Logo
Explore Help
Sign In
timothy/ersatztv
Watch 1
Star 0
Fork 0
Code Issues 54 Pull Requests 6 Actions Packages Projects Releases 9 Wiki Activity
Labels Milestones New Issue
0 Open 44 Closed
Label
Use alt + click/enter to exclude labels
All labels No label
ad-hoc

api

bug

ci-cd

content

dependencies

enhancement

frontend

in-progress

jellyfin

parked

priority: high

priority: low

priority: medium

review

security

Milestone
All milestones No milestones
Open milestones
Auto-Tune DetailPanel Defect-shape hardening Design system (Claude Design ↔ prod) Scheduling: refactor + distribution
Closed milestones
Blazor removal (#91 phase b) ChicoryTV go-live ChicoryTV modularization
Project
All projects No project
Author
All users
Assignee
Assigned to nobody Assigned to anybody
renovate timothy (Timothy)
Sort
Newest Oldest Most recently updated Least recently updated Most commented Least commented Nearest due date Farthest due date
0 Open 44 Closed
Label
Clear labels
ad-hoc
api
bug
ci-cd
content
dependencies
enhancement
frontend
in-progress
jellyfin
parked
priority: high
priority: low
priority: medium
review
security
Milestone
No milestone
Open milestones
Auto-Tune DetailPanel
Defect-shape hardening
Design system (Claude Design ↔ prod)
Scheduling: refactor + distribution
Closed milestones
Blazor removal (#91 phase b)
ChicoryTV go-live
ChicoryTV modularization
Projects
Clear projects
Assignee
Clear assignees
renovate
timothy
Make decision knowledge lifecycle-addressable and retrieval-efficient enhancementpriority: mediumreview
#521
by timothy was closed 2026-07-21 12:30:19 +02:00
14 / 14
3
Retire #237 from startup; run orientation and mechanical top-five selection in parallel enhancementpriority: mediumreview
#520
by timothy was closed 2026-07-21 12:29:19 +02:00
13 / 13
3
Add Cross-Origin-Resource-Policy header (ZAP #314 authenticated-scan Low) priority: lowreviewsecurity
#330
by timothy was closed 2026-07-13 21:33:15 +02:00
3 / 3
3
Set security response headers (CSP, X-Content-Type-Options, Permissions-Policy, COEP) on the host — ZAP baseline finding (#314 / #197 input) priority: mediumreviewsecurity
#319
by timothy was closed 2026-07-12 22:52:50 +02:00
4 / 4
3
Out-of-ecosystem black-box security scan against the running container (#197 exit criterion) ci-cdpriority: highreviewsecurity
#314
by timothy was closed 2026-07-13 08:42:43 +02:00
4 / 4
3
#197 MCP [HIGH]: harden the read-only MCP server (runtime verb-guard, JSON-crash DoS, injection framing) — PR #76 priority: mediumreviewsecurity
#289
by timothy was closed 2026-07-12 01:27:12 +02:00
3
#197 C3+C7 [HIGH]: DTO nullability noise + raw VMs + search pageNum before freeze apipriority: mediumreview
#288
by timothy was closed 2026-07-12 12:25:22 +02:00
3
#197 C2/C4/C5/C6 [BLOCKER/HIGH]: OpenAPI security scheme, 401/400 docs, operationIds, DayOfWeek — by construction apipriority: highreview
#287
by timothy was closed 2026-07-12 12:25:22 +02:00
3
#197 C1 [BLOCKER]: no API versioning — mount /api/v1 before the contract freezes apipriority: highreview
#286
by timothy was closed 2026-07-13 00:52:26 +02:00
8 / 8
3
#197 S7+S10 [MED]: mutating GETs, spoofable ForwardedHeaders, scanner exemption, unpaged all-items priority: mediumreviewsecurity
#285
by timothy was closed 2026-07-12 00:36:30 +02:00
2
#197 S6 [HIGH/MED]: CORS AllowAll — drive-by cross-origin reads/writes priority: highreviewsecurity
#284
by timothy was closed 2026-07-12 00:36:28 +02:00
2
#197 S4+S9 [HIGH]: stored XSS via unvalidated upload content-type reflected on serve (supersedes #66) priority: highreviewsecurity
#283
by timothy was closed 2026-07-12 01:00:55 +02:00
3
#197 S3+S5 [HIGH]: unauthenticated GETs leak private media samples, env vars, logs, settings, FS paths priority: highreviewsecurity
#282
by timothy was closed 2026-07-12 00:36:22 +02:00
2
#197 S2 [HIGH]: persistent mutation outside /api bypasses the write key even when configured (SortController) priority: highreviewsecurity
#281
by timothy was closed 2026-07-12 00:36:21 +02:00
2
#197 S1 [BLOCKER]: API writes are fail-OPEN by default — no key ⇒ every mutation unauthenticated priority: highreviewsecurity
#280
by timothy was closed 2026-07-12 00:34:46 +02:00
2
External-collections scan has no status/progress REST surface — SPA collections buttons are optimistic + timeout-bounded frontendreview
#271
by timothy was closed 2026-07-12 15:08:24 +02:00
3
If-Match parsing: return 412 (not 400) for syntactically-valid but non-matching entity-tags (RFC 7232 semantics) apipriority: mediumreview
#265
by timothy was closed 2026-07-12 23:32:26 +02:00
3 / 3
3
Replace-all reconcile: content-aware stable child identity (moved item inherits the wrong slot's state) — split from #253 apicontentpriority: mediumreview
#259
by timothy was closed 2026-07-11 22:11:28 +02:00
2
Plex library-preferences save releases the library lock before the network scan runs (Unlock ordering) bugreview
#257
by timothy was closed 2026-07-11 17:39:36 +02:00
1
Media-source sign-out/disconnect handlers leak their EntityLocker on exception (no finally) — permanent 409 bugreview
#256
by timothy was closed 2026-07-11 17:39:31 +02:00
1
First Previous 1 2 3 Next Last
Powered by Gitea Version: 1.27.1 Page: 83ms Template: 24ms
Auto
English
Bahasa Indonesia Deutsch English Español Français Gaeilge Italiano Latviešu Magyar nyelv Nederlands Polski Português de Portugal Português do Brasil Suomi Svenska Türkçe Čeština Ελληνικά Български Русский Українська فارسی മലയാളം 日本語 简体中文 繁體中文(台灣) 繁體中文(香港) 한국어
Licenses API