Skip to content
Navigation Menu
Sign in
Appearance settings
Platform
AI CODE CREATION
GitHub Copilot
Write better code with AI
GitHub Copilot app
Direct agents from issue to merge
MCP Registry
Integrate external tools
DEVELOPER WORKFLOWS
Actions
Automate any workflow
Codespaces
Instant dev environments
Issues
Plan and track work
Code Review
Manage code changes
Code Quality
Enforce quality at merge
APPLICATION SECURITY
GitHub Advanced Security
Find and fix vulnerabilities
Code security
Secure your code as you build
Secret protection
Stop leaks before they start
EXPLORE
Why GitHub
Documentation
Blog
Changelog
Marketplace
View all features
Solutions
BY COMPANY SIZE
Enterprises
Small and medium teams
Startups
Nonprofits
BY USE CASE
App Modernization
DevSecOps
DevOps
CI/CD
View all use cases
BY INDUSTRY
Healthcare
Financial services
Manufacturing
Government
View all industries
View all solutions
Resources
EXPLORE BY TOPIC
AI
Software Development
DevOps
Security
View all topics
EXPLORE BY TYPE
Customer stories
Events & webinars
Ebooks & reports
Business insights
GitHub Skills
SUPPORT & SERVICES
Documentation
Customer support
Community forum
Trust center
Partners
View all resources
Open Source
COMMUNITY
GitHub Sponsors
Fund open source developers
PROGRAMS
Security Lab
Maintainer Community
GitHub Stars
Archive Program
REPOSITORIES
Topics
Trending
Collections
Enterprise
ENTERPRISE SOLUTIONS
Enterprise platform
AI-powered developer platform
AVAILABLE ADD-ONS
GitHub Advanced Security
Enterprise-grade security features
Copilot for Business
Enterprise-grade AI features
Premium Support
Enterprise-grade 24/7 support
Pricing
Search
/
Sign in
Sign up
Appearance settings
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
opendefender
OpenRisk
Repository navigation
Code
Issues
310
(310)
Pull requests
Discussions
Actions
Projects
Security and quality
2
(2)
Insights
More
items
Actions: opendefender/OpenRisk
Actions
All workflows
Workflows
Agent Review
Agent Review
Agent Triage
Agent Triage
CI Pipeline
CI Pipeline
DCO
DCO
Dependency gate
Dependency gate
Deploy
Deploy
E2E Tests
E2E Tests
pages-build-deployment
pages-build-deployment
Release
Release
Security Scanning
Security Scanning
Show more workflows...
Management
Caches
Deployments
DCO
DCO
Actions
Loading...
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading.
Please reload this page
.
will be ignored since log searching is not yet available
Show workflow options
Create status badge
Create status badge
Loading
Uh oh!
There was an error while loading.
Please reload this page
.
dco.yml
will be ignored since log searching is not yet available
215 workflow runs
215 workflow runs
Event
Filter by Event
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching events.
Status
Filter by Status
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching statuses.
Branch
Filter by Branch
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching branches.
Actor
Filter by Actor
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching users.
fix(auth): store the MFA enrolment in one transaction and never return database text (#714)
DCO
#215:
Pull request
#898
opened by
alex-dembele
16s
fix/714-mfa-setup-atomic
fix/714-mfa-setup-atomic
16s
View #898
View workflow file
test(auth): prove two tabs refreshing at once stay signed in (#700)
DCO
#214:
Pull request
#896
opened by
alex-dembele
19s
fix/700-concurrent-refresh-two-tabs
fix/700-concurrent-refresh-two-tabs
19s
View #896
View workflow file
fix(frontend): give LoginForm its notice prop back (#893)
DCO
#213:
Pull request
#894
opened by
alex-dembele
12s
fix/893-login-notice-prop
fix/893-login-notice-prop
12s
View #894
View workflow file
fix(frontend): tell users to sign in again or wait after too many MFA codes (#872)
DCO
#212:
Pull request
#880
synchronize by
alex-dembele
14s
fix/872-mfa-challenge-refusals
fix/872-mfa-challenge-refusals
14s
View #880
View workflow file
fix(auth): per-purpose throttles, per-address sign-in backoff, constant-work login (#688)
DCO
#211:
Pull request
#874
reopened by
alex-dembele
1m 13s
688-auth-throttle
688-auth-throttle
1m 13s
View #874
View workflow file
fix(frontend): tell users to sign in again or wait after too many MFA codes (#872)
DCO
#210:
Pull request
#880
synchronize by
alex-dembele
36s
fix/872-mfa-challenge-refusals
fix/872-mfa-challenge-refusals
36s
View #880
View workflow file
fix(auth): let an unfinished MFA enrolment start over (#889)
DCO
#209:
Pull request
#892
opened by
alex-dembele
45s
fix/889-reenrol-after-unfinished-setup
fix/889-reenrol-after-unfinished-setup
45s
View #892
View workflow file
chore(lint): make the ESLint ratchet pass on master again, and tighten it to 99 (#627)
DCO
#208:
Pull request
#891
opened by
alex-dembele
17s
chore/627-lint-ratchet-green
chore/627-lint-ratchet-green
17s
View #891
View workflow file
feat(assets): CSV import of the asset inventory (#861)
DCO
#207:
Pull request
#862
reopened by
alex-dembele
15s
861-featassets-csv-import-of-the-asset-inventory
861-featassets-csv-import-of-the-asset-inventory
15s
View #862
View workflow file
fix(auth): sweep refresh revocations until a pass finds nothing (#725)
DCO
#206:
Pull request
#890
opened by
alex-dembele
12s
fix/725-revocation-sweep
fix/725-revocation-sweep
12s
View #890
View workflow file
fix(auth): accept a TOTP code only once (#849)
DCO
#205:
Pull request
#851
reopened by
alex-dembele
16s
849-securityauth-a-totp-code-can-be-replayed-within-its-validity-window
849-securityauth-a-totp-code-can-be-replayed-within-its-validity-window
16s
View #851
View workflow file
fix(settings): tell an SSO account its password lives at the identity provider (#850)
DCO
#204:
Pull request
#852
reopened by
alex-dembele
15s
850-bugsettings-an-sso-account-is-offered-a-change-password-form-it-cannot-use
850-bugsettings-an-sso-account-is-offered-a-change-password-form-it-cannot-use
15s
View #852
View workflow file
fix(auth): restore the fail-closed SAML handler so master compiles (#886)
DCO
#203:
Pull request
#888
opened by
alex-dembele
15s
fix/886-saml-handler-build
fix/886-saml-handler-build
15s
View #888
View workflow file
docs(decisions): raise D-064 (sign-in lock) and D-065 (audit address hash) (#879)
DCO
#202:
Pull request
#887
opened by
alex-dembele
16s
879-decisions-login-lock
879-decisions-login-lock
16s
View #887
View workflow file
chore(frontend): clear the two eslint errors in the auth feature (#878)
DCO
#201:
Pull request
#885
opened by
alex-dembele
17s
878-auth-lint
878-auth-lint
17s
View #885
View workflow file
perf(db): index LOWER(email) for the case-insensitive account lookup (#876)
DCO
#200:
Pull request
#884
opened by
alex-dembele
17s
876-email-lower-index
876-email-lower-index
17s
View #884
View workflow file
fix(audit): record the trusted-proxy-aware client IP, never raw X-Forwarded-For (#877)
DCO
#199:
Pull request
#883
opened by
alex-dembele
14s
877-audit-ip
877-audit-ip
14s
View #883
View workflow file
fix(auth): master does not build — restore the #866 SAML handler (#881)
DCO
#198:
Pull request
#882
opened by
alex-dembele
14s
fix/881-saml-merge-build
fix/881-saml-merge-build
14s
View #882
View workflow file
fix(frontend): tell users to sign in again or wait after too many MFA codes (#872)
DCO
#197:
Pull request
#880
opened by
alex-dembele
16s
fix/872-mfa-challenge-refusals
fix/872-mfa-challenge-refusals
16s
View #880
View workflow file
fix(auth): SAML endpoints refuse every request until assertions are verified (#866)
DCO
#196:
Pull request
#868
synchronize by
alex-dembele
12s
security/866-saml-fail-closed
security/866-saml-fail-closed
12s
View #868
View workflow file
fix(auth): API tokens from Settings authenticate, persist and stay in their tenant (#782)
DCO
#195:
Pull request
#853
synchronize by
alex-dembele
11s
782-fixauth-les-jetons-api-generes-depuis-reglages-nauthentifient-rien-et-ne-persistent-pas
782-fixauth-les-jetons-api-generes-depuis-reglages-nauthentifient-rien-et-ne-persistent-pas
11s
View #853
View workflow file
fix(auth): limit MFA challenge attempts and revoke the access token on logout (#689)
DCO
#194:
Pull request
#875
opened by
alex-dembele
15s
689-mfa-challenge-limits
689-mfa-challenge-limits
15s
View #875
View workflow file
fix(auth): per-purpose throttles, per-address sign-in backoff, constant-work login (#688)
DCO
#193:
Pull request
#874
opened by
alex-dembele
11s
688-auth-throttle
688-auth-throttle
11s
View #874
View workflow file
fix(users): POST /users creates an account that can sign in (#870)
DCO
#192:
Pull request
#871
synchronize by
alex-dembele
20s
689-securityauth-mfa-challenge-codes-can-be-guessed-without-limit-no-attempt-counter-no-rate-limit
689-securityauth-mfa-challenge-codes-can-be-guessed-without-limit-no-attempt-counter-no-rate-limit
20s
View #871
View workflow file
fix(users): POST /users creates an account that can sign in (#870)
DCO
#191:
Pull request
#871
opened by
alex-dembele
11s
689-securityauth-mfa-challenge-codes-can-be-guessed-without-limit-no-attempt-counter-no-rate-limit
689-securityauth-mfa-challenge-codes-can-be-guessed-without-limit-no-attempt-counter-no-rate-limit
11s
View #871
View workflow file
Previous
1
2
3
4
5
…
8
9
Next
You can’t perform that action at this time.