Live good-first-issue & help-wanted feed

Find meaningful ways to contribute

Browse open GitHub issues that maintainers labeled for help. Filter by language, stars, category, and difficulty — then pick something you can finish.

Projects
110,262
Open issues
752,442
Cost
Free
Illustration of a Good first issue card with GitHub, plus Learn new skills, Work on real projects, Make an impact, and Open source is for everyone

Active projects

Unique repos with open help-wanted issues updated in the last 30 days

Showing 30 of ~20,351 matching filters (10+ stars)

List

Add support for bitbucket

AI summary

This issue requests the implementation of a new Git provider for Bitbucket. It specifically mentions building upon the new structural changes introduced in a recent pull request, indicating a need to integrate with an existing framework.

good first issueSize: Steam:library-maintainers
731
Difficulty
3/5

Add setting to prevent burrito from destroying resources

AI summary

This issue proposes adding a new configuration setting to the Burrito tool. This setting would prevent Burrito from executing 'apply' operations if the 'plan' output indicates that any resources are scheduled for destruction. The goal is to enhance safety and facilitate adoption on critical Terraform code by preventing accidental resource deletion.

good first issueSize: Steam:library-maintainers
731
Difficulty
2/5

[Security] JAX-RS REST hasPrivilege sweep — residual: ConsentService (3 endpoints), AppService.getApps, ReportByTemplateService review; the other 15 listed services are now guarded

AI summary

A significant security vulnerability exists in the JAX-RS REST services where most endpoints lack proper privilege checks. This allows any authenticated user, regardless of their role, to access or modify sensitive data and functionality. The `securityInfoManager.hasPrivilege()` method is not being called, which is a critical security requirement.

help wantedtype: securitytype: bugReview effort [1-5]: 2priority: high
25
Difficulty
4/5

[docs] Document synchronous timeout limitation in Python

AI summary

This issue requests an update to the Python documentation for SmoothAPI to explicitly state that the `timeout_ms` configuration is only supported for asynchronous requests. The documentation should clarify what happens when `timeout_ms` is used with synchronous requests and suggest using the underlying request library's timeout functionality as an alternative for synchronous users.

docsgood first issuepythonbeginnerfix-failed
10
Difficulty
1/5

🐝 Hive Advisory Report

AI summary

This issue serves as a central hub for advisory findings from Hive agents, particularly at lower ACMM levels where agents analyze code without creating direct issues or PRs. A governor agent periodically posts digest comments summarizing these advisory findings. This issue is intended to be a living document and should not be closed.

help wantedagent/scannerhive/advisoryagent/securityhive/hosted-kubestellar-console-4vkt
119
Difficulty
2/5

Add calendars that aren't tied to a mail account (CalDAV, ICS subscriptions)

AI summary

This issue requests the ability to add calendars in Penguin Mail that are not directly linked to a mail account. This includes supporting CalDAV (e.g., Nextcloud, Radicale, iCloud) and ICS/webcal subscriptions, allowing users to view and manage external calendars alongside their existing account-based ones. The goal is to consolidate all calendar information within Penguin Mail and enable features like free-time search across all calendars.

enhancementgood first issue
150
Difficulty
4/5

[good first issue, hacktoberfest] 🏮 Add new Dialect Entry 441 (good-first-issue)

AI summary

This issue is a beginner-friendly task to add a new regional Japanese dialect entry to a JSON file. It requires no coding and can be completed directly in the browser by forking the repository, editing the specified JSON file, and submitting a pull request. The entry to be added is for the Kansai dialect word 'あかん'.

help wantedgood first issuehacktoberfestcommunitylow hanging fruitup-for-grabs
1.9K
Difficulty
1/5
mozilla/neqo

QUIC Stream Resets with Partial Delivery

AI summary

This issue proposes implementing a new draft specification for QUIC stream resets that handles partial delivery. The goal is to ensure reliable stream resets even when data has not been fully acknowledged.

help wantedgood first issue
2.2K
Difficulty
3/5
mopidy/mopidy

Provide way to get errors to MPD/WS users

AI summary

This issue addresses the lack of a mechanism to inform users about errors in the system. The goal is to implement a way for users, specifically those interacting with MPD/WS, to be notified when something goes wrong.

A-coreA-ext-httpgood first issue
8.5K
Difficulty
2/5
rtk-ai/rtk

Feature request: add `tea` subcommand for Gitea CLI

AI summary

This issue requests the addition of a new `tea` subcommand to the `rtk` CLI tool. The goal is to provide token-optimized output for the Gitea CLI (`tea`), similar to how the existing `gh` subcommand optimizes GitHub CLI output. This would significantly reduce token consumption for users who manage both GitHub and Gitea repositories.

enhancementhelp wantedpriority:lowarea:cli
67.6K
Difficulty
3/5

Move ESP32 out of the ARM Cortex-M family list

AI summary

This issue requests the correction of a README file that incorrectly categorizes ESP32 microcontrollers as part of the ARM Cortex-M family. The ESP32 actually uses Xtensa or RISC-V cores and needs to be listed under its own architecture. The fix involves updating the README files and ensuring no other part of the repository mislabels the ESP32.

good first issuemenuup-next
49
Difficulty
1/5

Auto downsampling should take available resolution into account

AI summary

This issue describes a problem with Thanos's auto-downsampling feature, where it incorrectly attempts to query data at a finer resolution (5m) than what is available (1h) after a certain retention period. This leads to missing historical data in Grafana graphs, particularly during backfilling operations, and requires manual intervention to select the correct resolution. The proposal is to make auto-downsampling aware of the available data resolutions.

help wantedcomponent: compactcomponent: query-frontenddont-go-stale
14.1K
Difficulty
3/5

[Security] CSRF via GET — AddRxComment.jsp and completeMedRec.jsp perform DB mutations without CSRF protection (companion to #2449)

AI summary

Two JSP files, AddRxComment.jsp and completeMedRec.jsp, are vulnerable to Cross-Site Request Forgery (CSRF) attacks because they perform database mutations via GET requests without proper CSRF protection. This allows an attacker to trick an authenticated user into unknowingly executing these sensitive actions.

help wantedtype: securityReview effort [1-5]: 2priority: high
25
Difficulty
3/5
Expensify/App

[CFI] [$250] Spend - Add a Paid column option to the reports table

AI summary

This issue proposes adding a 'Paid' column to the reports table on the Spend page. Currently, users must open individual reports to find payment dates, which is inconvenient. The new column would display the payment timestamp directly in the table, similar to existing 'Submitted' and 'Approved' date columns.

ExternalDailyHelp Wanted
4.9K
Difficulty
2/5

🐛 Move upgraded banner into dashboard alert stack

AI summary

This issue proposes moving the 'upgraded banner' on the dashboard to a shared alert stack at the top of the page. The goal is to consolidate notices and warnings while maintaining the existing functionality of the upgraded banner, such as dismissal and 'What changed' behavior.

help wanteddashboard
51
Difficulty
2/5

chore(linting): fix linting failures for C and C++

AI summary

This issue addresses failing C++ linting checks in the repository, which prevent the `pnpm run lint:cpp` command from passing. The goal is to fix the identified lint failures in specific C and C++ files, ensuring the linting process completes successfully without errors.

good first issuetakenhelp wantedc/cppdifficulty: easy
39
Difficulty
2/5

🐛 Advisory digest subsection formatting differs from siblings

AI summary

The 'ADVISORY DIGEST' subsection in the spoke dashboard has inconsistent formatting compared to its sibling sections. This includes issues with its header placement, missing interactive elements, and misaligned empty-state text. The goal is to make it visually and functionally consistent with other subsections like 'HIVE ADVICE'.

help wanteddashboard
51
Difficulty
2/5

test(utils): add unit tests for non_recoverable_utils

AI summary

This issue requests the addition of unit tests for the `non_recoverable_utils.py` module. These tests are crucial to ensure that the logic for identifying and handling permanently skipped documents in incremental runs is correct and doesn't introduce regressions. The tests should cover the `is_non_recoverable_error`, `extract_non_recoverable_rows`, and `process_non_recoverable_errors` functions, with specific behaviors outlined for each.

good first issuehacktoberfest
10
Difficulty
2/5

WordPress Education Dashboard: Institutions module - bugs and feature requests

AI summary

This GitHub issue serves as a central hub for reporting bugs and suggesting features for the "Institutions module" within the WordPress Education Dashboard plugin. It outlines the module's current functionalities, such as managing student rosters, collaboration agreements, and semester reports for partner institutions. The issue also provides links to relevant code, design documents, and handbook pages for context.

help wantedWebsiteWP Credits
12
Difficulty
3/5

net/http: TLS handshake timeout using OpenBao CLI

AI summary

The OpenBao CLI is experiencing TLS handshake timeouts when connecting to a TLS-enabled OpenBao server. This appears to be caused by the CLI taking too long to search the system's CA certificate pool. The issue proposes exposing a variable that skips system CA certs as an environment variable to potentially resolve this.

bughelp wantedwindows
6.6K
Difficulty
3/5

Option to *not* remote-load google font and fontawesome

AI summary

The user requests an option to disable remote loading of Google Fonts and Font Awesome in the mkdocs-simple-blog theme. This would allow users to host these assets locally or avoid external dependencies for reasons like improved performance, data privacy, and control over delivered content.

enhancementgood first issuefeature-requestWIP
128
Difficulty
2/5

Custom artifact types: keep the webhook's difference type and paths in compatibility violations

AI summary

This issue aims to enhance the compatibility violation reporting for custom artifact types by including the `diffType`, `pathOriginal`, and `pathUpdated` fields from webhook responses. Currently, only `description` and `context` are retained, leading to a loss of detailed information about compatibility differences. The work involves mapping these fields to `code` and location pointers, respectively, with a test to verify the correct data flow.

area/rules/compatibilityarea/rulesarea/sdkarea/performance/cachinggood first issuearea/artifact-types
830
Difficulty
3/5

fix(rest): JSON deserialization errors on ccompat endpoints return v3 ProblemDetails instead of the Confluent error shape

AI summary

This issue addresses a bug where JSON deserialization errors on ccompat endpoints are returning a v3 ProblemDetails format instead of the expected Confluent error shape. The current implementation leaks server exception details and doesn't correctly route errors based on the API surface. The fix involves ensuring errors are mapped according to the requested API surface, specifically for ccompat and v2 endpoints.

type/bugBeginner Friendlyarea/restarea/rest/ccompatarea/sdkgood first issue
830
Difficulty
2/5

[feat] Support HTTP-Date and Unix Epoch `RateLimit-Reset` headers for 429 backoff

AI summary

This issue proposes adding support for more sophisticated `RateLimit-Reset` headers in the `smooth-api` libraries. Currently, only simple integer seconds are handled for `429 Too Many Requests` responses. The enhancement aims to parse HTTP-Date formats and Unix epoch timestamps from headers like `Retry-After`, `RateLimit-Reset`, and `X-RateLimit-Reset` to accurately calculate backoff delays.

enhancementhelp wantedpythontypescriptpackagesWIP
10
Difficulty
3/5

New QueryBuilder method: none()

AI summary

This issue proposes adding a `none()` method to the QueryBuilder. This method would return a builder that guarantees no database query and an empty result set, similar to Django's `none()` functionality. The primary use case is to simplify conditional query building, allowing developers to easily short-circuit query execution when no results are desired.

enhancementhelp wanted
7.3K
Difficulty
2/5
neomjs/neo

config order: add an exception for `layout` to always be in front of `items`

AI summary

This issue proposes adding a new rule to the coding guidelines to ensure the `layout` configuration always precedes `items`. This change requires updating the documentation and then applying the new rule across potentially over 100 view-related files in the repository.

enhancementhelp wantedgood first issue
3.2K
Difficulty
3/5

🐛 bug: Overlapping and duplicate issues/PRs

AI summary

This issue reports a recurring problem with the Hive `sec-check` agent automatically creating duplicate or near-duplicate security issues related to SVG vulnerabilities. The agent's reliance on regex to detect bypasses of SVG security gates leads to numerous individual issues for each new escaping or structural variation, rather than a consolidated report. This results in a high volume of similar, narrowly defined bug reports that are difficult to manage.

bughelp wantedtriage/acceptedhive/likely-doneneeds-reporter-confirmation
51
Difficulty
4/5

[1.8.0] Release TODOs and cross-repository integration checklist

AI summary

This issue outlines the comprehensive checklist for the HugeGraph 1.8.0 release, focusing on functionality, compatibility, documentation, and cross-repository integration. It details specific tasks for HugeGraph Server, Toolchain, AI, website, and documentation, including Kubernetes/Helm support, various deployment configurations, and authentication mechanisms.

help wantedapache
3.1K
Difficulty
4/5

How it works

Three steps from browsing to opening a PR.

Read the beginner guide →
  1. 1

    Filter the feed

    Pick a language, minimum stars, category, and difficulty that match what you can ship.

  2. 2

    Read the AI summary

    Each card includes a short summary and difficulty score when we have one — so you can skip the wall of text.

  3. 3

    Open the issue

    Jump to GitHub, talk to the maintainer if needed, and contribute where help is actually wanted.

Not finding what you’re looking for?

Browse 110,262 projects or reset filters to see more of the 752,442 indexed issues.