Open Issues Need Help
View All on GitHub [sec-check] copilot-dco.yml: missing top-level permissions block (over-permissive GITHUB_TOKEN) 3 days ago
help wanted security
[ci-maintainer] PR Verifier reusable workflow (kubestellar/infra@main) fails on non-dependabot PRs — blocks all PR merges about 1 month ago
help wanted ci
[sec-check] Track: Scorecard Token-Permissions cluster — 5 write-scoped GITHUB_TOKEN alerts across 4 workflows about 1 month ago
help wanted security
[ci-maintainer] Fuzzing workflow fails: ruby/setup-ruby v1.99.0 doesn't know Ruby 3.2 about 1 month ago
help wanted ci
[sec-check] 6 Scorecard Token-Permissions + 2 Pinned-Dependencies alerts — supply-chain hardening about 1 month ago
help wanted security
[ci-maintainer] PR Verifier failing on all Dependabot pull_request_target runs (startup_failure, 0 jobs) about 1 month ago
help wanted ci
[sec-check] Code-Review score failing — insufficient changeset review coverage (Scorecard #8) about 1 month ago
help wanted security
[sec-check] Branch-Protection score failing — main branch has no required reviews or status checks (Scorecard #1) about 1 month ago
help wanted security
help wanted security
[sec-check] Fuzzing not enabled — Scorecard score 0/10 (no fuzzer integrations found) about 1 month ago
help wanted security
[sec-check] BranchProtection score low — main branch requires PRs, status checks, and admin enforcement about 1 month ago
help wanted security
[sec-check] Code review not enforced — only 1 of 29 recent changesets approved (Scorecard) about 1 month ago
help wanted security
[sec-check] homebrew-tap: top-level write permissions in ai-fix.yml and copilot-automation.yml (TokenPermissions CWE-732) about 1 month ago
help wanted security
[sec-check] pull_request_target greetings.yml missing fork-repo guard about 1 month ago
help wanted security
[sec-check] homebrew-tap: copilot-dco.yml.disabled lacks permissions block and uses @main ref about 1 month ago
help wanted security
[sec-check] homebrew-tap: copilot-dco.yml sets statuses:write at top-level permissions about 1 month ago
help wanted security
[sec-check] homebrew-tap: ai-fix.yml and copilot-automation.yml grant contents:write on pull_request_target without fork guard about 1 month ago
help wanted security
[ci-maintainer] PR Verifier rejects scanner/agent PR titles — [actor] prefix not valid conventional commits about 1 month ago
help wanted ci
[sec-check] homebrew-tap: no mandatory code review — formula changes can be merged without approval about 1 month ago
help wanted security
[sec-check] homebrew-tap: default branch lacks branch protection — formula tampering possible about 1 month ago
help wanted security
[sec-check] homebrew-tap: 5 additional workflows call mutable reusable workflows @main (pull_request_target + schedule) about 1 month ago
help wanted security
[sec-check] homebrew-tap: scorecard.yml passes secrets:inherit to mutable @main reusable workflow with id-token:write about 1 month ago
help wanted security
[sec-check] copilot-dco.yml missing permissions block — GITHUB_TOKEN inherits repo-wide defaults about 1 month ago
help wanted security
[sec-check] pull_request_target workflows (greetings.yml, pr-verifier.yml) call mutable reusable workflows @main about 1 month ago
help wanted security
[sec-check] pull_request_target ai-fix.yml calls mutable reusable workflow @main — pwn-request risk about 1 month ago
help wanted security
[ci-maintainer] PR Verifier workflow startup failure — broken reusable workflow reference about 1 month ago
help wanted ci
[sec-check] TokenPermissions: 4 workflows lack top-level read-all permissions (Scorecard HIGH) about 1 month ago
help wanted security
[sec-check] reusable workflow refs unpinned @main in 6 workflows (supply-chain risk) about 2 months ago
help wanted security
[sec-check] disabled workflow files retain pre-fix pwn-request patterns — delete or update about 2 months ago
help wanted security
[sec-check] copilot-dco.yml: no top-level permissions + @main reusable ref about 2 months ago
help wanted security
help wanted security
[sec-check] Token-Permissions: ai-fix.yml and copilot-automation.yml use top-level write permissions with pull_request_target about 2 months ago
help wanted security
[sec-check] copilot-automation.yml + ai-fix.yml: pull_request_target with top-level write permissions, no fork guards about 2 months ago
help wanted security
[sec-check] pr-verifier.yml calls non-existent reusable-pr-verifier.yml — PR title check is broken about 2 months ago
help wanted security
[sec-check] No branch protection on default branch about 2 months ago
help wanted security
[sec-check] Scorecard Code-Review score 0/10 — unreviewed commits merged about 2 months ago
help wanted security
[sec-check] No branch protection on default branch (Scorecard BranchProtectionID high) about 2 months ago
help wanted security
[sec-check] Code-Review score 0 — 0/27 recent changesets had an approved review (Scorecard high) about 2 months ago
help wanted security
[sec-check] Token-Permissions: 6 Scorecard alerts for over-permissive GITHUB_TOKEN in workflows about 2 months ago
help wanted security
[sec-check] homebrew-tap: assignment-helper.yml uses unpinned @main reusable workflow (supply-chain risk) about 2 months ago
help wanted security
[sec-check] Token-Permissions: 6 Scorecard alerts across 5 workflows (Scorecard high) about 2 months ago
help wanted security
[sec-check] Token-Permissions: 6 job-level write scopes in 5 workflows (Scorecard high) about 2 months ago
help wanted security
[sec-check] over-permissive GITHUB_TOKEN in 6 workflows including missing top-level permissions in copilot-dco.yml about 2 months ago
help wanted security
[sec-check] pr-verifier.yml: PRT + secrets: inherit exposes all repo secrets (2nd filing — fix not applied) about 2 months ago
help wanted security
[sec-check] ai-fix.yml: PRT with 3 write permissions and no fork guard (2nd filing — fix not applied) about 2 months ago
help wanted security
[sec-check] copilot-automation.yml: PRT with 4 write permissions and no fork guard (2nd filing — fix not applied) about 2 months ago
help wanted security
[sec-check] greetings.yml: PRT + secrets: inherit exposes all repo secrets (2nd filing — fix not applied) about 2 months ago
help wanted security
[ci-maintainer] Homebrew CI: kubestellar-deploy formula fails brew audit --strict on every nightly update (#{bin} → bin/) about 2 months ago
help wanted ci
[ci-maintainer] PR Verifier startup_failure: unpinned @main reusable workflow broken about 2 months ago
help wanted ci
help wanted ci
help wanted ci
help wanted security
[sec-check] Dependabot security updates disabled 2 months ago
help wanted security
enhancement help wanted kind/test
[sec-check] HIGH: Code-Review score 1/10 — only 3 of 30 recent changesets reviewed (Scorecard #8) 2 months ago
help wanted security
help wanted security
help wanted security
bug help wanted
[guide] homebrew-tap missing CODE_OF_CONDUCT.md 2 months ago
documentation help wanted
[guide] homebrew-tap missing LICENSE file — README references Apache 2.0 but no file present 2 months ago
documentation help wanted
[guide] Add SECURITY.md for vulnerability reporting 2 months ago
documentation help wanted
help wanted security
help wanted security
[sec-check] LOW: Code-Review not enforced + no Dependency-Update-Tool configured (Scorecard HIGH) 2 months ago
help wanted security
help wanted security
[sec-check] Over-permissive GITHUB_TOKEN in 12 workflows — token-permissions hardening needed 2 months ago
help wanted security
help wanted kind/bug
[guide] README formula-status table links to closed issues — kubectl-claude and kubestellar-console entries are stale 2 months ago
documentation help wanted
bug help wanted security agent/reviewer hive/hive-v1
bug help wanted
[guide] README kubectl-claude section has no actionable installation path or link to upstream source 3 months ago
documentation help wanted
[guide] CONTRIBUTING.md does not mention that Formula files are auto-generated by GoReleaser 3 months ago
documentation help wanted
[guide] README misleadingly documents kubectl-claude as a Homebrew formula despite noting it is not yet available 3 months ago
documentation help wanted
[ci-maintainer] brew audit --strict fails on kc-agent.rb: description length and bin interpolation 3 months ago
bug help wanted kind/failing-test
documentation help wanted
[sec-check] Supply chain risk: unpinned @main reusable workflow refs with pull_request_target + secrets:inherit 3 months ago
help wanted security