forked from OWASP/crAPI
-
Notifications
You must be signed in to change notification settings - Fork 0
Main Branch Into Develop #1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
Geoffrey-Keygraph
wants to merge
1
commit into
develop
Choose a base branch
from
main
base: develop
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
* Support disabling wait-for * Init handling workshop service * Dependency handling community service * Lint * Handle health * Bump k8s-wait-for to v2.0 for arm64 (OWASP#256) * Bump k8s-wait-for to v2.0 for arm64 * Update certs * Update README.md (OWASP#257) * Correct training * Timeout handling for gateway (OWASP#259) Timeout handling for gateway * Update pr-build.yml * Make vin numbers to be VIN regex complaint (OWASP#261) * Fix VIN * add permissions pull request write --------- Co-authored-by: Roshan Piyush <[email protected]> * Make storage provisions configurable. (OWASP#263) Persistent volume helm configuration * Escaped validation for unsigned JWTs (OWASP#265) * added check for unsigned jwt * Change to typescript from js and show service request history (OWASP#269) * Use typescript * Fix bugs * lint * Convert more to typescript * More typescript * User service req view * Update dockerfile * Implement service history * Update docker-compose.yml * Implement report view (OWASP#270) * Update pr-build.yml * Change phone number feature (OWASP#268) * Added functionality to send otp for phone number change request --------- Co-authored-by: Roshan Piyush <[email protected]> * Phone number change web service (OWASP#271) * web service verify OTP impl * minor identity service changes --------- Co-authored-by: Roshan Piyush <[email protected]> * Mechanic ux (OWASP#281) * E2E-UI * Mechanic UX fixes * Fix profile pages * Update web and identity images (OWASP#282) * Fix convention * Enhanced README to Pull and Modify Variables in the .env file (OWASP#288) * enhanced readme * enhanced setup.md * enhanced setup.md * Update LICENSE.md * Update README.md * Update setup.md * Fix health of gateway image (OWASP#289) * Fix health of gateway image * Update docker compose * Fix filename typos in README.md (OWASP#290) The current name of the docker compose file is `docker-compose.yml`. The readme command examples indicated that the name was `docker compose.yml`. This commit updates all README cases of this error to reflect the actual name of the file, making the command functional again. * Update values-pv.yaml * Chatbot impl (OWASP#295) * Implement chatbot UI * added llm chatbot service (OWASP#242) * added llm chatbot service * Llm chatbot (OWASP#243) * removed unused imports * Integration * Lint * Minor fixes * Fix ssl issue * Fix docker * Fix entrypoint * increase timeout * Implement helm * Fix entrypoint * Store user state for chatbot * resolved segmentation fault error in chatbot (OWASP#245) * Add release workflow * Instructions * Fix tag publish * Strip tag prefix * String tag prefix for docker tags * Fix entrypoint.sh * Session based chat * Fix UI * Lint * Fix configmap * Update requirements * Fix dockerfile * Fix UX * Seperate prompts * Change to ChatOpenAI * Change to ChatOpenAI * Return messages * Save chat history * Cleanup * Cleanup * Preserve X-Forwarded-For * Add mongo dependency for chatbot * Use old turbo model * FSession logs not clearer debug * Add ssn * Fix gateway service health * Chatbot typescript * Upgrade packages * Dummy commit * Lint * lint * Reduce max mem * Update chatbot * Update chatbot * Potential fix for code scanning alert no. 21: Flask app is run in debug mode Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> * Chatbot mcp impl * spotless * Fix chatbot * Spotless * Fix usage * MCP server fix (OWASP#303) * Remove errors * Remove variables not needed * Add management scripts * Make executable * Fix config * Fix config * Add init for chatbot * Add retry for apikey * Add retry for apikey * Chatbot UX fix * update tool versions * Lint fix * Upgrade golangci-lint * Npm lint fix --------- Co-authored-by: Dhruv Singhal <[email protected]> Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> Co-authored-by: keyurdoshi03 <[email protected]> * Update Chart.yaml * Update VERSION - Correct value (OWASP#305) Align VERSION file with release info. * Chatbot markdown (OWASP#308) * Bot support markdown in chat * Model selection implemented (OWASP#309) * Model selection implemented * Refactor: moved default model env variable to correct files * User context provided (OWASP#310) * Model selection implemented * Refactor: moved default model env variable to correct files * User context provided * Create challenges.md * Update challenges * Update challenges * lint * Implemented vector index and MCP tool for semantic search (OWASP#311) * Implemented vector index for chat history context and MCP tool for semantic search & summarization * Persisted storage of vectors using Chroma * JWT auth added for MCP server's api calls (OWASP#314) * JWT auth added for MCP server's api calls * Uxrevamp (OWASP#316) * Chroma fixes (OWASP#317) * Fix mcpserver * fix chatbot * Fix async calls * black * Http client fix * Fix async * Fix async * Upgrade chromadb * Fixes * Fix css of remaining components * Interaction fix * chat fix (OWASP#318) * chat fix * prettier formatting * LFI vuln (v1) (OWASP#319) * LFI vuln (v1) * Change log level for API key retrieval success * helm fixes (OWASP#320) * helm fixes * resolved comments --------- Co-authored-by: Namburi Soujanya <[email protected]> Co-authored-by: Mathew Jose Mammoottil <[email protected]> Co-authored-by: Pushkar Pawar <[email protected]> Co-authored-by: massey-n <[email protected]> Co-authored-by: Dhruv Singhal <[email protected]> Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> Co-authored-by: keyurdoshi03 <[email protected]> Co-authored-by: Rick M <[email protected]>
Keygraph Security Scan ResultsOverall Status: pass AI Security AnalysisRisk Level: HIGH
Scan Results Overview
Security Findings SummaryTotal Issues: 101 By Severity
Security scan powered by Keygraph |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Support disabling wait-for
Init handling workshop service
Dependency handling community service
Lint
Handle health
Bump k8s-wait-for to v2.0 for arm64 (Bump k8s-wait-for to v2.0 for arm64 OWASP/crAPI#256)
Bump k8s-wait-for to v2.0 for arm64
Update certs
Update README.md (Update README.md OWASP/crAPI#257)
Correct training
Timeout handling for gateway (Timeout handling for gateway OWASP/crAPI#259)
Timeout handling for gateway
Update pr-build.yml
Make vin numbers to be VIN regex complaint (Make vin numbers to be VIN regex complaint OWASP/crAPI#261)
Fix VIN
add permissions pull request write
Persistent volume helm configuration
Escaped validation for unsigned JWTs (Escaped validation for unsigned JWTs OWASP/crAPI#265)
added check for unsigned jwt
Change to typescript from js and show service request history (Change to typescript from js and show service request history OWASP/crAPI#269)
Use typescript
Fix bugs
lint
Convert more to typescript
More typescript
User service req view
Update dockerfile
Implement service history
Update docker-compose.yml
Implement report view (Implement report view OWASP/crAPI#270)
Update pr-build.yml
Change phone number feature (Change phone number feature OWASP/crAPI#268)
Added functionality to send otp for phone number change request
Phone number change web service (Phone number change web service OWASP/crAPI#271)
web service verify OTP impl
minor identity service changes
Mechanic ux (Mechanic ux OWASP/crAPI#281)
E2E-UI
Mechanic UX fixes
Fix profile pages
Update web and identity images (Update web and identity images OWASP/crAPI#282)
Fix convention
Enhanced README to Pull and Modify Variables in the .env file (Enhanced README to Pull and Modify Variables in the .env file OWASP/crAPI#288)
enhanced readme
enhanced setup.md
enhanced setup.md
Update LICENSE.md
Update README.md
Update setup.md
Fix health of gateway image (Fix health of gateway image OWASP/crAPI#289)
Fix health of gateway image
Update docker compose
Fix filename typos in README.md (Fix filename typos in README.md OWASP/crAPI#290)
The current name of the docker compose file is
docker-compose.yml. The readme command examples indicated that the name wasdocker compose.yml. This commit updates all README cases of this error to reflect the actual name of the file, making the command functional again.Update values-pv.yaml
Chatbot impl (Chatbot impl OWASP/crAPI#295)
Implement chatbot UI
added llm chatbot service (added llm chatbot service OWASP/crAPI#242)
added llm chatbot service
Llm chatbot (Llm chatbot OWASP/crAPI#243)
removed unused imports
Integration
Lint
Minor fixes
Fix ssl issue
Fix docker
Fix entrypoint
increase timeout
Implement helm
Fix entrypoint
Store user state for chatbot
resolved segmentation fault error in chatbot (resolved segmentation fault error in chatbot OWASP/crAPI#245)
Add release workflow
Instructions
Fix tag publish
Strip tag prefix
String tag prefix for docker tags
Fix entrypoint.sh
Session based chat
Fix UI
Lint
Fix configmap
Update requirements
Fix dockerfile
Fix UX
Seperate prompts
Change to ChatOpenAI
Change to ChatOpenAI
Return messages
Save chat history
Cleanup
Cleanup
Preserve X-Forwarded-For
Add mongo dependency for chatbot
Use old turbo model
FSession logs not clearer debug
Add ssn
Fix gateway service health
Chatbot typescript
Upgrade packages
Dummy commit
Lint
lint
Reduce max mem
Update chatbot
Update chatbot
Potential fix for code scanning alert no. 21: Flask app is run in debug mode
Chatbot mcp impl
spotless
Fix chatbot
Spotless
Fix usage
MCP server fix (MCP functionality enabled OWASP/crAPI#303)
Remove errors
Remove variables not needed
Add management scripts
Make executable
Fix config
Fix config
Add init for chatbot
Add retry for apikey
Add retry for apikey
Chatbot UX fix
update tool versions
Lint fix
Upgrade golangci-lint
Npm lint fix
Update Chart.yaml
Update VERSION - Correct value (Update VERSION - Correct value OWASP/crAPI#305)
Align VERSION file with release info.
Chatbot markdown (Chatbot markdown OWASP/crAPI#308)
Bot support markdown in chat
Model selection implemented (Model selection implemented OWASP/crAPI#309)
Model selection implemented
Refactor: moved default model env variable to correct files
User context provided (User context provided OWASP/crAPI#310)
Model selection implemented
Refactor: moved default model env variable to correct files
User context provided
Create challenges.md
Update challenges
Update challenges
lint
Implemented vector index and MCP tool for semantic search (Implemented vector index and MCP tool for semantic search OWASP/crAPI#311)
Implemented vector index for chat history context and MCP tool for semantic search & summarization
Persisted storage of vectors using Chroma
JWT auth added for MCP server's api calls (JWT auth added for MCP server's api calls OWASP/crAPI#314)
JWT auth added for MCP server's api calls
Uxrevamp (Uxrevamp OWASP/crAPI#316)
Chroma fixes (Chroma fixes OWASP/crAPI#317)
Fix mcpserver
fix chatbot
Fix async calls
black
Http client fix
Fix async
Fix async
Upgrade chromadb
Fixes
Fix css of remaining components
Interaction fix
chat fix (chat fix OWASP/crAPI#318)
chat fix
prettier formatting
LFI vuln (v1) (LFI vuln (v1) OWASP/crAPI#319)
LFI vuln (v1)
Change log level for API key retrieval success
helm fixes (helm fixes OWASP/crAPI#320)
helm fixes
resolved comments
Description
Please include a summary of the change, motivation and context.
Testing
Please describe the tests that you ran to verify your changes. Please summarize what did you test and what needs to be tested e.g. deployed and tested the service locally.
Documentation
Make sure that you have documented corresponding changes in this repository.
Checklist: