-
Notifications
You must be signed in to change notification settings - Fork 4.3k
Pull requests: openedx/openedx-platform
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
fix(extract_archive): reject zip/tar bombs in safe_extractall
open-source-contribution
PR author is not from Axim or 2U
#38346
opened Apr 10, 2026 by
kingoftech-v01
Loading…
3 tasks
fix(profile_images): reject PIL decompression bombs on profile upload
open-source-contribution
PR author is not from Axim or 2U
#38345
opened Apr 10, 2026 by
kingoftech-v01
Loading…
3 tasks
fix: pin CELERY_ACCEPT_CONTENT to json-only to block unsafe payloads
open-source-contribution
PR author is not from Axim or 2U
#38344
opened Apr 10, 2026 by
kingoftech-v01
Loading…
3 tasks
fix: set SECURE_REFERRER_POLICY and COOP defaults for SecurityMiddleware
open-source-contribution
PR author is not from Axim or 2U
#38343
opened Apr 10, 2026 by
kingoftech-v01
Loading…
3 tasks
fix(track): use hmac.compare_digest for segmentio webhook secret check
open-source-contribution
PR author is not from Axim or 2U
#38342
opened Apr 10, 2026 by
kingoftech-v01
Loading…
3 tasks
fix(notification_prefs): return opaque error for unsubscribe token failures
open-source-contribution
PR author is not from Axim or 2U
#38341
opened Apr 10, 2026 by
kingoftech-v01
Loading…
4 tasks
fix(contentstore): harden git export URL validator against option injection and SSRF
open-source-contribution
PR author is not from Axim or 2U
#38340
opened Apr 10, 2026 by
kingoftech-v01
Loading…
4 tasks
fix(password_policy): stop logging password SHA-1 hash in HIBP client
open-source-contribution
PR author is not from Axim or 2U
#38339
opened Apr 10, 2026 by
kingoftech-v01
Loading…
3 tasks
fix(verify_student): redact access keys and signatures in mismatch logs
open-source-contribution
PR author is not from Axim or 2U
#38338
opened Apr 10, 2026 by
kingoftech-v01
Loading…
fix: add SecurityMiddleware and deploy-time security checks
open-source-contribution
PR author is not from Axim or 2U
#38337
opened Apr 10, 2026 by
kingoftech-v01
Loading…
fix: escape user-controlled data in certificate templates and ACE bulk email
open-source-contribution
PR author is not from Axim or 2U
#38336
opened Apr 10, 2026 by
kingoftech-v01
Loading…
fix(sessions): authenticate session payloads with HMAC
open-source-contribution
PR author is not from Axim or 2U
#38335
opened Apr 10, 2026 by
kingoftech-v01
Loading…
fix(lti_provider): validate nonce/timestamp and outcome URL to prevent replay and SSRF
open-source-contribution
PR author is not from Axim or 2U
#38334
opened Apr 10, 2026 by
kingoftech-v01
Loading…
fix(deps): remove dead babel-plugin-transform-class-properties and bump bootstrap to 4.6.2
open-source-contribution
PR author is not from Axim or 2U
#38333
opened Apr 10, 2026 by
kingoftech-v01
Loading…
fix(api): correct IsUserInUrlOrStaff permission class to return boolean
open-source-contribution
PR author is not from Axim or 2U
#38332
opened Apr 10, 2026 by
kingoftech-v01
Loading…
fix(lms): default S3 object ACL to private in production
open-source-contribution
PR author is not from Axim or 2U
#38331
opened Apr 10, 2026 by
kingoftech-v01
Loading…
fix: use secrets module for security-sensitive random values
open-source-contribution
PR author is not from Axim or 2U
#38330
opened Apr 10, 2026 by
kingoftech-v01
Loading…
fix(lms): gate debug endpoints behind DEBUG setting
open-source-contribution
PR author is not from Axim or 2U
#38329
opened Apr 10, 2026 by
kingoftech-v01
Loading…
fix: resolve OLX pointer tags for external XBlocks at runtime level
open-source-contribution
PR author is not from Axim or 2U
#38328
opened Apr 10, 2026 by
kingoftech-v01
Loading…
fix(olx): persist subsection prerequisites across export/import
open-source-contribution
PR author is not from Axim or 2U
#38327
opened Apr 10, 2026 by
kingoftech-v01
Loading…
fix(ccx): generate CCX course outlines in LMS process
open-source-contribution
PR author is not from Axim or 2U
#38326
opened Apr 10, 2026 by
kingoftech-v01
Loading…
fix: seed ItemBankMixin.make_selection to eliminate selection race
open-source-contribution
PR author is not from Axim or 2U
#38325
opened Apr 10, 2026 by
kingoftech-v01
Loading…
fix(courseware): restore anonymous video viewing on public courses
open-source-contribution
PR author is not from Axim or 2U
#38324
opened Apr 10, 2026 by
kingoftech-v01
Loading…
fix(content_libraries): mark pasted unit children as can_stand_alone=False
open-source-contribution
PR author is not from Axim or 2U
#38323
opened Apr 10, 2026 by
kingoftech-v01
Loading…
fix(content_libraries): keep collection num_children in sync after item updates
open-source-contribution
PR author is not from Axim or 2U
#38322
opened Apr 10, 2026 by
kingoftech-v01
Loading…
Previous Next
ProTip!
Find all pull requests that aren't related to any open issues with -linked:issue.