This issue serves as a central hub for advisory findings from Hive agents, particularly at lower ACMM levels where agents analyze code without creating direct issues or PRs. A governor agent periodically posts digest comments summarizing these advisory findings. This issue is intended to be a living document and should not be closed.
help wantedagent/scannerhive/advisoryagent/securityhive/hosted-kubestellar-console-4vkt
This issue requests the creation of a blog post for Java developers on how to safely extract archives, specifically addressing Zip Slip vulnerabilities and decompression bombs. The post should include runnable examples, be published on dev.to, and promoted on relevant platforms like r/java and Show HN. It's considered done when live and linked from the repository's README.
This issue proposes the creation of a new "Partner Registration Page" and its associated POST API. The goal is to implement the backend functionality for registering partners through a new page, likely involving data validation and persistence.
This issue proposes the implementation of a GET API for the WCC Partner Page. The goal is to retrieve information related to WCC partners, likely for display on a web page. The 'good first issue' label suggests it's a suitable task for new contributors.
This issue proposes an update to the Gradle version used in the project. The goal is to upgrade Gradle to a newer version, likely to leverage new features, performance improvements, or security patches. Specific requirements, edge cases, and expected behavior are not detailed, but the intent is a straightforward version bump.
enhancementgood first issuedeploymentjava/springboot
This issue proposes upgrading the Spring Boot version of the project. The description is currently a placeholder and lacks specific details about the problem it solves, requirements, or edge cases. Further information is needed to understand the impact and scope of this upgrade.
enhancementgood first issuedeploymentjava/springbootto-be-refined
This issue is a beginner-friendly task to add a new Japanese example sentence to a JSON file. It requires no coding and can be completed in under a minute by forking the repository, editing the JSON file directly in the browser, and submitting a pull request. This is an excellent opportunity for new contributors to make their first open-source contribution and is tagged for Hacktoberfest.
help wantedgood first issuehacktoberfestcommunitylow hanging fruitup-for-grabs
The bundled embedding model in SurfSense is currently using FP16 weights instead of the specified int8 weights as outlined in ADR 0007. This discrepancy leads to larger file sizes and slower embedding performance, impacting the accuracy of documentation and potentially the efficiency of the retrieval proposal.
This issue addresses a large, unmergeable pull request that attempted to fix numerous comments. The proposed solution is to break down the changes from that PR into smaller, more manageable chunks, merging them one crate at a time to facilitate review and approval.
This issue proposes adding new functions to detect bridges and articulation points in undirected graphs. The implementation will leverage a single Depth First Search (DFS) with discovery times and low-link values, similar to Tarjan's algorithm for strongly connected components. The goal is to integrate these new functionalities into the existing `connectivity` module without altering any current code.
The in-app updater is incorrectly enabled for applications installed via Homebrew Cask and WinGet. This leads to conflicts as the in-app updater can overwrite or interfere with updates managed by these package managers. The fix involves updating the installation source detection logic to recognize these package managers.
The `--debug` command-line flag is intended to enable debug logging, but it currently only opens DevTools and re-enables the context menu. The log level is hard-coded to 'Info' and does not respond to the `--debug` flag or the `RUST_LOG` environment variable, preventing users from accessing debug logs for troubleshooting.
The Visual Explain AI analysis incorrectly defaults to English even when the application language is set to 'Auto' and the UI is displayed in another language. The fix involves modifying the `getAiExplanationLanguage` function to correctly use the resolved UI language when 'Auto' is selected, falling back to English only if the resolved language is unsupported.
The PostgreSQL driver in the application incorrectly handles overloaded functions. When multiple functions share the same name but have different argument types, the 'View Definition' and 'Edit' features select an arbitrary overload instead of the specific one clicked. This leads to displaying or editing the wrong function definition.
This bug report describes an issue where specific plugin UI slots (`data-grid.toolbar.actions` and `sidebar.footer.actions`) are receiving an empty context object instead of the expected data like `connectionId`, `tableName`, and `driver`. This prevents UI extensions that rely on the `driver` property for filtering from rendering correctly, particularly in the common `data-grid.toolbar.actions` slot.
The `create-plugin --with-ui` command generates a UI extension bundle but fails to add the necessary `ui_extensions` entry to the plugin's manifest file. This prevents the host application from loading the UI extension, as it relies on this entry to discover and load UI modules. The fix involves updating the manifest template to include the `ui_extensions` placeholder when the `--with-ui` flag is used.
Plugins generated with `create-plugin` using the `rust-driver` template incorrectly report unimplemented methods. The error message bypasses the host's fallback mechanism, causing errors to be displayed to the user instead of the host attempting to handle optional methods. This impacts various features like batch queries and materialized views.
This bug report details three issues with the trigger editor's guided mode. Firstly, it generates invalid SQL for MySQL and SQLite when multiple events are selected. Secondly, trigger edits are not atomic, leading to data loss if the new definition fails. Finally, only the first event is parsed when loading existing triggers, causing data loss on re-saving.
The "New routine" button is missing in the UI for PostgreSQL schemas and MySQL multi-database connections, preventing users from creating new procedures or functions in these contexts. The issue points to specific UI components and suggests a pattern to follow from existing Views and Triggers functionality.
The "Run..." dialog for stored routines incorrectly executes the generated SQL immediately instead of opening it for review as promised. This bypasses the intended safety step, especially for routines that modify data. The fix involves changing a `preventAutoRun` flag from `false` to `true` in the `ExplorerSidebar.tsx` component.
Kubernetes port-forward tunnels in Tabularis are not properly managed. They are never stopped, leading to orphaned `kubectl port-forward` processes. Additionally, existing tunnels are reused without checking if the underlying `kubectl` process is still alive, causing connection failures after pod restarts or network issues until the application is restarted.
The one-click installation for Claude Desktop on Windows incorrectly writes its configuration file to a subfolder within the Roaming AppData directory. This prevents Claude Desktop from detecting the Tabularis server, as it expects the configuration file in the root of the Roaming AppData directory. The fix involves adjusting the path resolution in the Rust code to match the expected location.
The Visual Explain feature incorrectly enables 'Analyze' by default for data-modifying SQL statements like REPLACE, MERGE, and data-modifying CTEs. This is because the detection logic only checks the first keyword and doesn't account for comments or more complex statement structures, leading to unintended data modification when fetching query plans.
The user is encountering an installation error ('error curl 23, failure, cant open file /root/stream.py, errono 2') when trying to run `modmium.sh` on versions 152 and 150. While `quickinstall` appears to work, the system boots to OOBE without VT2 access after a restart, and recovery keys are also affected.
Several user-configurable settings, including column masking, sticky headers, and row editor behavior, are not persisting across application restarts. This is because these settings are not being correctly deserialized and saved into the application's configuration file (`config.json`) by the backend Rust code, causing them to revert to defaults upon relaunch.
This issue proposes adding a new data-source connector for Nuclino to the cognee-community project. The connector should support API key authentication, ingest items, collections, and content, and implement incremental sync and deletion handling. It's intended as a beginner-friendly task for a hackathon.
This issue proposes adding a new data-source connector for Freshdesk to the cognee-community project. The connector will ingest tickets, conversations, and solution articles using API key authentication and support incremental syncing and deletion handling. It's intended to be a beginner-friendly task as part of a hackathon.
This issue proposes adding a new data-source connector for Rollbar to the cognee-community project. The connector will ingest error items, occurrences, and resolution states, supporting incremental sync and deletion handling. The implementation should follow the pattern of existing connectors, particularly the Notion connector, and is considered beginner-friendly due to its simple access token authentication.
This issue requires updating user-facing text in the webhooks settings and execution detail views. The term 'Recipe' needs to be replaced with the canonical term 'Playbook' in specific UI elements and descriptions. The underlying data check for 'recipe' should remain unchanged as it's an API value.
This issue requests adding `aria-label` attributes to the Send and Stop buttons in the chat composer. Currently, these icon-only buttons are announced as just "button" by screen readers, hindering accessibility. The fix involves adding descriptive `aria-label`s and ensuring appropriate testing.