This issue serves as a central hub for advisory findings from Hive agents, particularly at lower ACMM levels where agents analyze code without creating direct issues or PRs. A governor agent periodically posts digest comments summarizing these advisory findings. This issue is intended to be a living document and should not be closed.
help wantedagent/scannerhive/advisoryagent/securityhive/hosted-kubestellar-console-4vkt
The 'Test Connection' feature incorrectly reports success for Couchbase and Trino when the specified bucket or catalog does not exist. For Couchbase, it only verifies cluster access, not the bucket, and for Trino, the initial connection check doesn't require a catalog. This leads to users believing a connection is valid when it's not, with errors only appearing later in the application.
This issue proposes the creation of a validating webhook for the Burrito project. The webhook will be responsible for validating resources before they are applied, specifically focusing on the `remediationStrategy` enum and complex interactions between various options.
enhancementgood first issueplannedteam:library-maintainers
This issue requests the implementation of a new Git provider for Bitbucket. It specifically mentions building upon the new structural changes introduced in a recent pull request, indicating a need to integrate with an existing framework.
This issue proposes adding a new configuration setting to the Burrito tool. This setting would prevent Burrito from executing 'apply' operations if the 'plan' output indicates that any resources are scheduled for destruction. The goal is to enhance safety and facilitate adoption on critical Terraform code by preventing accidental resource deletion.
This issue is a "good first issue" and part of Hacktoberfest, requesting a new trivia question to be added to a JSON file. The task involves no coding and can be completed in under a minute by forking the repository, editing the specified JSON file, and submitting a pull request.
help wantedgood first issuehacktoberfestcommunitylow hanging fruitup-for-grabs
This issue reports a visual bug in the unstable 1.21.1 build where shallow ocean and beach control points are not correctly matching the 'breaks biome' previews. The provided image likely illustrates this discrepancy, indicating an inconsistency in how biomes are rendered or applied in these specific areas.
The user is reporting a visual bug where small ground flowers from mods like VanillaBackport and nomansland are appearing on top of snow, instead of being covered by it. This suggests a potential layering or rendering conflict between the mods and the snow system.
The `tls_verify_false` security pattern incorrectly flags any use of `verify=False` as a security risk, even when it's unrelated to TLS verification. This is because the pattern uses a broad regular expression that matches the keyword argument regardless of its context. The issue needs to be refined to only trigger on actual TLS/HTTP calls.
This issue proposes simplifying the API for the Clue/React/Ami library by removing the `Factory` and `ActionSender` classes and introducing a new `AmiClient` constructor. This change aims to make the library more user-friendly by allowing direct instantiation of the client and accessing actions directly on it, aligning with upcoming ReactPHP v3 features. The proposed changes will be a breaking change and will be part of the next major release.
This issue requests the addition of new tests for two specific code paths related to closing time functionality in the application. It also requires updating an outdated docstring to accurately reflect the current code behavior. The task is explicitly stated as "Tests only, plus the docstring. No behaviour change."
This issue aims to prevent visual glitches caused by long sequences of combining marks in closing time detail lines. The proposed solution is to either collapse these long runs of marks or clip the overflow, with a preference for a text-based fix that can be unit tested. The goal is to ensure normal text, including special characters and right-to-left scripts, remains unaffected.
The `deleteSecret` function currently fails silently when the secrets file is unreadable, leading to incorrect success reports for secret removals. This issue proposes modifying `deleteSecret` to return a boolean indicating whether a secret was actually removed, while still preventing it from throwing errors. The calling functions should then log the failure if the secret could not be removed.
This issue proposes to add a validation step to the `quickbooks:setAccess` function. Before saving an agent ID to `agentCapabilities`, the system should verify if the provided agent ID exists in the current team roster (hive registry). If the ID is not found, the function should return an error object `{ ok: false }` instead of silently saving an invalid ID.
This issue proposes logging the actual parse error message when invalid JSON is entered into the webhook format editor. Currently, the detailed error is lost, and only a generic message is shown to the user. The fix involves `console.error`ing the raw `JSON.parse` error and updating the error state to a boolean.
This issue requests the addition of a new de-identification locale pack for an additional country. The task involves copying a template file, populating it with country-specific Personally Identifiable Information (PHI) patterns, and potentially adding a test case. The goal is to expand the existing de-identification capabilities to support more regions.
This issue highlights an unknown number of blocking bugs in the EDG compiler when processing C++ header units and named modules. Coverage for these features is currently disabled in tests, and the team is seeking help to identify, reduce, and report individual issues to accelerate the resolution process. Several specific EDG bugs have already been reported and are listed.
The author is requesting feedback on a test version (3.11.0 for the main script, 1.13.0 for the helper) of their Kleinanzeigen (classified ads) duplication tool. They have fixed four bugs but cannot perform end-to-end testing without active ads. They are particularly interested in verifying if all images are included in the recovery ZIP, the functionality of re-posting ads individually and in batches, and the accuracy of the progress counter.
This issue addresses a compatibility problem between Kiro CLI versions 2.x and 3.0. The Guardian, a component of Kiro, is currently configured in a way that only the older CLI version recognizes. The goal is to update the configuration so that the Guardian is registered within the `.kiro/hooks/` directory, ensuring it functions correctly with Kiro CLI 3.0 while maintaining compatibility with 2.x.
The unit test suite is currently unorganized and difficult to read due to its age and incremental updates. The issue proposes refactoring by breaking down long test functions into smaller, more focused ones and splitting large test files into more manageable units, potentially using subdirectories.
This issue identifies a bug where unrecognized model IDs in usage data are silently priced using a default model, leading to significant undercounting. The task is to create a new conformance test vector to ensure that unknown model IDs are correctly flagged as unpriced, rather than being assigned a default price.
The `reduces_per_key` function incorrectly identifies a loop as a per-key reduction if any statement within it uses `setdefault` to keep the first row, even if another statement in the same loop collects all rows for a given key. This leads to misclassification of loops that perform both operations, causing subsequent analysis to treat them as Python-reduced queries.
The 'Extract Method' feature incorrectly identifies input variables for extracted code blocks. When a variable is reassigned within a multi-line statement and then its old value is read later in the same statement, the tool fails to recognize it as an input because it relies on line-by-line analysis instead of statement-level analysis. This leads to the extracted method missing necessary parameters.
This bug report describes an issue where CoreTrust signed Mach-O binaries fail to resign correctly because they contain data after the existing signature, violating codesigning rules. This often occurs with apps produced by the @iosdecrypt Telegram bot, leading to a "DataAfterSignature" error during the codesigning process.
The user is requesting the addition of a fullscreen mode for the Windows application, similar to the F11 shortcut found in other applications. This feature would help reduce distractions by hiding the taskbar and improving focus.
The current method for generating random names in the World Conquest campaign uses a long, potentially difficult string for translators. This issue proposes replacing it with a simpler alternative to improve the translation process.
EnhancementTranslationsGood first issueCampaign WC
On Android, the keyboard obstructs the "Apply/Cancel" row in the "Create or edit task" modal, requiring users to manually dismiss the keyboard before confirming edits. This issue persists despite previous attempts to fix it, as the `clamp()` function's calculation for padding is insufficient on certain devices.
This issue proposes removing unnecessary transparent padding from specific unit images (Knight, Fire, Skeletal Dragon) in the game. The padding is currently used as a workaround for positioning, but it causes issues in other contexts. The suggested solution is to remove the padding from the image files and utilize a new `[default_frame]` tag to manage offsets, as demonstrated by an example.
The GPT-2 statistical engines are currently limited to processing only the first 1,024 tokens of a text, causing them to miss a significant portion of longer reports. The proposed solution is to adapt the engines to process multiple 1,024-token windows across the entire text and pool their statistics, similar to how neural classifiers operate. This change will require re-evaluation of the models and potential adjustments to configuration weights.
This issue proposes enhancing the interactive API documentation for FastAPI by adding example request bodies to various request models. Currently, the 'Try it out' feature starts with an empty body, making it less user-friendly. The goal is to prefill these examples with relevant text or URL data to improve the developer experience when interacting with the API.
documentationhelp wantedgood first issuebeginnereasyhacktoberfest