Open Issues Need Help
View All on GitHub [sec-check] copilot-dco.yml: missing top-level permissions block (over-permissive GITHUB_TOKEN) about 1 hour ago
help wanted security
[ci-maintainer] PR Verifier workflow: 100% failure — reusable target missing in kubestellar/infra 8 days ago
help wanted ci
help wanted security
help wanted quality testing
help wanted ci
help wanted quality testing
help wanted quality testing
[sec-check] Track: Scorecard `Token-Permissions` alerts — workflows use write-scoped GITHUB_TOKEN at top-level about 1 month ago
help wanted security
[sec-check] Script injection in pr-verifier.yml — `${{ github.event.pull_request.title }}` in `pull_request_target` run block about 1 month ago
help wanted security
[ci-maintainer] PR Verifier failing on all Dependabot pull_request_target runs (startup_failure, 0 jobs) about 1 month ago
help wanted ci
[sec-check] 6 Scorecard Token-Permissions alerts — workflows missing top-level `permissions:` block (supply-chain hardening) about 1 month ago
help wanted security
[sec-check] SAST not running on all commits — Scorecard alert #14 persists (re-filed, prior #496 closed) about 1 month ago
help wanted security
[sec-check] Code-Review score failing — Scorecard alert #11 persists (re-filed, prior #497 closed) about 1 month ago
help wanted security
[sec-check] Branch-Protection score failing — main branch has no required reviews or status checks (Scorecard #1) about 1 month ago
help wanted security
[sec-check] Code-Review score failing — insufficient changeset review coverage (Scorecard #11) about 1 month ago
help wanted security
help wanted security
[ci-maintainer] Generate Platform Install Missions: workflow failure on master (run 29019147911) about 1 month ago
help wanted ci
[sec-check] GO-2026-5856: Go 1.26.0 crypto/tls ECH PSK identity leak in kubestellar-mcp about 1 month ago
help wanted security
help wanted ci
[sec-check] kubestellar-mcp: top-level write permissions in ai-fix.yml and copilot-automation.yml (TokenPermissions CWE-732) about 1 month ago
help wanted security
[sec-check] copilot-automation.yml lacks fork guard on pull_request_target (write-capable) about 1 month ago
help wanted security
[sec-check] kubestellar-mcp: copilot-dco.yml sets statuses:write at top-level permissions about 1 month ago
help wanted security
[sec-check] kubestellar-mcp: copilot-automation.yml grants contents/issues/pull-requests/statuses write at workflow scope on pull_request_target about 1 month ago
help wanted security
[sec-check] kubestellar-mcp: no fuzzing tool configured — external input parsing not tested for adversarial inputs about 1 month ago
help wanted security
[ci-maintainer] PR Verifier rejects scanner/agent PR titles — [actor] prefix not valid conventional commits about 1 month ago
help wanted ci
[sec-check] kubestellar-mcp: no mandatory code review — PRs can be merged without human approval about 1 month ago
help wanted security
[sec-check] kubestellar-mcp: default branch lacks branch protection — force-push and bypass possible about 1 month ago
help wanted security
[sec-check] kubestellar-mcp: 5 additional workflows call mutable reusable workflows @main (pull_request_target + schedule) about 1 month ago
help wanted security
[sec-check] kubestellar-mcp: scorecard.yml passes secrets:inherit to mutable @main reusable workflow with id-token:write about 1 month ago
help wanted security
[ci-maintainer] PR Verifier workflow failing — missing reusable-pr-verifier.yml in kubestellar/infra about 1 month ago
help wanted ci
[sec-check] copilot-dco.yml missing permissions block — GITHUB_TOKEN inherits repo-wide defaults about 1 month ago
help wanted security
[sec-check] pull_request_target workflows (greetings.yml, pr-verifier.yml) call mutable reusable workflows @main about 1 month ago
help wanted security
[sec-check] pull_request_target ai-fix.yml calls mutable reusable workflow @main — pwn-request risk about 1 month ago
help wanted security
[ci-maintainer] PR Verifier workflow fails at startup on all PR branches about 1 month ago
help wanted ci
[ci-maintainer] Build and Test: lint job fails — golangci-lint v1 not supported by golangci-lint-action >= v7 about 1 month ago
help wanted ci
[sec-check] Partial branch protection and insufficient code review — MCP server supply-chain risk about 1 month ago
help wanted security
[sec-check] TokenPermissions: 4 workflows lack top-level read-all permissions (Scorecard HIGH) about 1 month ago
help wanted security
[sec-check] TokenPermissions: pr-verifier.yml lacks top-level read-all permissions (Scorecard HIGH) about 1 month ago
help wanted security
[ci-maintainer] CodeQL Analysis fails: go.mod needs tidy before build about 2 months ago
help wanted ci
[ci-maintainer] lint: gofmt violations in quality-agent test files block CI about 2 months ago
help wanted ci
[ci-maintainer] build-test.yml: 200+ consecutive failures on main — 0 jobs, pre-job failure pattern about 2 months ago
help wanted ci
[sec-check] reusable workflow refs unpinned @main in 7 workflows (supply-chain risk) about 2 months ago
help wanted security
[ci-maintainer] build-test.yml still failing after #413 — invalid golangci-lint-action SHA about 2 months ago
help wanted ci
[sec-check] golang.org/x/net v0.55.0 is behind latest — potential missed security patches about 2 months ago
help wanted security
[sec-check] kubestellar-mcp: branch protection score 3/10 — PRs not required, no status checks, 93% commits unreviewed about 2 months ago
help wanted security
[sec-check] disabled workflow files retain pre-fix pwn-request patterns — delete or update about 2 months ago
help wanted security
[sec-check] copilot-dco.yml: no top-level permissions + @main reusable ref about 2 months ago
help wanted security
help wanted security
[ci-maintainer] build-test.yml failing on every push/PR — 30+ consecutive failures, zero jobs recorded about 2 months ago
help wanted ci
[sec-check] Token-Permissions: ai-fix.yml and copilot-automation.yml use top-level write permissions with pull_request_target about 2 months ago
help wanted security
[sec-check] copilot-automation.yml + ai-fix.yml: pull_request_target with top-level write permissions, no fork guards about 2 months ago
help wanted security
[sec-check] pr-verifier.yml calls non-existent reusable-pr-verifier.yml — PR title check disabled about 2 months ago
help wanted security
[sec-check] greetings.yml pull_request_target missing fork guard — pwn-request risk about 2 months ago
help wanted security
[sec-check] publish-mcp-registry.yml downloads mcp-publisher binary without checksum verification — supply chain risk about 2 months ago
help wanted security
[sec-check] namespace_validator_test.go has stale assertions incompatible with new allowlist regex — CI tests likely failing about 2 months ago
help wanted security
[sec-check] tools_kustomize.go skips namespace validation — TODO(#377) still unresolved about 2 months ago
help wanted security
[sec-check] ValidateNamespace uses blocklist instead of allowlist — prompt injection bypass possible about 2 months ago
help wanted security
[sec-check] kubestellar-mcp tools_app.go: unvalidated app/namespace/pod inputs passed directly to Kubernetes API about 2 months ago
help wanted security
[sec-check] No branch protection on default branch (Scorecard BranchProtectionID high) about 2 months ago
help wanted security needs-admin
[sec-check] No branch protection on default branch about 2 months ago
help wanted security
[sec-check] Scorecard Code-Review score 0/10 — unreviewed commits merged about 2 months ago
help wanted security
[sec-check] Token-Permissions: 5 Scorecard alerts for over-permissive GITHUB_TOKEN in workflows about 2 months ago
help wanted security
[quality] Add server.json schema validation to CI about 2 months ago
help wanted quality testing
[sec-check] kubestellar-mcp CLI: cluster names injected unsanitized into AI prompts (prompt injection) about 2 months ago
help wanted security
[sec-check] Code-Review score 0 — 0/21 recent changesets had an approved review (Scorecard high) about 2 months ago
help wanted security
[sec-check] Token-Permissions: copilot-automation.yml job-level write scopes (Scorecard high) about 2 months ago
help wanted security
[sec-check] Token-Permissions: ai-fix.yml job-level write scopes (Scorecard high) about 2 months ago
help wanted security
[quality] MCP tool registry files lack unit tests (RBAC, policy, upgrades) about 2 months ago
help wanted quality testing
[quality] pkg/deploy/mcp/server.go MCP protocol layer needs expanded test coverage about 2 months ago
help wanted quality testing
[quality] MCP Registry publish workflow lacks post-publish validation and binary verification about 2 months ago
help wanted quality testing
[sec-check] Unpinned @main reusable workflow refs from kubestellar/infra (supply-chain risk) about 2 months ago
help wanted security
[sec-check] over-permissive GITHUB_TOKEN in 5 workflows (ai-fix, copilot-automation, scorecard, pr-verifier) about 2 months ago
help wanted security
[sec-check] kubestellar-mcp: over-permissive GITHUB_TOKEN in ai-fix.yml and copilot-automation.yml — top-level write permissions (Scorecard Token-Permissions) about 2 months ago
help wanted security
[sec-check] kubestellar-mcp: handleHelmList missing validateHelmIdentifier for namespace — inconsistent CLI argument validation about 2 months ago
help wanted security
[sec-check] Missing permissions block in copilot-dco.yml (not propagated from console fix) about 2 months ago
help wanted security
[sec-check] pr-verifier.yml: pull_request_target + secrets: inherit exposes all repo secrets (2nd filing — fix not applied) about 2 months ago
help wanted security
[sec-check] greetings.yml: pull_request_target + secrets: inherit exposes all repo secrets (3rd filing — fix not applied) about 2 months ago
help wanted security
[sec-check] copilot-automation.yml: pull_request_target with 4 write permissions and no fork guard (re-filed) about 2 months ago
help wanted security
[sec-check] ai-fix.yml: pull_request_target with write permissions and no fork guard about 2 months ago
help wanted security
[sec-check] 11 workflows use kubestellar/infra reusable workflows at @main (mutable ref) about 2 months ago
help wanted security
[sec-check] copilot-automation.yml: pull_request_target with write permissions and no fork guard about 2 months ago
help wanted security
[ci-maintainer] PR Verifier startup_failure: unpinned @main reusable workflow broken about 2 months ago
help wanted ci
[sec-check] user-supplied cluster names in Clusters[] passed as --kube-context without validateHelmIdentifier 2 months ago
help wanted security
[sec-check] helm --set values not sanitized — comma in value injects extra key=value pairs 2 months ago
help wanted security
[sec-check] MEDIUM: GitOps repo URL lacks DNS-rebinding SSRF guard — git clone can reach private/cloud-metadata IPs 2 months ago
help wanted security
help wanted security
help wanted security
help wanted quality testing
help wanted quality testing
help wanted quality testing
help wanted quality testing
[quality] pkg/mcp/server/upgrades.go has critically low test coverage (10% test:source ratio) 2 months ago
help wanted quality testing
[quality] tools_kubectl.go handlers (handleDeleteResource, handleKubectlApply) lack unit tests 2 months ago
help wanted quality testing
help wanted security
[sec-check] MEDIUM: No SAST/CodeQL configured — static analysis not run on commits (Scorecard #14 score 0/10) 2 months ago
help wanted security
[sec-check] HIGH: Branch protection not configured on main branch (Scorecard score 3/10) 2 months ago
help wanted security
[sec-check] HIGH: Code-Review score 4/10 — only 10 of 24 recent changesets reviewed (Scorecard #11) 2 months ago
help wanted security
help wanted security
help wanted quality testing
[quality] Missing unit tests for pkg/gitops/resource_mapping.go and pkg/mcp/server/tools_drift.go 2 months ago
help wanted quality testing