler [SonarQube AZhSVLrd4wE…
snyk code manual test
#660:
Commit
4169a01
pushed by
devin-ai-integration
Bot
23s
devin/sonarqube-fix-AZhSVLrd4wErqc9Ey1Y3-1789463125
devin/sonarqube-fix-AZhSVLrd4wErqc9Ey1Y3-1789463125
23s
View #286
View workflow file
fix(S5147): validate login credentials are strings before MongoDB query [SonarQube AZhSVLrd4wErqc9Ey1Y3]
snyk code manual test
#659:
Pull request
#286
opened by
devin-ai-integration
Bot
20s
devin/sonarqube-fix-AZhSVLrd4wErqc9Ey1Y3-1789463125
devin/sonarqube-fix-AZhSVLrd4wErqc9Ey1Y3-1789463125
20s
View #286
View workflow file
fix(S2083): stop passing raw request body to account view render [SonarQube AZoM-zIBs8nSf3VywcRW]
snyk code manual test
#658:
Pull request
#285
opened by
devin-ai-integration
Bot
20s
devin/sonarqube-fix-AZoM-zIBs8nSf3VywcRW-1789463148
devin/sonarqube-fix-AZoM-zIBs8nSf3VywcRW-1789463148
20s
View #285
View workflow file
fix(S5146): validate admin login redirect target to prevent open redirect [SonarQube AZhSVLrd4wErqc9Ey1Y4]
snyk code manual test
#657:
Pull request
#284
opened by
devin-ai-integration
Bot
20s
devin/sonarqube-fix-AZhSVLrd4wErqc9Ey1Y4-1789463126
devin/sonarqube-fix-AZhSVLrd4wErqc9Ey1Y4-1789463126
20s
View #284
View workflow file
fix(S2083): pass only validated fields to account view render [SonarQ…
snyk code manual test
#656:
Commit
1f1bb4a
pushed by
devin-ai-integration
Bot
23s
devin/sonarqube-fix-AZoM-zIBs8nSf3VywcRW-1789463148
devin/sonarqube-fix-AZoM-zIBs8nSf3VywcRW-1789463148
23s
View #285
View workflow file
fix(S5147): validate login credentials are strings before MongoDB que…
snyk code manual test
#655:
Commit
b8f70e8
pushed by
devin-ai-integration
Bot
22s
devin/sonarqube-fix-AZhSVLrd4wErqc9Ey1Y3-1789463125
devin/sonarqube-fix-AZhSVLrd4wErqc9Ey1Y3-1789463125
22s
View workflow file
bug: categorize S5146 open redirect fix [SonarQube AZhSVLrd4wErqc9Ey1Y4]
snyk code manual test
#654:
Commit
4155956
pushed by
devin-ai-integration
Bot
22s
devin/sonarqube-fix-AZhSVLrd4wErqc9Ey1Y4-1789463126
devin/sonarqube-fix-AZhSVLrd4wErqc9Ey1Y4-1789463126
22s
View #284
View workflow file
fix(S5146): validate admin login redirect target to prevent open redi…
snyk code manual test
#653:
Commit
19b51bc
pushed by
devin-ai-integration
Bot
23s
devin/sonarqube-fix-AZhSVLrd4wErqc9Ey1Y4-1789463126
devin/sonarqube-fix-AZhSVLrd4wErqc9Ey1Y4-1789463126
23s
View workflow file
Fix NoSQL/SQL injection, prototype pollution and vulnerable dependencies
snyk code manual test
#652:
Pull request
#283
opened by
devin-ai-integration
Bot
22s
devin/1789402286-fix-injection-proto-pollution
devin/1789402286-fix-injection-proto-pollution
22s
View #283
View workflow file
bug: fix NoSQL/SQL injection, prototype pollution and upgrade vulnera…
snyk code manual test
#651:
Commit
c9d0c71
pushed by
devin-ai-integration
Bot
32s
devin/1789402286-fix-injection-proto-pollution
devin/1789402286-fix-injection-proto-pollution
32s
View #283
View workflow file
Update deprecated checkout and upload-sarif actions (#1318)
snyk code manual test
#650:
Commit
d240896
pushed by
devin-ai-integration
Bot
26s
devin/1789402286-fix-injection-proto-pollution
devin/1789402286-fix-injection-proto-pollution
26s
View workflow file
fix(security): remediate jssecurity:S5147 NoSQL injection in routes/index.js loginHandler (SonarQube AZhSVLrd4wErqc9Ey1Y3)
snyk code manual test
#649:
Pull request
#277
synchronize by
devin-ai-integration
Bot
34s
devin/sonarqube-fix-AZhSVLrd4wErqc9Ey1Y3
devin/sonarqube-fix-AZhSVLrd4wErqc9Ey1Y3
34s
View #277
View workflow file
bug: fix jssecurity:S5147 in routes/index.js (SonarQube AZhSVLrd4wErq…
snyk code manual test
#648:
Commit
f026411
pushed by
devin-ai-integration
Bot
21s
devin/sonarqube-fix-AZhSVLrd4wErqc9Ey1Y3
devin/sonarqube-fix-AZhSVLrd4wErqc9Ey1Y3
21s
View #277
View workflow file
fix: [sha.js] Upgrade sha.js from 2.4.11 to 2.4.12 to resolve CVE-2025-9288
snyk code manual test
#647:
Pull request
#280
synchronize by
devin-ai-integration
Bot
23s
devin/1789373306-fix-shajs-cve-2025-9288
devin/1789373306-fix-shajs-cve-2025-9288
23s
View #280
View workflow file
bug: lock sha.js 2.4.12 transitive deps (to-buffer) so clean installs…
snyk code manual test
#646:
Commit
b9acc3a
pushed by
devin-ai-integration
Bot
20s
devin/1789373306-fix-shajs-cve-2025-9288
devin/1789373306-fix-shajs-cve-2025-9288
20s
View #280
View workflow file
fix: [sha.js] Upgrade sha.js from 2.4.11 to 2.4.12 to resolve CVE-2025-9288
snyk code manual test
#645:
Pull request
#280
synchronize by
devin-ai-integration
Bot
23s
devin/1789373306-fix-shajs-cve-2025-9288
devin/1789373306-fix-shajs-cve-2025-9288
23s
View #280
View workflow file
bug: relock legacy dependencies entry for sha.js 2.4.12 too
snyk code manual test
#644:
Commit
b6db170
pushed by
devin-ai-integration
Bot
23s
devin/1789373306-fix-shajs-cve-2025-9288
devin/1789373306-fix-shajs-cve-2025-9288
23s
View workflow file
fix: [ejs] Upgrade ejs from 1.0.0 to 3.1.10 to resolve CVE-2022-29078
snyk code manual test
#643:
Pull request
#282
opened by
hannahhuh-cog
23s
devin/1789373378-fix-ejs-rce-cve-2022-29078
devin/1789373378-fix-ejs-rce-cve-2022-29078
23s
View #282
View workflow file
fix: [form-data] Upgrade form-data from 2.3.3 to 2.5.4 to resolve CVE-2025-7783
snyk code manual test
#642:
Pull request
#281
opened by
hannahhuh-cog
30s
devin/1789373356-fix-form-data-cve-2025-7783
devin/1789373356-fix-form-data-cve-2025-7783
30s
View #281
View workflow file
fix: [sha.js] Upgrade sha.js from 2.4.11 to 2.4.12 to resolve CVE-2025-9288
snyk code manual test
#641:
Pull request
#280
opened by
hannahhuh-cog
23s
devin/1789373306-fix-shajs-cve-2025-9288
devin/1789373306-fix-shajs-cve-2025-9288
23s
View #280
View workflow file
fix: [hbs] Upgrade hbs from 4.0.4 to 4.3.0 (handlebars 4.0.14 to 4.7.9) to resolve CVE-2026-33938
snyk code manual test
#640:
Pull request
#279
opened by
hannahhuh-cog
21s
devin/1789373286-fix-hbs-handlebars-type-confusion
devin/1789373286-fix-hbs-handlebars-type-confusion
21s
View #279
View workflow file
fix: [adm-zip] Upgrade adm-zip from 0.4.7 to 0.5.18 to resolve CVE-2018-1002204
snyk code manual test
#639:
Pull request
#278
opened by
hannahhuh-cog
25s
devin/1789373255-fix-adm-zip-zip-slip
devin/1789373255-fix-adm-zip-zip-slip
25s
View #278
View workflow file
bug: upgrade ejs to 3.1.10
snyk code manual test
#638:
Commit
a6bba44
pushed by
devin-ai-integration
Bot
21s
devin/1789373378-fix-ejs-rce-cve-2022-29078
devin/1789373378-fix-ejs-rce-cve-2022-29078
21s
View #282
View workflow file
bug: override form-data to 2.5.4
snyk code manual test
#637:
Commit
4d15cc3
pushed by
devin-ai-integration
Bot
18s
devin/1789373356-fix-form-data-cve-2025-7783
devin/1789373356-fix-form-data-cve-2025-7783
18s
View #281
View workflow file
Previous
1
2
3
4
5
…
26
27
Next
You can’t perform that action at this time.