6bdd76b4f013eba4fe1fcc058157822e9d3f3dd2
- Auth (#2/#3): UUID PK, 256-bit keys, SHA-256 lookup + bcrypt hash - SSRF (#1): validate URLs, block private IPs, cloud metadata endpoints - CORS (#4): lock to pingql.com origins, not wildcard - SSE limit (#6): 10 connections per monitor max - ReDoS (#7): cap $regex patterns at 200 chars - Monitor limit (#8): 100 per account default - Cookie env config (#9): secure/domain from env vars - Bearer parsing (#10): case-insensitive RFC 6750 - Pings retention (#11): 90-day pruner, hourly interval - monitors.enabled index (#12): partial index for /internal/due - Runner locking (#14): locked_until for horizontal scale safety - COALESCE nullable bug (#17): dynamic PATCH with explicit undefined checks - MONITOR_TOKEN null guard (#18): startup validation + middleware hardening - reset-key cookie fix (#16): sets new cookie in response
PingQL
Developer-friendly uptime monitoring. Works like a query — filter status, parse content, write custom checks.
Apps
- apps/web — API, dashboard, and job coordinator (Bun + Elysia)
- apps/monitor — Check runner (Rust + Tokio)
- cli — CLI tool (Bun)
Quick start
bun install
bun run dev # starts web app
Docs
Coming soon at pingql.com
Languages
EJS
46.6%
TypeScript
40.1%
Rust
5.1%
JavaScript
4.3%
CSS
2.3%
Other
1.6%