Security

Fixing issues

Three ways to fix what the scan found. Each fix is a new version, scanned again.

Every issue in the app's security review (Open review on the app's Security card) offers one or more of these fixes. Each fix becomes a new version and is scanned again, so an issue only closes when the fix really worked.

1. Paste the fix prompt into your AI tool

Every issue comes with a fix prompt written for your AI tool. When you deploy from a chat, your AI tool already has them. Ask:

Fix the security issues Inhaus found and redeploy.

Or copy the prompt from the security review, for example:

Move the HubSpot private app token in src/api.js (line 12) into an Inhaus secret
called HUBSPOT_PRIVATE_APP_TOKEN and read it from env.HUBSPOT_PRIVATE_APP_TOKEN.
Then redeploy.

2. Move to secrets (one click, no AI)

For keys found in code, choose Move to secrets. Inhaus stores the value as a secret, rewrites the line to read it from env, and deploys a new version.

3. Ask AI to write a fix

Choose Fix with AI. Inhaus sends the affected files (secret values removed) and the issue to an AI model, which writes a code change and a short explanation. You can add a note to guide it.

Nothing is deployed until you have seen the change. The review shows the explanation and the diff. Choose Apply and deploy to deploy it as a new version, or close it.

Domains that are not allowed

For a call to a website that is not on your workspace's list, you have two choices:

  • Remove the call with one of the fixes above.
  • Keep it and ask an admin. Choose Ask admin to allow and give a reason. Admins see it next to the request. See Allowed domains.