pr-checks-comment.yml runs in the privileged workflow_run context with a
write token while consuming artifacts produced by the untrusted PR
workflow. Seven spots template-interpolated that untrusted data (and the
fork-controlled head branch name) directly into github-script source —
a crafted artifact could escape the string literal and run arbitrary JS
with the privileged token (CodeQL actions/code-injection, critical).
- All untrusted values now flow through env vars and process.env; the PR
number is parsed and validated before use
- test.yml / docker-build.yml gain workflow-level 'permissions:
contents: read' (CodeQL actions/missing-workflow-permissions); publish
jobs keep their job-level packages:write
- Add PostgreSQL + SQLite hybrid database support with automatic switching
- Implement frontend AES-GCM + RSA-OAEP encryption for sensitive data
- Add comprehensive DatabaseInterface with all required methods
- Fix compilation issues with interface consistency
- Update all database method signatures to use DatabaseInterface
- Add missing UpdateTraderInitialBalance method to PostgreSQL implementation
- Integrate RSA public key distribution via /api/config endpoint
- Add frontend crypto service with proper error handling
- Support graceful degradation between encrypted and plaintext transmission
- Add directory creation for RSA keys and PEM parsing fixes
- Test both SQLite and PostgreSQL modes successfully
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: tinkle-community <tinklefund@gmail.com>