Open Issues Need Help
View All on GitHub [leaderboard-gen-failure] Leaderboard generation workflow failing about 4 hours ago
help wanted ci-failure
bug documentation good first issue help wanted
[sec-check] Scorecard Vulnerability: brace-expansion GHSA-mh99-v99m-4gvg (uncatchable OOM DoS) 9 days ago
help wanted security
help wanted security
help wanted security
[sec-check] 3 osv-scanner vulnerabilities in docs deps (sharp/libvips high, DOMPurify, linkify-it DoS) 15 days ago
help wanted security
[sec-check] brace-expansion DoS (CVE-2026-13149 / GHSA-3jxr-9vmj-r5cp) in package-lock.json 16 days ago
help wanted security
help wanted ci
[sec-check] Stale Dependabot alert #2: tj-actions/changed-files (CVE-2025-30066) — workflow already removed 19 days ago
help wanted security
[ci-maintainer] Scheduled Link Checker and Typo Checker workflows failing on main (2+ consecutive days) 21 days ago
help wanted ci
help wanted security
help wanted security
help wanted ci
bug documentation good first issue help wanted
bug documentation good first issue help wanted
help wanted ci
help wanted security
help wanted security
help wanted security
help wanted ci
[sec-check] SAST not running on all commits — Scorecard alert #71 persists (re-filed, prior #6271 closed) 27 days ago
help wanted security
[sec-check] Code-Review score failing — Scorecard alert #69 persists (re-filed, prior #6273 closed) 27 days ago
help wanted security
[sec-check] Code-Review score failing — insufficient changeset review coverage (Scorecard #69) 27 days ago
help wanted security
help wanted security
help wanted security
help wanted security
help wanted ci-failure
help wanted security
help wanted security
help wanted security
[sec-check] ai-fix.yml and copilot-automation.yml lack fork guard on pull_request_target (write-capable) 29 days ago
help wanted security
help wanted security
help wanted security
[sec-check] ci: copilot-dco.yml.disabled retains unsafe defaults — no permissions block, uses @main ref 29 days ago
help wanted security
help wanted ci
[sec-check] docs: pr-verifier.yml uses third-party action not pinned by hash (Scorecard alert #224) 29 days ago
help wanted security
help wanted security
[sec-check] docs: no fuzzing tool configured — MDX sanitizer and search API routes not fuzz-tested 29 days ago
help wanted security
[sec-check] docs: 4 new workflows with job-level write token permissions flagged by Scorecard 29 days ago
help wanted security
[ci-maintainer] Fuzz MDX Sanitizer CI check failing on scanner/fix-6215 (fuzz harness exits non-zero) 29 days ago
help wanted ci
[sec-check] docs: no SAST tool configured — Next.js API routes not analyzed for injection vulnerabilities 29 days ago
help wanted security
help wanted security
[sec-check] docs: default branch lacks branch protection — force-push and bypass possible 29 days ago
help wanted security
help wanted security
help wanted security
help wanted security
[sec-check] pull_request_target ai-fix.yml calls mutable reusable workflow @main — pwn-request risk 29 days ago
help wanted security
[sec-check] docs: copilot-dco.yml has no permissions block — token inherits repo-wide defaults 30 days ago
help wanted security
help wanted security
[ci-maintainer] PR Verifier workflow startup failure on all PRs — missing reusable workflow 30 days ago
help wanted ci
help wanted ci
help wanted kind/documentation
[ci-maintainer] Run All Maintainer Audits: recurring bash syntax error — missing opening quote causes workflow failure every Monday about 1 month ago
help wanted ci
[sec-check] Weak supply-chain posture: no branch protection and no code review required on main (Scorecard alerts #76, #69) about 1 month ago
help wanted security
[sec-check] TokenPermissions: multiple workflows lack top-level read-all permissions (Scorecard HIGH) about 1 month ago
help wanted security
[ci-maintainer] Greetings workflow startup_failure on all runs — broken reusable workflow reference about 1 month ago
help wanted ci
[sec-check] TokenPermissions: pr-verifier.yml lacks top-level read-all permissions (Scorecard HIGH) about 1 month ago
help wanted security
[sec-check] OpenSSF CII Best Practices badge absent — Scorecard CIIBestPracticesID alert in 5 repos about 1 month ago
help wanted security
[sec-check] workflow_run trigger with write permissions in technical-doc-writer.lock.yml — privilege escalation risk about 1 month ago
help wanted security
[sec-check] 14 open Scorecard security alerts — TokenPermissions (11) + BranchProtection (2) + CodeReview (1) about 1 month ago
help wanted security
[ci-maintainer] Sync Console Release Versions fails daily — no stable releases found about 1 month ago
help wanted ci
[sec-check] reusable workflow refs unpinned @main in 6 workflows (supply-chain risk) about 1 month ago
help wanted security
[sec-check] disabled workflow files retain pre-fix pwn-request patterns — delete or update about 1 month ago
help wanted security
help wanted security
help wanted security
[sec-check] Token-Permissions: ai-fix.yml and copilot-automation.yml use top-level write permissions with pull_request_target about 1 month ago
help wanted security
[sec-check] copilot-automation.yml + ai-fix.yml: pull_request_target with top-level write permissions, no fork guards about 1 month ago
help wanted security
[sec-check] pr-verifier.yml calls non-existent reusable-pr-verifier.yml — PR title check disabled about 1 month ago
help wanted security
[sec-check] greetings.yml pull_request_target missing fork guard — pwn-request risk about 1 month ago
help wanted security
Broken link: https://kubestellar.io/usage_guide... about 1 month ago
bug documentation good first issue help wanted
Broken link: https://kubestellar.io/architecture_guide... about 1 month ago
bug documentation good first issue help wanted
Broken link: https://kubestellar.io/installation_guide... about 1 month ago
bug documentation good first issue help wanted
Broken link: https://kubestellar.io/development_guide... about 1 month ago
bug documentation good first issue help wanted
[sec-check] Scorecard Code-Review score 0/10 — unreviewed commits merged about 1 month ago
help wanted security
[sec-check] No branch protection on default branch about 1 month ago
help wanted security
[sec-check] No branch protection on default branch (Scorecard BranchProtectionID high) about 1 month ago
help wanted security
Broken link: https://kubestellar.io/architecture_guide... about 1 month ago
bug documentation good first issue help wanted
Broken link: https://kubestellar.io/usage_guide... about 1 month ago
bug documentation good first issue help wanted
Broken link: https://kubestellar.io/development_guide... about 1 month ago
bug documentation good first issue help wanted
Broken link: https://kubestellar.io/installation_guide... about 1 month ago
bug documentation good first issue help wanted
[sec-check] Token-Permissions: 11 Scorecard alerts for over-permissive GITHUB_TOKEN in workflows about 1 month ago
help wanted security
[quality] Test coverage critically low — only 1 of 35 source dirs tested about 1 month ago
help wanted quality testing
[sec-check] Token-Permissions: 7 additional Scorecard alerts in 5 workflows not covered by #6099 about 1 month ago
help wanted security
[sec-check] Code-Review score 0 — 0/26 recent changesets had an approved review (Scorecard high) about 1 month ago
help wanted security
[sec-check] Token-Permissions: 9 workflow files with job-level write scopes (Scorecard high) about 1 month ago
help wanted security
[sec-check] Scorecard VulnerabilitiesID: open/unfixed known vulnerabilities in dependency tree (high) about 1 month ago
help wanted security
[sec-check] run-all-maintainer-audits.yml: actions:write can dispatch any workflow + 10 TokenPermissions alerts (hardening) about 1 month ago
help wanted security
[quality] src/config/versions.ts has 11 routing-critical functions with zero test coverage about 1 month ago
help wanted quality testing
[sec-check] Rollout-checker CronJobs mount OCI config at /root/.oci — containers likely running as root about 1 month ago
help wanted security
[sec-check] Missing securityContext in deployment.yaml and pr-job.yaml preview template (regression from #5877) about 1 month ago
help wanted security
help wanted security
[sec-check] over-permissive GITHUB_TOKEN in 11 workflows (ai-fix, copilot-automation, run-all-maintainer-audits, scorecard, pr-verifier) about 1 month ago
help wanted security
Broken link: https://kubestellar.io/installation_guide... about 1 month ago
bug documentation good first issue help wanted
Broken link: https://kubestellar.io/architecture_guide... about 1 month ago
bug documentation good first issue help wanted
Broken link: https://kubestellar.io/development_guide... about 1 month ago
bug documentation good first issue help wanted
Broken link: https://kubestellar.io/usage_guide... about 1 month ago
bug documentation good first issue help wanted
[sec-check] Token-Permissions regression — 5 new workflows missing job-level permission scoping about 1 month ago
help wanted security
[sec-check] Missing permissions block in copilot-dco.yml (not propagated from console fix) about 1 month ago
help wanted security
Broken link: https://kubestellar.io/installation_guide... about 1 month ago
bug documentation good first issue help wanted
Broken link: https://kubestellar.io/development_guide... about 1 month ago
bug documentation good first issue help wanted