This issue requests the implementation of a new Git provider for Bitbucket. It specifically mentions building upon the new structural changes introduced in a recent pull request, indicating a need to integrate with an existing framework.
This issue proposes adding a new configuration setting to the Burrito tool. This setting would prevent Burrito from executing 'apply' operations if the 'plan' output indicates that any resources are scheduled for destruction. The goal is to enhance safety and facilitate adoption on critical Terraform code by preventing accidental resource deletion.
A significant security vulnerability exists in the JAX-RS REST services where most endpoints lack proper privilege checks. This allows any authenticated user, regardless of their role, to access or modify sensitive data and functionality. The `securityInfoManager.hasPrivilege()` method is not being called, which is a critical security requirement.
help wantedtype: securitytype: bugReview effort [1-5]: 2priority: high
This issue requests an update to the Python documentation for SmoothAPI to explicitly state that the `timeout_ms` configuration is only supported for asynchronous requests. The documentation should clarify what happens when `timeout_ms` is used with synchronous requests and suggest using the underlying request library's timeout functionality as an alternative for synchronous users.
The user is experiencing an issue where their phone prompts to select Android Auto, but the tablet running the headunit app does not respond. The phone connects to the Wi-Fi Direct network, but the connection process repeats indefinitely, preventing Android Auto from launching.
This issue serves as a central hub for advisory findings from Hive agents, particularly at lower ACMM levels where agents analyze code without creating direct issues or PRs. A governor agent periodically posts digest comments summarizing these advisory findings. This issue is intended to be a living document and should not be closed.
help wantedagent/scannerhive/advisoryagent/securityhive/hosted-kubestellar-console-4vkt
This issue requests the ability to add calendars in Penguin Mail that are not directly linked to a mail account. This includes supporting CalDAV (e.g., Nextcloud, Radicale, iCloud) and ICS/webcal subscriptions, allowing users to view and manage external calendars alongside their existing account-based ones. The goal is to consolidate all calendar information within Penguin Mail and enable features like free-time search across all calendars.
This issue is a beginner-friendly task to add a new regional Japanese dialect entry to a JSON file. It requires no coding and can be completed directly in the browser by forking the repository, editing the specified JSON file, and submitting a pull request. The entry to be added is for the Kansai dialect word 'あかん'.
help wantedgood first issuehacktoberfestcommunitylow hanging fruitup-for-grabs
This issue proposes implementing a new draft specification for QUIC stream resets that handles partial delivery. The goal is to ensure reliable stream resets even when data has not been fully acknowledged.
This issue addresses the lack of a mechanism to inform users about errors in the system. The goal is to implement a way for users, specifically those interacting with MPD/WS, to be notified when something goes wrong.
This issue requests the addition of a new `tea` subcommand to the `rtk` CLI tool. The goal is to provide token-optimized output for the Gitea CLI (`tea`), similar to how the existing `gh` subcommand optimizes GitHub CLI output. This would significantly reduce token consumption for users who manage both GitHub and Gitea repositories.
This issue requests the correction of a README file that incorrectly categorizes ESP32 microcontrollers as part of the ARM Cortex-M family. The ESP32 actually uses Xtensa or RISC-V cores and needs to be listed under its own architecture. The fix involves updating the README files and ensuring no other part of the repository mislabels the ESP32.
This issue describes a problem with Thanos's auto-downsampling feature, where it incorrectly attempts to query data at a finer resolution (5m) than what is available (1h) after a certain retention period. This leads to missing historical data in Grafana graphs, particularly during backfilling operations, and requires manual intervention to select the correct resolution. The proposal is to make auto-downsampling aware of the available data resolutions.
help wantedcomponent: compactcomponent: query-frontenddont-go-stale
Two JSP files, AddRxComment.jsp and completeMedRec.jsp, are vulnerable to Cross-Site Request Forgery (CSRF) attacks because they perform database mutations via GET requests without proper CSRF protection. This allows an attacker to trick an authenticated user into unknowingly executing these sensitive actions.
help wantedtype: securityReview effort [1-5]: 2priority: high
This issue proposes adding a 'Paid' column to the reports table on the Spend page. Currently, users must open individual reports to find payment dates, which is inconvenient. The new column would display the payment timestamp directly in the table, similar to existing 'Submitted' and 'Approved' date columns.
This issue proposes moving the 'upgraded banner' on the dashboard to a shared alert stack at the top of the page. The goal is to consolidate notices and warnings while maintaining the existing functionality of the upgraded banner, such as dismissal and 'What changed' behavior.
The README file for sample flows is outdated and does not accurately reflect the existing flow files. This issue requires updating the README to include missing flows, remove references to non-existent files, and ensure all listed flows are present and correctly categorized.
This issue addresses failing C++ linting checks in the repository, which prevent the `pnpm run lint:cpp` command from passing. The goal is to fix the identified lint failures in specific C and C++ files, ensuring the linting process completes successfully without errors.
good first issuetakenhelp wantedc/cppdifficulty: easy
The 'ADVISORY DIGEST' subsection in the spoke dashboard has inconsistent formatting compared to its sibling sections. This includes issues with its header placement, missing interactive elements, and misaligned empty-state text. The goal is to make it visually and functionally consistent with other subsections like 'HIVE ADVICE'.
This issue requests the addition of unit tests for the `non_recoverable_utils.py` module. These tests are crucial to ensure that the logic for identifying and handling permanently skipped documents in incremental runs is correct and doesn't introduce regressions. The tests should cover the `is_non_recoverable_error`, `extract_non_recoverable_rows`, and `process_non_recoverable_errors` functions, with specific behaviors outlined for each.
This GitHub issue serves as a central hub for reporting bugs and suggesting features for the "Institutions module" within the WordPress Education Dashboard plugin. It outlines the module's current functionalities, such as managing student rosters, collaboration agreements, and semester reports for partner institutions. The issue also provides links to relevant code, design documents, and handbook pages for context.
The OpenBao CLI is experiencing TLS handshake timeouts when connecting to a TLS-enabled OpenBao server. This appears to be caused by the CLI taking too long to search the system's CA certificate pool. The issue proposes exposing a variable that skips system CA certs as an environment variable to potentially resolve this.
The user requests an option to disable remote loading of Google Fonts and Font Awesome in the mkdocs-simple-blog theme. This would allow users to host these assets locally or avoid external dependencies for reasons like improved performance, data privacy, and control over delivered content.
This issue aims to enhance the compatibility violation reporting for custom artifact types by including the `diffType`, `pathOriginal`, and `pathUpdated` fields from webhook responses. Currently, only `description` and `context` are retained, leading to a loss of detailed information about compatibility differences. The work involves mapping these fields to `code` and location pointers, respectively, with a test to verify the correct data flow.
area/rules/compatibilityarea/rulesarea/sdkarea/performance/cachinggood first issuearea/artifact-types
This issue addresses a bug where JSON deserialization errors on ccompat endpoints are returning a v3 ProblemDetails format instead of the expected Confluent error shape. The current implementation leaks server exception details and doesn't correctly route errors based on the API surface. The fix involves ensuring errors are mapped according to the requested API surface, specifically for ccompat and v2 endpoints.
type/bugBeginner Friendlyarea/restarea/rest/ccompatarea/sdkgood first issue
This issue proposes adding support for more sophisticated `RateLimit-Reset` headers in the `smooth-api` libraries. Currently, only simple integer seconds are handled for `429 Too Many Requests` responses. The enhancement aims to parse HTTP-Date formats and Unix epoch timestamps from headers like `Retry-After`, `RateLimit-Reset`, and `X-RateLimit-Reset` to accurately calculate backoff delays.
This issue proposes adding a `none()` method to the QueryBuilder. This method would return a builder that guarantees no database query and an empty result set, similar to Django's `none()` functionality. The primary use case is to simplify conditional query building, allowing developers to easily short-circuit query execution when no results are desired.
This issue proposes adding a new rule to the coding guidelines to ensure the `layout` configuration always precedes `items`. This change requires updating the documentation and then applying the new rule across potentially over 100 view-related files in the repository.
This issue reports a recurring problem with the Hive `sec-check` agent automatically creating duplicate or near-duplicate security issues related to SVG vulnerabilities. The agent's reliance on regex to detect bypasses of SVG security gates leads to numerous individual issues for each new escaping or structural variation, rather than a consolidated report. This results in a high volume of similar, narrowly defined bug reports that are difficult to manage.
This issue outlines the comprehensive checklist for the HugeGraph 1.8.0 release, focusing on functionality, compatibility, documentation, and cross-repository integration. It details specific tasks for HugeGraph Server, Toolchain, AI, website, and documentation, including Kubernetes/Helm support, various deployment configurations, and authentication mechanisms.