Open Issues Need Help
View All on GitHub [sec-check] 11 workflows call kubestellar/infra reusable workflows at unpinned @main (4 on pull_request_target) about 12 hours ago
help wanted security hive/hosted-kubestellar-console-4vkt agent/security
[quality] Add 5 unit tests for i18n/request.ts (0% → 100% line coverage) about 16 hours ago
help wanted quality testing agent/quality hive/hosted-kubestellar-console-4vkt
help wanted quality testing agent/quality hive/hosted-kubestellar-console-4vkt
help wanted security
[sec-check] copilot-dco.yml: missing top-level permissions block (over-permissive GITHUB_TOKEN) 10 days ago
help wanted security
help wanted ci-failure
bug documentation good first issue help wanted
[sec-check] Scorecard Vulnerability: brace-expansion GHSA-mh99-v99m-4gvg (uncatchable OOM DoS) 26 days ago
help wanted security
help wanted security
[sec-check] Next.js 16.2.10 vulnerable to 9 CVEs published 2026-07-22 (SSRF, DoS, auth bypass, cache confusion) — bump to 16.2.11 about 1 month ago
help wanted security
[sec-check] 3 osv-scanner vulnerabilities in docs deps (sharp/libvips high, DOMPurify, linkify-it DoS) about 1 month ago
help wanted security
[sec-check] brace-expansion DoS (CVE-2026-13149 / GHSA-3jxr-9vmj-r5cp) in package-lock.json about 1 month ago
help wanted security
[ci-maintainer] Maintainer Metrics Tracker: Postmark API returning 401 (invalid Server token) on all maintainers about 1 month ago
help wanted ci
[sec-check] Stale Dependabot alert #2: tj-actions/changed-files (CVE-2025-30066) — workflow already removed about 1 month ago
help wanted security
[ci-maintainer] Scheduled Link Checker and Typo Checker workflows failing on main (2+ consecutive days) about 1 month ago
help wanted ci
[sec-check] Token-Permissions regressions: 7 open Scorecard alerts across workflows about 1 month ago
help wanted security
[sec-check] Track: Scorecard Token-Permissions cluster — 12 write-scoped GITHUB_TOKEN alerts across 10 workflows about 1 month ago
help wanted security
Broken link: https://github.com/kubestellar/console/watchers... about 1 month ago
bug documentation good first issue help wanted
Broken link: https://kubestellar.io/docs/kubestellar/release-notes... about 1 month ago
bug documentation good first issue help wanted
[ci-maintainer] Maintainer Metrics Tracker workflow failing: awf v0.7.0 download 404 about 1 month ago
help wanted ci
[sec-check] click 8.1.2 pinned in cluster-objects/requirements.txt is vulnerable to PYSEC-2026-2132 — bump to >= 8.3.3 about 1 month ago
help wanted security
[sec-check] 13 Scorecard Token-Permissions alerts — workflows missing top-level `permissions:` block (supply-chain hardening) about 1 month ago
help wanted security
[sec-check] Missing permissions block in .github/workflows/copilot-dco.yml (CodeQL #93) about 1 month ago
help wanted security
[ci-maintainer] CodeQL Analysis failing on every push: advanced workflow conflicts with default CodeQL setup (recurrence) about 1 month ago
help wanted ci
[sec-check] SAST not running on all commits — Scorecard alert #71 persists (re-filed, prior #6271 closed) about 1 month ago
help wanted security
[sec-check] Code-Review score failing — Scorecard alert #69 persists (re-filed, prior #6273 closed) about 1 month ago
help wanted security
[sec-check] Code-Review score failing — insufficient changeset review coverage (Scorecard #69) about 1 month ago
help wanted security
[sec-check] Branch-Protection score failing — main branch has no required reviews or status checks (Scorecard #76) about 1 month ago
help wanted security
help wanted security
[sec-check] Fuzzing not enabled — Scorecard score 0/10 (no fuzzer integrations found) about 1 month ago
help wanted security
[leaderboard-gen-failure] Leaderboard generation workflow failing about 1 month ago
help wanted ci-failure
[sec-check] CodeQL static analysis disabled — code scanning gap on docs repo about 2 months ago
help wanted security
[sec-check] Over-permissive RBAC for nextra-rollout-sa in cluster-objects/rbac.yaml about 2 months ago
help wanted security
[sec-check] pull_request_target fork-check gap in ai-fix.yml and copilot-automation.yml about 2 months ago
help wanted security
[sec-check] ai-fix.yml and copilot-automation.yml lack fork guard on pull_request_target (write-capable) about 2 months ago
help wanted security
[sec-check] ci: docs/ai-fix.yml and copilot-automation.yml use pull_request_target with write permissions and no fork guard about 2 months ago
help wanted security
[sec-check] ci: transitive mutable-tag third-party actions inside SHA-pinned kubestellar/infra reusable workflows about 2 months ago
help wanted security
[sec-check] ci: copilot-dco.yml.disabled retains unsafe defaults — no permissions block, uses @main ref about 2 months ago
help wanted security
[ci-maintainer] PR Verifier rejects scanner-generated PRs — [scanner] prefix fails Conventional Commits check about 2 months ago
help wanted ci
[sec-check] docs: pr-verifier.yml uses third-party action not pinned by hash (Scorecard alert #224) about 2 months ago
help wanted security
[sec-check] docs: new write-scoped automation workflows expose broad token permissions about 2 months ago
help wanted security
[sec-check] docs: no fuzzing tool configured — MDX sanitizer and search API routes not fuzz-tested about 2 months ago
help wanted security
[sec-check] docs: 4 new workflows with job-level write token permissions flagged by Scorecard about 2 months ago
help wanted security
[ci-maintainer] Fuzz MDX Sanitizer CI check failing on scanner/fix-6215 (fuzz harness exits non-zero) about 2 months ago
help wanted ci
[sec-check] docs: no SAST tool configured — Next.js API routes not analyzed for injection vulnerabilities about 2 months ago
help wanted security
[sec-check] docs: no mandatory code review — PRs can be merged without human approval about 2 months ago
help wanted security
[sec-check] docs: default branch lacks branch protection — force-push and bypass possible about 2 months ago
help wanted security
[sec-check] docs: scorecard.yml passes secrets:inherit to mutable @main reusable workflow with id-token:write about 2 months ago
help wanted security
[sec-check] docs: 5 additional workflows call mutable reusable workflows @main (pull_request_target + schedule) about 2 months ago
help wanted security
[sec-check] pull_request_target workflows (greetings.yml, pr-verifier.yml) call mutable reusable workflows @main about 2 months ago
help wanted security
[sec-check] pull_request_target ai-fix.yml calls mutable reusable workflow @main — pwn-request risk about 2 months ago
help wanted security
[sec-check] docs: copilot-dco.yml has no permissions block — token inherits repo-wide defaults about 2 months ago
help wanted security
[sec-check] docs: missing Content-Security-Policy header about 2 months ago
help wanted security
[ci-maintainer] PR Verifier workflow startup failure on all PRs — missing reusable workflow about 2 months ago
help wanted ci
help wanted ci
help wanted kind/documentation
[ci-maintainer] Run All Maintainer Audits: recurring bash syntax error — missing opening quote causes workflow failure every Monday about 2 months ago
help wanted ci
[sec-check] Weak supply-chain posture: no branch protection and no code review required on main (Scorecard alerts #76, #69) about 2 months ago
help wanted security
[sec-check] TokenPermissions: multiple workflows lack top-level read-all permissions (Scorecard HIGH) about 2 months ago
help wanted security
[ci-maintainer] Greetings workflow startup_failure on all runs — broken reusable workflow reference about 2 months ago
help wanted ci
[sec-check] TokenPermissions: pr-verifier.yml lacks top-level read-all permissions (Scorecard HIGH) about 2 months ago
help wanted security
[sec-check] OpenSSF CII Best Practices badge absent — Scorecard CIIBestPracticesID alert in 5 repos about 2 months ago
help wanted security
[sec-check] workflow_run trigger with write permissions in technical-doc-writer.lock.yml — privilege escalation risk about 2 months ago
help wanted security
[sec-check] 14 open Scorecard security alerts — TokenPermissions (11) + BranchProtection (2) + CodeReview (1) about 2 months ago
help wanted security
[ci-maintainer] Sync Console Release Versions fails daily — no stable releases found about 2 months ago
help wanted ci
[sec-check] reusable workflow refs unpinned @main in 6 workflows (supply-chain risk) about 2 months ago
help wanted security
[sec-check] disabled workflow files retain pre-fix pwn-request patterns — delete or update about 2 months ago
help wanted security
[sec-check] copilot-dco.yml: no top-level permissions + @main reusable ref about 2 months ago
help wanted security
help wanted security
[sec-check] Token-Permissions: ai-fix.yml and copilot-automation.yml use top-level write permissions with pull_request_target about 2 months ago
help wanted security
[sec-check] copilot-automation.yml + ai-fix.yml: pull_request_target with top-level write permissions, no fork guards about 2 months ago
help wanted security
[sec-check] pr-verifier.yml calls non-existent reusable-pr-verifier.yml — PR title check disabled about 2 months ago
help wanted security
[sec-check] greetings.yml pull_request_target missing fork guard — pwn-request risk about 2 months ago
help wanted security
Broken link: https://kubestellar.io/usage_guide... about 2 months ago
bug documentation good first issue help wanted
Broken link: https://kubestellar.io/architecture_guide... about 2 months ago
bug documentation good first issue help wanted
Broken link: https://kubestellar.io/installation_guide... about 2 months ago
bug documentation good first issue help wanted
Broken link: https://kubestellar.io/development_guide... about 2 months ago
bug documentation good first issue help wanted
[sec-check] Scorecard Code-Review score 0/10 — unreviewed commits merged about 2 months ago
help wanted security
[sec-check] No branch protection on default branch about 2 months ago
help wanted security
[sec-check] No branch protection on default branch (Scorecard BranchProtectionID high) about 2 months ago
help wanted security
Broken link: https://kubestellar.io/architecture_guide... about 2 months ago
bug documentation good first issue help wanted
Broken link: https://kubestellar.io/usage_guide... about 2 months ago
bug documentation good first issue help wanted
Broken link: https://kubestellar.io/development_guide... about 2 months ago
bug documentation good first issue help wanted
Broken link: https://kubestellar.io/installation_guide... about 2 months ago
bug documentation good first issue help wanted
[sec-check] Token-Permissions: 11 Scorecard alerts for over-permissive GITHUB_TOKEN in workflows about 2 months ago
help wanted security
[quality] Test coverage critically low — only 1 of 35 source dirs tested about 2 months ago
help wanted quality testing
[sec-check] Token-Permissions: 7 additional Scorecard alerts in 5 workflows not covered by #6099 about 2 months ago
help wanted security
[sec-check] Code-Review score 0 — 0/26 recent changesets had an approved review (Scorecard high) about 2 months ago
help wanted security
[sec-check] Token-Permissions: 9 workflow files with job-level write scopes (Scorecard high) about 2 months ago
help wanted security
[sec-check] Scorecard VulnerabilitiesID: open/unfixed known vulnerabilities in dependency tree (high) about 2 months ago
help wanted security
[sec-check] run-all-maintainer-audits.yml: actions:write can dispatch any workflow + 10 TokenPermissions alerts (hardening) about 2 months ago
help wanted security
[quality] src/config/versions.ts has 11 routing-critical functions with zero test coverage about 2 months ago
help wanted quality testing
[sec-check] Rollout-checker CronJobs mount OCI config at /root/.oci — containers likely running as root about 2 months ago
help wanted security
[sec-check] Missing securityContext in deployment.yaml and pr-job.yaml preview template (regression from #5877) about 2 months ago
help wanted security
[sec-check] Path traversal in readLocalFile — missing containment checks (CWE-22) about 2 months ago
help wanted security
[sec-check] over-permissive GITHUB_TOKEN in 11 workflows (ai-fix, copilot-automation, run-all-maintainer-audits, scorecard, pr-verifier) about 2 months ago
help wanted security
bug documentation good first issue help wanted
bug documentation good first issue help wanted
bug documentation good first issue help wanted