Add Deel integration with API key support - #108
Conversation
Co-Authored-By: mariano@trycomp.ai <mariano@trycomp.ai>
|
The latest updates on your projects. Learn more about Vercel for Git ↗︎ |
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
…w perms) (#3419) * fix(security): resolve open CodeQL alerts (XSS, sanitization, workflow perms) - #108 (high, js/xss-through-dom): preview.tsx assigned user-typed input to iframe.src / anchor href, allowing javascript:/data: URIs to execute in the preview context. Gate every URL sink through an http(s)-only validator. - #95 (high, js/incomplete-sanitization): generate-task-types.ts escaped single quotes but not backslashes when embedding task fields in single-quoted TS string literals. Add a helper that escapes backslash-first and apply it to id/name/department/frequency. - #80/#81/#84/#85 (medium, actions/missing-workflow-permissions): the two Trigger.dev deploy + two DB-migration workflows had no permissions block. Add top-level 'permissions: contents: read' (they only check out to build/ deploy/migrate — no repo writes). Verified: app typecheck clean for preview.tsx; codegen script typechecks; all 4 workflow YAMLs valid. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(ui): keep currentUrl state in sync when loading a new preview URL loadNewUrl navigated the iframe imperatively (iframeRef.current.src) without updating currentUrl, so the external-link href, refresh, and try-again all referred to the stale previous URL. Drive navigation through setCurrentUrl instead (the iframe src prop follows currentUrl/safeUrl), keeping every URL consumer in sync with what's shown — and avoiding a double-load from setting both iframe.src and the src prop. Same-URL entries still go through refreshIframe's cache-bust. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
# [3.102.0](v3.101.2...v3.102.0) (2026-07-15) ### Bug Fixes * **ci:** pin Syft 1.46.0 in SBOM action (1.42.3 can't parse bun.lock) ([#3415](#3415)) ([5f47024](5f47024)) * **ci:** scan bun.lock via file: input so the SBOM isn't empty ([#3414](#3414)) ([e47e6fd](e47e6fd)) * **deps:** override uuid to ^11.1.1 (Dependabot [#85](#85)) ([#3418](#3418)) ([598ff8c](598ff8c)) * **deps:** patch tmp and js-yaml in mcp-server (Dependabot [#58](https://github.com/trycompai/comp/issues/58)/[#59](https://github.com/trycompai/comp/issues/59)/[#71](https://github.com/trycompai/comp/issues/71)) ([#3412](#3412)) ([59a6b0f](59a6b0f)) * **deps:** remediate dependency security vulnerabilities ([#3403](#3403)) ([7577a37](7577a37)) * **deps:** remediate dependency security vulnerabilities (165→16, 4 critical→0) ([#3406](#3406)) ([d403e9c](d403e9c)) * **device-agent:** implement the installer-cleanup fix ([#3381](#3381)) ([0f7581b](0f7581b)) * **security:** prevent SSRF in task-automation enterprise API calls ([#3411](#3411)) ([dcec288](dcec288)), closes [#116](#116) * **security:** resolve open CodeQL alerts (XSS, sanitization, workflow perms) ([#3419](#3419)) ([32329be](32329be)), closes [#108](#108) [js/xss-throu#dom](https://github.com/js/xss-throu/issues/dom) [#95](#95) [84/#85](#85) ### Features * **framework-editor:** raise requirement description limit to 100,000 chars (FRAME-2) ([67c9f4a](67c9f4a))
Added a new integration for Deel under packages/integrations/src that supports connecting via API key, and included a PNG logo for it. The integration follows the same patterns as existing integrations like GitHub and Gusto.
Link to Devin run: https://app.devin.ai/sessions/987fdcbcbfc943938fa05ac6343a4d2c
Requested by: mariano@trycomp.ai