Open Issues Need Help
View All on GitHub help wanted ci
help wanted security
help wanted ci
[sec-check] 6 Scorecard Token-Permissions + 2 Pinned-Dependencies alerts — supply-chain hardening 23 days ago
help wanted security
[ci-maintainer] PR Verifier failing on all Dependabot pull_request_target runs (startup_failure, 0 jobs) 23 days ago
help wanted ci
[sec-check] Code-Review score failing — insufficient changeset review coverage (Scorecard #8) 27 days ago
help wanted security
help wanted security
help wanted security
help wanted security
[sec-check] BranchProtection score low — main branch requires PRs, status checks, and admin enforcement 27 days ago
help wanted security
[sec-check] Code review not enforced — only 1 of 29 recent changesets approved (Scorecard) 27 days ago
help wanted security
help wanted security
help wanted security
[sec-check] homebrew-tap: copilot-dco.yml.disabled lacks permissions block and uses @main ref 29 days ago
help wanted security
help wanted security
help wanted security
[ci-maintainer] PR Verifier rejects scanner/agent PR titles — [actor] prefix not valid conventional commits 29 days ago
help wanted ci
[sec-check] homebrew-tap: no mandatory code review — formula changes can be merged without approval 29 days ago
help wanted security
[sec-check] homebrew-tap: default branch lacks branch protection — formula tampering possible 29 days ago
help wanted security
help wanted security
help wanted security
[sec-check] copilot-dco.yml missing permissions block — GITHUB_TOKEN inherits repo-wide defaults 29 days ago
help wanted security
help wanted security
[sec-check] pull_request_target ai-fix.yml calls mutable reusable workflow @main — pwn-request risk 29 days ago
help wanted security
[ci-maintainer] PR Verifier workflow startup failure — broken reusable workflow reference 30 days ago
help wanted ci
[sec-check] TokenPermissions: 4 workflows lack top-level read-all permissions (Scorecard HIGH) about 1 month ago
help wanted security
[sec-check] reusable workflow refs unpinned @main in 6 workflows (supply-chain risk) about 1 month ago
help wanted security
[sec-check] disabled workflow files retain pre-fix pwn-request patterns — delete or update about 1 month ago
help wanted security
help wanted security
help wanted security
[sec-check] Token-Permissions: ai-fix.yml and copilot-automation.yml use top-level write permissions with pull_request_target about 1 month ago
help wanted security
[sec-check] copilot-automation.yml + ai-fix.yml: pull_request_target with top-level write permissions, no fork guards about 1 month ago
help wanted security
[sec-check] pr-verifier.yml calls non-existent reusable-pr-verifier.yml — PR title check is broken about 1 month ago
help wanted security
[sec-check] No branch protection on default branch about 1 month ago
help wanted security
[sec-check] Scorecard Code-Review score 0/10 — unreviewed commits merged about 1 month ago
help wanted security
[sec-check] No branch protection on default branch (Scorecard BranchProtectionID high) about 1 month ago
help wanted security
[sec-check] Code-Review score 0 — 0/27 recent changesets had an approved review (Scorecard high) about 1 month ago
help wanted security
[sec-check] Token-Permissions: 6 Scorecard alerts for over-permissive GITHUB_TOKEN in workflows about 1 month ago
help wanted security
[sec-check] homebrew-tap: assignment-helper.yml uses unpinned @main reusable workflow (supply-chain risk) about 1 month ago
help wanted security
[sec-check] Token-Permissions: 6 Scorecard alerts across 5 workflows (Scorecard high) about 1 month ago
help wanted security
[sec-check] Token-Permissions: 6 job-level write scopes in 5 workflows (Scorecard high) about 1 month ago
help wanted security
[sec-check] over-permissive GITHUB_TOKEN in 6 workflows including missing top-level permissions in copilot-dco.yml about 1 month ago
help wanted security
help wanted security
[sec-check] pr-verifier.yml: PRT + secrets: inherit exposes all repo secrets (2nd filing — fix not applied) about 1 month ago
help wanted security
[sec-check] ai-fix.yml: PRT with 3 write permissions and no fork guard (2nd filing — fix not applied) about 1 month ago
help wanted security
[sec-check] copilot-automation.yml: PRT with 4 write permissions and no fork guard (2nd filing — fix not applied) about 1 month ago
help wanted security
[sec-check] greetings.yml: PRT + secrets: inherit exposes all repo secrets (2nd filing — fix not applied) about 1 month ago
help wanted security
[ci-maintainer] Homebrew CI: kubestellar-deploy formula fails brew audit --strict on every nightly update (#{bin} → bin/) about 2 months ago
help wanted ci
[ci-maintainer] PR Verifier startup_failure: unpinned @main reusable workflow broken about 2 months ago
help wanted ci
[ci-maintainer] Homebrew CI: brew audit --strict fails for kubestellar-ops formula about 2 months ago
help wanted ci
[ci-maintainer] Homebrew CI: brew audit --strict fails on kubestellar-deploy formula about 2 months ago
help wanted ci
[sec-check] HIGH: Branch protection incomplete on main — no required reviews or status checks (Scorecard #1, score 3/10) about 2 months ago
help wanted security
[sec-check] Dependabot security updates disabled about 2 months ago
help wanted security
[quality] Add formula unit tests with brew test blocks about 2 months ago
enhancement help wanted kind/test
[sec-check] HIGH: Code-Review score 1/10 — only 3 of 30 recent changesets reviewed (Scorecard #8) about 2 months ago
help wanted security
help wanted security
help wanted security
[scanner] kc-agent.rb brew audit failures: desc too long + bin interpolation style about 2 months ago
bug help wanted
[guide] homebrew-tap missing CODE_OF_CONDUCT.md about 2 months ago
documentation help wanted
[guide] homebrew-tap missing LICENSE file — README references Apache 2.0 but no file present about 2 months ago
documentation help wanted
[guide] Add SECURITY.md for vulnerability reporting about 2 months ago
documentation help wanted
help wanted security
help wanted security
[sec-check] LOW: Code-Review not enforced + no Dependency-Update-Tool configured (Scorecard HIGH) 2 months ago
help wanted security
help wanted security
[sec-check] Over-permissive GITHUB_TOKEN in 12 workflows — token-permissions hardening needed 2 months ago
help wanted security
help wanted kind/bug
[guide] README formula-status table links to closed issues — kubectl-claude and kubestellar-console entries are stale 2 months ago
documentation help wanted
bug help wanted security agent/reviewer hive/hive-v1
bug help wanted
[guide] README kubectl-claude section has no actionable installation path or link to upstream source 2 months ago
documentation help wanted
[guide] CONTRIBUTING.md does not mention that Formula files are auto-generated by GoReleaser 2 months ago
documentation help wanted
[guide] README misleadingly documents kubectl-claude as a Homebrew formula despite noting it is not yet available 2 months ago
documentation help wanted
[ci-maintainer] brew audit --strict fails on kc-agent.rb: description length and bin interpolation 2 months ago
bug help wanted kind/failing-test
documentation help wanted
[sec-check] Supply chain risk: unpinned @main reusable workflow refs with pull_request_target + secrets:inherit 2 months ago
help wanted security