Scoped integration
Pick the repositories, triggers, and boundaries that fit your process, and roll out one team at a time.
Bring application-aware security review into every pull request and pipeline, with fixes suggested where developers already work.
Add admin export endpoint
#2481 · feat/export → main · +48 −6
| @@ -9,0 +10,6 @@ router | ||
| 10 | +router.get( | |
| 11 | + "/admin/export", | |
winfuncHighCWE-862 This admin route has no role check. Any signed-in user can export every customer's invoices. Reproduced with a member account. + requireRole("admin"), Commit suggestionDismiss | ||
| 12 | + async (req, res) => { | |
| 13 | + const rows = await exportAll(req.query); | |
| 14 | + res.csv(rows); | |
Point-in-time reviews can't keep up with daily deploys, and noisy checks on every diff get ignored. winfunc reviews the changes that matter, anchors findings to the lines under review, and verifies the fix before merge.
Pick the repositories, triggers, and boundaries that fit your process, and roll out one team at a time.
Findings land on the affected change with severity, evidence, and a suggested fix, so developers act in the review.
Define who can request a review, assess a finding, and approve a change. Merge authority stays with your team.
A vulnerability fixed before merge never needs an incident, a hotfix, or a customer notice.
Continue the evaluation
Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.