ProReview
How it works
Features
Tracks
Start reviewing
Challenge Library
23 challenges in Security Traps.
All
Prod Debugging
Cloud & Infra
Data Migrations
Git & CI
Security Traps
Any difficulty
Easy
Medium
Hard
Enable this staging deploy workflow?
Security Traps
medium
ci_cd
github-actions, oidc, aws, deployment
Approve this reusable deployment workflow?
Security Traps
hard
ci_cd
github-actions, workflow call, injection, deployment
Would you ship this endpoint?
Security Traps
hard
generated_application_code
python, fastapi, path traversal
Would you merge this OAuth callback change?
Security Traps
medium
generated_application_code
oauth, nextjs, redirect, session
Would you use this password module?
Security Traps
medium
generated_application_code
password-hashing, argon2, python, authentication
Add this audit logging middleware?
Security Traps
medium
generated_application_code
express, logging, audit, nodejs
Review this form session middleware
Security Traps
medium
generated_application_code
javascript, express, csrf, safe
Review this admin query handler
Security Traps
hard
generated_application_code
security, injection
Add this request logging middleware?
Security Traps
easy
generated_application_code
express, logging, secrets, nodejs
Would you ship this upload handler?
Security Traps
medium
generated_application_code
python, fastapi, upload, validation
Review this PR benchmark workflow
Security Traps
hard
ci_cd
github actions, ci cd
Review this response header middleware
Security Traps
medium
generated_application_code
javascript, express, helmet, headers
Is this auth middleware ok to deploy?
Security Traps
hard
generated_application_code
javascript, express, jwt, auth bypass
Add this authentication middleware?
Security Traps
hard
generated_application_code
typescript, jwt, auth, middleware
Would you ship this settings merger?
Security Traps
medium
generated_application_code
prototype-pollution, javascript, express, config
Add this cache storage endpoint?
Security Traps
medium
generated_application_code
python, fastapi, pickle, deserialization
Review this session cache helper
Security Traps
hard
generated_application_code
security, injection
Review this outbound webhook helper
Security Traps
hard
generated_application_code
security, injection
Is this Python file upload handler ok?
Security Traps
medium
generated_application_code
security, injection
Would you ship this webhook validator?
Security Traps
hard
generated_application_code
ssrf, axios, url-validation, webhook
Would you ship this Express middleware?
Security Traps
medium
generated_application_code
csp, helmet, express, headers
Is this Next.js middleware with security headers ok?
Security Traps
medium
generated_application_code
security, injection
Review this CLI handler loader
Security Traps
hard
generated_application_code
security, injection
That's all.