Critical · Authorization bypass
Exploit reproduced. A focused fix as branch + PR, ready for review.
Critical finding in a customer-facing app, on main.
Matches your policy: severity, repo, branch.
Verify, fix, test. Never a blind patch.
Slack + email, with the trace.
Critical · Authorization bypass
Exploit reproduced. A focused fix as branch + PR, ready for review.
High · Unsafe deserialization
Sink unreachable. Reasoned, documented, closed.
High · SSRF
Not exploitable. Explained, in the trace, no backlog line.
No. Every action starts with verification: reproduce the exploit, load context, then decide: fix-PR, no change, false positive.
Every action with a trace: verify, context, decision. In the report and the channel.
Your review stays the gate. Nothing merges without you.