Skip to content

feat(dashboard): complete governed semantic evidence paths - #614

Merged
seonghobae merged 42 commits into
mainfrom
feat/dashboard-live-evidence
Aug 25, 2026
Merged

seonghobae merged 42 commits into
mainfrom
feat/dashboard-live-evidence

docs: fix temporal topic compute contracts (#617)

3e3b3ee
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / Semgrep OSS succeeded Aug 25, 2026 in 6s

2 new alerts

New alerts in code changed by this pull request

  • 2 warnings

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 1844 in backend/app/main.py

See this annotation in the file changed.

Code scanning / Semgrep OSS

Semgrep Finding: python.lang.security.audit.sqli.asyncpg-sqli.asyncpg-sqli Warning

Detected string concatenation with a non-literal variable in a asyncpg Python SQL statement. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can create parameterized queries like so: 'conn.fetch("SELECT """Fa FROM table", value)'. You can also create prepared statements with 'Connection.prepare': 'stmt = conn.prepare("SELECT """Fa FROM table"); await stmt.fetch(user_value)'

Check warning on line 1844 in backend/app/main.py

See this annotation in the file changed.

Code scanning / Semgrep OSS

Semgrep Finding: python.lang.security.audit.sqli.asyncpg-sqli.asyncpg-sqli Warning

Detected string concatenation with a non-literal variable in a asyncpg Python SQL statement. This could lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements instead. You can create parameterized queries like so: 'conn.fetch("SELECT $1 FROM table", value)'. You can also create prepared statements with 'Connection.prepare': 'stmt = conn.prepare("SELECT $1 FROM table"); await stmt.fetch(user_value)'