Shift security left
Review happens while the change is still open. Developers see the finding next to the code that caused it and fix it before merge.
Diff-aware analysis of each change, with findings anchored to the lines under review and fixes suggested in place. Catch the vulnerability before it merges.
Add admin export endpoint
#2481 · feat/export → main · +48 −6
| @@ -9,0 +10,6 @@ router | ||
| 10 | +router.get( | |
| 11 | + "/admin/export", | |
winfuncHighCWE-862 This admin route has no role check. Any signed-in user can export every customer's invoices. Reproduced with a member account. + requireRole("admin"), Commit suggestionDismiss | ||
| 12 | + async (req, res) => { | |
| 13 | + const rows = await exportAll(req.query); | |
| 14 | + res.csv(rows); | |
Review happens while the change is still open. Developers see the finding next to the code that caused it and fix it before merge.
Focus on what changed while following the surrounding code the change touches, so reviews stay fast without losing context.
Push an update and winfunc checks it again, returning an explicit verdict of fixed or still present.
Install the app, choose repositories, and reviews appear in the pull request. Everything also stays available in the winfunc workspace.
Continue the evaluation
Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.