-
Notifications
You must be signed in to change notification settings - Fork 241
[comp] Production Deploy #1823
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[comp] Production Deploy #1823
Conversation
Co-authored-by: chasprowebdev <chasgarciaprowebdev@gmail.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
1 Skipped Deployment
|
|
|
🔒 Comp AI - Security Review🔴 Risk Level: HIGH2 high CVEs in xlsx@0.18.5 (Prototype Pollution GHSA-4r6h...; ReDoS GHSA-5pgg...) and 1 low CVE in ai@5.0.0 (filetype whitelist bypass GHSA-rwvc..., fixed in 5.0.52). 📦 Dependency Vulnerabilities🟠 NPM Packages (HIGH)Risk Score: 8/10 | Summary: 2 high, 1 low CVEs found
🛡️ Code Security AnalysisView 15 file(s) with issues🔴 apps/app/src/actions/safe-action.ts (HIGH Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/actions/answer-single-question.ts (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/actions/save-answer.ts (MEDIUM Risk)
Recommendations:
🔴 apps/app/src/app/(app)/[orgId]/security-questionnaire/actions/update-questionnaire-answer.ts (HIGH Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/components/QuestionnaireUpload.tsx (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/hooks/usePersistGeneratedAnswers.ts (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/hooks/useQuestionnaireActions.ts (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/hooks/useQuestionnaireAutoAnswer.ts (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/hooks/useQuestionnaireDetail/useQuestionnaireDetailHandlers.ts (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/hooks/useQuestionnaireDetail/useQuestionnaireDetailState.ts (MEDIUM Risk)
Recommendations:
🔴 apps/app/src/app/(app)/[orgId]/security-questionnaire/hooks/useQuestionnaireParse.ts (HIGH Risk)
Recommendations:
🔴 apps/app/src/app/(app)/[orgId]/security-questionnaire/hooks/useQuestionnaireParser.ts (HIGH Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/hooks/useQuestionnaireSingleAnswer.ts (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/knowledge-base/manual-answers/components/ManualAnswersSection.tsx (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/knowledge-base/page.tsx (MEDIUM Risk)
Recommendations:
💡 RecommendationsView 3 recommendation(s)
Powered by Comp AI - AI that handles compliance for you. Reviewed Nov 24, 2025 |
* fix(security-questionnaire): implement double-click protection and improve parsing state management * fix(file-uploader): remove unnecessary padding from uploader component * refactor(security-questionnaire): clean up auto-answer hook by removing debug logging and optimizing metadata handling * refactor(security-questionnaire): add parse process state management * feat(security-questionnaire): implement manual answer linking and update questionnaire components * fix(security-questionnaire): enable CTA button for navigating to policies page * feat(docs): create documentation (without video) * refactor(security-questionnaire): normalize results and update button states * refactor(parse-questionnaire): enhance chunk processing and question extraction logic --------- Co-authored-by: Tofik Hasanov <annexcies@gmail.com> Co-authored-by: Mariano Fuentes <marfuen98@gmail.com>
🔒 Comp AI - Security Review🔴 Risk Level: HIGHOSV: 2 HIGH CVEs in xlsx@0.18.5 and 1 LOW CVE in ai@5.0.0. Code: SQL injection in questionnaire page and multiple stored XSS (page.tsx, save-answer.ts, update-questionnaire-answer.ts). 📦 Dependency Vulnerabilities🟠 NPM Packages (HIGH)Risk Score: 8/10 | Summary: 2 high, 1 low CVEs found
🛡️ Code Security AnalysisView 14 file(s) with issues🔴 apps/app/src/actions/safe-action.ts (HIGH Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/[questionnaireId]/page.tsx (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/actions/save-answer.ts (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/actions/update-questionnaire-answer.ts (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/components/QuestionnaireUpload.tsx (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/hooks/usePersistGeneratedAnswers.ts (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/hooks/useQuestionnaireActions.ts (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/hooks/useQuestionnaireAutoAnswer.ts (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/hooks/useQuestionnaireDetail/useQuestionnaireDetailHandlers.ts (MEDIUM Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/hooks/useQuestionnaireDetail/useQuestionnaireDetailState.ts (MEDIUM Risk)
Recommendations:
🔴 apps/app/src/app/(app)/[orgId]/security-questionnaire/hooks/useQuestionnaireParse.ts (HIGH Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/knowledge-base/page.tsx (MEDIUM Risk)
Recommendations:
🟢 apps/app/src/app/(app)/[orgId]/security-questionnaire/knowledge-base/published-policies/components/PublishedPoliciesSection.tsx (LOW Risk)
Recommendations:
🟡 apps/app/src/app/(app)/[orgId]/security-questionnaire/page.tsx (MEDIUM Risk)
Recommendations:
💡 RecommendationsView 1 recommendation(s)
Powered by Comp AI - AI that handles compliance for you. Reviewed Nov 24, 2025 |
…1825) Co-authored-by: Tofik Hasanov <annexcies@gmail.com>
…1826) Co-authored-by: Tofik Hasanov <annexcies@gmail.com>
|
🎉 This PR is included in version 1.64.0 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
This is an automated pull request to release the candidate branch into production, which will trigger a deployment.
It was created by the [Production PR] action.