Skip to content
winfunc
Pull requests
Available

Security review on every pull request.

Diff-aware analysis of each change, with findings anchored to the lines under review and fixes suggested in place. Catch the vulnerability before it merges.

  1. acme
  2. /billing-api
  3. /PR reviews
  4. /#2481
1 finding

Add admin export endpoint

#2481 · feat/export → main · +48 −6

  1. Diff scoped
  2. Traced
  3. Reproduced
src/routes/admin/export.ts+5−0
@@ -9,0 +10,6 @@ router
10+router.get(
11+ "/admin/export",
winfuncHighCWE-862

This admin route has no role check. Any signed-in user can export every customer's invoices. Reproduced with a member account.

+ requireRole("admin"),
Commit suggestionDismiss
12+ async (req, res) => {
13+ const rows = await exportAll(req.query);
14+ res.csv(rows);
PR review · inline findingIllustrative data
What it does

Capabilities.

  • Automatic review of pull requests, or on request with @winfunc
  • Diff-aware analysis of changed files and relevant surrounding code
  • Findings anchored to changed lines in the pull request
  • Suggested fixes inside the review conversation
  • Repository-owned review criteria and focus rules
  • Base and head revisions recorded for every review
  • Explicit re-review: fixed or still present
  • Dedicated pull-request scans view in the dashboard
  • Works with GitHub, GitLab, Bitbucket, and Azure DevOps
Why it matters

Built for decisions, not queues.

01

Shift security left

Review happens while the change is still open. Developers see the finding next to the code that caused it and fix it before merge.

02

Incremental analysis

Focus on what changed while following the surrounding code the change touches, so reviews stay fast without losing context.

03

Re-review that proves the fix

Push an update and winfunc checks it again, returning an explicit verdict of fixed or still present.

04

Native to your source control

Install the app, choose repositories, and reviews appear in the pull request. Everything also stays available in the winfunc workspace.

Continue the evaluation

Start with one repository

Bring us your hardest codebase.
We'll bring the proof.

Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.