Diff-aware security scanner for GitHub PRs — flags mutable Express/NestJS/Next.js routes with no auth middleware and responses leaking sensitive fields. Deterministic, AST-based, human-in-the-loop.
-
Updated
Aug 11, 2026 - Go
Diff-aware security scanner for GitHub PRs — flags mutable Express/NestJS/Next.js routes with no auth middleware and responses leaking sensitive fields. Deterministic, AST-based, human-in-the-loop.
Coordinated disclosure portfolio: information-exposure (CWE-200) advisories for open-source web apps
Add a description, image, and links to the cwe-200 topic page so that developers can more easily learn about it.
To associate your repository with the cwe-200 topic, visit your repo's landing page and select "manage topics."