active 2026-07-26 → 2026-08-15 (UTC)
Activity over time
Daily event counts in the loaded window
Line chart, 21 days from 2026-07-26 to 2026-08-15. Pushes: 22 total, peak 5 in a day. Pull requests: 2 total, peak 2 in a day. Issues: 14 total, peak 13 in a day. Comments: 3 total, peak 3 in a day. Stars: 0 total, peak 0 in a day.
- Pushes
- Pull requests
- Issues
- Comments
- Stars
Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.
Top contributors
Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity
| Contributor | Contributions | Pushes | PRs | Comments |
|---|---|---|---|---|
| Xore | 39 | 22 | 2 | 1 |
| github-advanced-security[bot] | 3 | 0 | 0 | 2 |
Recent activity
Latest issues, pull requests and releases
- Issue#104Xore2026-08-09 03:54Theme parity: replace the split demo with the historical centered login experience
- Issue#40Xore2026-08-07 19:17WebAuthn user verification is never required, even in passwordless (passkey-only) mode
- Pull request#56Xore2026-08-07 18:46
- Issue comment#45Xore2026-08-07 18:35COOKIE_SECRET rotation silently resets the audit chain instead of failing safely
- Pull request#54Xore2026-08-07 18:34
- Issue#50Xore2026-08-07 18:18REDIS_URL receives no scheme, auth, or TLS validation, unlike every other network-destination setting
- Issue#50Xore2026-08-07 18:18REDIS_URL receives no scheme, auth, or TLS validation, unlike every other network-destination setting
- Issue#50Xore2026-08-07 18:18REDIS_URL receives no scheme, auth, or TLS validation, unlike every other network-destination setting
- Issue#49Xore2026-08-07 18:18COOKIE_SECRET is documented as required but silently falls back to an ephemeral, restart-losing secret
- Issue#47Xore2026-08-07 18:18/static/ serves the raw, un-rendered login/verify/app page templates with no frame-ancestors, X-Frame-Options, or CSP at all
- Issue#47Xore2026-08-07 18:18/static/ serves the raw, un-rendered login/verify/app page templates with no frame-ancestors, X-Frame-Options, or CSP at all
- Issue#47Xore2026-08-07 18:18/static/ serves the raw, un-rendered login/verify/app page templates with no frame-ancestors, X-Frame-Options, or CSP at all
- Issue#45Xore2026-08-07 18:18COOKIE_SECRET rotation silently resets the audit chain instead of failing safely
- Issue#44Xore2026-08-07 18:18Server startup never verifies the full audit chain — verifyAuditLines is dead code outside tests
- Issue#38Xore2026-08-07 18:17PASSWORDLESS=true on a fresh install can permanently lock out every administrator
- Issue#36Xore2026-08-07 18:17Form/CSRF token ("ft") is not bound to the session that presents it, so it provides no real CSRF protection for authenticated mutating endpoints
- Issue#34Xore2026-08-07 18:17Recovery-token fingerprint ignores session generation, so "logout"/"reset 2fa"/"reset passkeys" do not revoke outstanding password-reset links as documented
Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 0 stars here means stars gained during the window, not the repo's star count.