| abiosoft/colima |
#1642 |
Recover from HTTP 416 when resuming a cached download so an interrupted colima start no longer fails until the cache is deleted |
✅ Merged |
| anchore/syft |
#5321 |
Fix a crash when cataloging ELF files with a truncated dynamic section by reading dynamic tags through debug/elf DynValue |
✅ Merged |
| falcosecurity/falcosidekick |
#1446 |
Close the syslog output connection after each event so every Falco alert no longer leaks a socket and file descriptor |
✅ Merged |
| argoproj-labs/gitops-promoter |
#2056 |
Release the old Secret finalizer when an ScmProvider or ClusterScmProvider secretRef changes |
✅ Merged |
| nginx/nginx-gateway-fabric |
#5953 |
Fix a control plane panic on a BackendTLSPolicy with an empty caCertificateRefs list |
✅ Merged |
| oras-project/oras |
#2174 |
Drop an index's own child manifests from the referrers a registry without Referrers API support reports for it, so oras cp -r copies the root index instead of failing to tag it |
✅ Merged |
| projectcalico/calico |
#13979 |
Accept the full 4-byte AS number range (RFC 4893) in the BGPConfiguration, BGPPeer and BGPFilter CRD schemas |
✅ Merged |
| databus23/helm-diff |
#1074 |
Skip Helm hooks in the --take-ownership ownership check, so unchanged hooks stop showing up as ownership changes and a leftover test hook no longer fails the diff |
✅ Merged |
| kubernetes-sigs/external-dns |
#6709 |
Reduce ApplyChanges cyclomatic complexity in the Exoscale provider (26 to 6) |
✅ Merged |
| kubernetes-sigs/kwok |
#1749 |
Buffer net.Tunnel's copy-result channel so both goroutines can exit, instead of leaking up to two per interrupted kubectl exec / kubectl port-forward |
✅ Merged |
| zalando/skipper |
#4201 |
Add an optional response status condition to the logBody filter, so a request body can be logged only for failing responses |
✅ Merged |
| k3s-io/k3s |
#14516 |
Add advertise-address to SANs before generating apiserver cert |
✅ Merged |
| go-gitea/gitea |
#38863 |
Stream bundle downloads instead of writing a repo-sized temp file to disk first |
✅ Merged |
| tektoncd/pipeline |
#10548 |
Filter ResolutionRequests by the resolver's own label selector on leader promotion, so one resolver no longer fails requests owned by another |
✅ Merged |
| argoproj-labs/terraform-provider-argocd |
#920 |
Restore project role policy validation lost in the plugin-framework migration, sourcing the allowed resources from Argo CD's exported project-scoped set |
✅ Merged |
| reviewdog/action-shellcheck |
#102 |
Fix word-splitting so shell file paths containing spaces are linted instead of silently skipped |
✅ Merged |
| prometheus-operator/prometheus-operator |
#8728 |
Add spec.retentionPercentage to the Prometheus CRD for percentage-based TSDB retention (Prometheus >= v3.11.0) |
✅ Merged |
| kubernetes-sigs/kueue |
#13428 |
Automated cherry pick of #12797: Keep the sticky workload consistent during ClusterQueue heap and snapshot sorts |
✅ Merged |
| argoproj-labs/terraform-provider-argocd |
#912 |
Add gitea labels filter to the application_set pull_request generator |
✅ Merged |
| groundhog2k/helm-charts |
#1521 |
Add Prometheus metrics and ServiceMonitor support to the mongodb chart (mongodb_exporter sidecar) |
✅ Merged |
| clouddrove/smurf |
#473 |
Return a non-zero exit code when stf apply/destroy is declined at the approval prompt |
✅ Merged |
| terraform-redhat/terraform-provider-rhcs |
#1273 |
Drop the vestigial terraform-plugin-sdk/v2 direct dependency by reimplementing LogLevel() locally (adds first unit tests to the logging package) |
✅ Merged |
| external-secrets/external-secrets |
#6675 |
Add opt-in schedulerName and runtimeClassName to the Helm chart pods |
✅ Merged |
| element-hq/ess-helm |
#1461 |
Add schedulerName and runtimeClassName support to matrix-stack component workloads |
✅ Merged |
| kubernetes-sigs/kubespray |
#13370 |
cilium: wire the scrape port variables into the Helm values template so they stop being no-ops |
✅ Merged |
| rancher/dynamiclistener |
#315 |
Guard the queuedSecret field with a mutex to fix a data race in the Kubernetes storage controller |
✅ Merged |
| restatedev/sdk-go |
#161 |
Fix data race between Drain and concurrent Read on the request stream |
✅ Merged |
| kubernetes-sigs/kubebuilder |
#5864 |
Authenticate pinact with GITHUB_TOKEN in the workflow-lint CI job to avoid GitHub API rate limits (#5817) |
✅ Merged |
| open-telemetry/opentelemetry-helm-charts |
#2299 |
Add opt-in crds.annotations to the opentelemetry-operator chart so CRDs can carry helm.sh/resource-policy: keep and survive helm uninstall |
✅ Merged |
| temporalio/helm-charts |
#949 |
Add schedulerName/runtimeClassName/priorityClassName to Temporal server/web/admintools pods |
✅ Merged |
| terraform-google-modules/terraform-google-kubernetes-engine |
#2617 |
Fixed add_shadow_firewall_rules requiring add_cluster_firewall_rules (null cluster_subnet_cidr plan error) |
✅ Merged |
| element-hq/ess-helm |
#1442 |
Add affinity support to component workloads |
✅ Merged |
| stakater/Reloader |
#1181 |
Add runtimeClassName and schedulerName support to the Reloader Helm chart deployment |
✅ Merged |
| open-telemetry/opentelemetry-go-contrib |
#9238 |
Fix otelslog dropping error attributes nested inside a slog.Group |
✅ Merged |
| apache/gravitino |
#11917 |
Add opt-in topologySpreadConstraints support to Gravitino/Iceberg-REST/Lance-REST Helm charts |
✅ Merged |
| open-feature/go-sdk |
#522 |
Guard memprovider Resolve against a non-nil pointer to a nil ContextEvaluator func (panic fix) |
✅ Merged |
| kubernetes-sigs/descheduler |
#1892 |
Added opt-in hostUsers (user-namespace sharing) to the descheduler Helm chart |
✅ Merged |
| terraform-docs/terraform-docs |
#947 |
Render explicit null variable defaults as null (not "") in tfvars hcl output |
✅ Merged |
| element-hq/ess-helm |
#1438 |
Add priorityClassName support to matrix-stack component workloads |
✅ Merged |
| kubernetes-sigs/kueue |
#12797 |
Fix non-transitive ClusterQueue sort when the sticky workload changes mid-sort |
✅ Merged |
| open-telemetry/opentelemetry-go-contrib |
#9229 |
Fix otelslog data race corrupting log attributes via shared kvBuffer (closes #9046) |
✅ Merged |
| valkey-io/valkey-helm |
#218 |
Add optional priorityClassName to the valkey-operator Deployment |
✅ Merged |
| kubernetes-sigs/kueue |
#12796 |
Fix data race on stickyWorkload between Snapshot and RequeueIfNotPresent |
✅ Merged |
| supabase-community/supabase-kubernetes |
#214 |
Add configurable Prometheus ServiceMonitor support to the Supabase Helm chart |
✅ Merged |
| ory/k8s |
#888 |
Completed the PodDisruptionBudget namespace fix across the remaining Ory Helm charts (kratos, hydra-maester, oathkeeper-maester) |
✅ Merged |
| valkey-io/valkey-helm |
#217 |
Add configurable health probes (startup/liveness/readiness) to the Valkey chart |
✅ Merged |
| kubernetes-sigs/kueue |
#12736 |
Fixed a data race on the ClusterQueue sticky workload between the Visibility API snapshot and preemption requeue (self-synchronizing mutex). |
✅ Merged |
| guerzon/vaultwarden |
#234 |
Add opt-in topologySpreadConstraints to the vaultwarden Helm chart pod spec |
✅ Merged |
| kubernetes-sigs/descheduler |
#1890 |
Add opt-in schedulerName and runtimeClassName to the descheduler Helm chart |
✅ Merged |
| elastic/docs-content |
#7182 |
Documented EKS Pod Identity setup for the S3 snapshot repository |
✅ Merged |
| inference-gateway/cli |
#713 |
Guard Tree tool gitignore cache and screenshot rate-limit against concurrent-map data races |
✅ Merged |
| istio/istio |
#60723 |
Add terminationGracePeriodSeconds option to the istiod Helm chart |
✅ Merged |
| terraform-aws-modules/terraform-aws-eks |
#3726 |
Fix the FAQ example so case 2 sets attach_cluster_primary_security_group = false (the two opposite remedies previously showed the same example); fixes #3724 |
✅ Merged |
| valkey-io/valkey-helm |
#197 |
Add aggregated admin/editor/viewer ClusterRoles to the valkey-operator chart |
✅ Merged |
| valkey-io/valkey-helm |
#196 |
Add optional Prometheus ServiceMonitor to the valkey-operator chart |
✅ Merged |
| actions-rust-lang/setup-rust-toolchain |
#96 |
Add cache-targets passthrough to rust-cache |
✅ Merged |
| redpanda-data/helm-charts |
#1756 |
kminion chart: add opt-in extraEnvFrom for Secret/ConfigMap env injection (Deployment + DaemonSet) |
✅ Merged |
| metallb/metallb |
#3079 |
Avoid stale resourceVersion errors in ServiceL2Status and ServiceBGPStatus reconcile |
✅ Merged |
| valkey-io/valkey-helm |
#195 |
Add optional topologySpreadConstraints to the valkey-operator chart Deployment |
✅ Merged |
| VictoriaMetrics/helm-charts |
#3016 |
Add runtimeClassName option to pod specs across all VictoriaMetrics charts |
✅ Merged |
| woodpecker-ci/helm |
#498 |
Add topologySpreadConstraints to the Woodpecker server (parity with the agent) |
✅ Merged |
| argoproj/argo-helm |
#3943 |
Add envFrom to the argo-workflows controller and argo-server containers |
✅ Merged |
| goauthentik/helm |
#483 |
Add server.automountServiceAccountToken to the authentik Helm chart (server-pod parity with the worker setting) |
✅ Merged |
| kubernetes-sigs/headlamp |
#6148 |
Replace the any return type of KubeObject.apiList with a typed value in the Headlamp Kubernetes dashboard frontend |
✅ Merged |
| redpanda-data/helm-charts |
#1754 |
Add opt-in topologySpreadConstraints to the kminion Helm chart (Deployment and DaemonSet) |
✅ Merged |
| kubernetes-sigs/descheduler |
#1885 |
Add an opt-in PodDisruptionBudget to the descheduler Helm chart (Deployment mode) |
✅ Merged |
| longhorn/longhorn |
#13378 |
Add an opt-in PodDisruptionBudget to the Longhorn UI Deployment in the Helm chart |
✅ Merged |
| kedacore/charts |
#881 |
Make the KEDA operator gRPC metrics service port configurable (#511) |
✅ Merged |
| anchore/grype |
#3519 |
Add vulnerable version ranges to the CycloneDX output format (closes #3512) |
✅ Merged |
| amacneil/dbmate |
#803 |
Add --wait-interval flag and DBMATE_WAIT_INTERVAL env var to configure the delay between connection attempts for --wait |
✅ Merged |
| metallb/metallb |
#3076 |
Remove deprecated metallb.universe.tf managed annotation lingering on Services after upgrade |
✅ Merged |
| fluent/fluentd |
#5390 |
Add umask option to the directive |
✅ Merged |
| kudobuilder/kuttl |
#694 |
Fix flaky integration test by randomizing namespace (prevents -count collision) |
✅ Merged |
| kedacore/charts |
#880 |
Add an opt-in hostUsers field to the KEDA operator, metrics server and webhooks pods (user namespaces) |
✅ Merged |
| stern/stern |
#373 |
Support nested-field extraction via dot notation in extractJSONParts/tryExtractJSONParts template funcs (closes #343) |
✅ Merged |
| jenkins-infra/helm-charts |
#1972 |
Add an opt-in PodDisruptionBudget to the httpd Helm chart |
✅ Merged |
| vmware-tanzu/helm-charts |
#740 |
Add optional PodDisruptionBudget to the Velero Helm chart |
✅ Merged |
| pypa/pipx |
#1842 |
Add --dry-run flag to pipx ensurepath to preview PATH changes without modifying any shell config |
✅ Merged |
| open-telemetry/opentelemetry-collector-contrib |
#49146 |
Add opt-in TLS support to the memcached receiver |
✅ Merged |
| elastic/elasticsearch |
#151614 |
S3 snapshot repository: EKS Pod Identity credential support |
✅ Merged |
| mindersec/minder |
#6520 |
Resolve OCI artifact created time from the image config instead of the time.Now() fallback (closes #6490) |
✅ Merged |
| open-policy-agent/conftest |
#1355 |
Add --github-hide-passed flag to skip passing files in the GitHub outputter (closes #1315) |
✅ Merged |
| dragonflydb/dragonfly-operator |
#550 |
Add optional PodDisruptionBudget to the operator Helm chart |
✅ Merged |
| external-secrets/external-secrets |
#6481 |
Scoped External Secrets Operator cert-controller ClusterRole to least-privilege (resourceNames-pinned write access) in the Helm chart |
✅ Merged |
| opentofu/setup-opentofu |
#121 |
Verify the downloaded OpenTofu CLI against the release's published SHA256SUMS by default (closes #117) |
✅ Merged |
| open-telemetry/opentelemetry-helm-charts |
#2258 |
Honor schedulerName in daemonset and statefulset collector modes |
✅ Merged |
| vectordotdev/vector |
#25607 |
Add a host_metrics temperature collector via sysinfo Components |
✅ Merged |
| jaegertracing/helm-charts |
#761 |
Restore extraVolumes/extraVolumeMounts on the all-in-one deployment |
✅ Merged |
| helm/chart-testing-action |
#210 |
Report a clear error when blob verification fails |
✅ Merged |
| nginx/nginx-gateway-fabric |
#5392 |
Add GEP-713 Programmed status condition to custom policies |
✅ Merged |
| helm/chart-testing |
#841 |
Honor --release-name instead of generating one |
✅ Merged |
| yannh/kubeconform |
#356 |
Avoid SIGSEGV panic on null-decoding schema |
✅ Merged |
| meshery/meshery |
#19835 |
Fix typos, function names & license header |
✅ Merged |
| prometheus-community/helm-charts |
#7310 |
Point the couchdb-exporter probes at /status, since image v28 answers / with 404 and the pod never became ready |
🔵 Review |
| kubernetes-sigs/kustomize |
#6287 |
Stop kustomize edit from duplicating # lines inside YAML block scalars by tracking block scalar indentation |
🔵 Review |
| fluent/fluent-operator |
#2063 |
Add autoExtractTimestamp to the Fluent Bit Splunk output CRD so Splunk extracts event timestamps via HEC auto_extract_timestamp |
🔵 Review |
| dapr/cli |
#1710 |
Send the DAPR_API_TOKEN header on workflow gRPC calls so list, history, purge and rerun work against token-secured sidecars |
🔵 Review |
| kubernetes-csi/external-snapshotter |
#1489 |
csi-snapshotter: stop the sidecar's own VolumeGroupSnapshotContent writes from bypassing the requeue backoff and flooding the driver with CreateVolumeGroupSnapshot calls |
🔵 Review |
| zalando/postgres-operator |
#3189 |
Delete cluster services with background propagation so the replica service's EndpointSlices are not orphaned |
🔵 Review |
| istio/istio |
#61851 |
Honor verifyCertificateHash and verifyCertificateSpki on file-mounted Gateway and Sidecar server certs |
🔵 Review |
| open-telemetry/opentelemetry-operator |
#5628 |
Add imagePullSecrets to the OpenTelemetryCollector and TargetAllocator CRs so their pods can pull images from private registries |
🔵 Review |
| nginx/nginx-gateway-fabric |
#5951 |
Remove BackendTLSPolicy validation already enforced by the Gateway API CRD schema and CEL rules |
🔵 Review |
| antrea-io/antrea |
#8436 |
Escape user-supplied L7 NetworkPolicy host / path / sni patterns in generated Suricata rules, so a quote or semicolon can no longer close content: early and inject extra rule keywords |
🔵 Review |
| woodpecker-ci/woodpecker |
#7158 |
Wait for the pod informer's cache sync before WaitStep's deleted-pod guard in the Kubernetes backend, so a service pod deleted at teardown no longer hangs the workflow until its timeout |
🔵 Review |
| mariadb-operator/mariadb-operator |
#1907 |
Enforce the PhysicalBackup timeout through the Job's activeDeadlineSeconds so timed out backups are reported as failed instead of Success, and never bootstrap replicas from a failed backup |
🔵 Review |
| k8ssandra/k8ssandra-operator |
#1795 |
Use a non-controller owner reference for telemetry ServiceMonitors so they can be created on OpenShift without cassandradatacenters/finalizers RBAC |
🔵 Review |
| rancher/cluster-api-provider-rke2 |
#1047 |
Keep the node's configured SELinux mode during Ignition bootstrap instead of forcing enforcing after setenforce 0, so permissive nodes (Flatcar default) stay permissive |
🔵 Review |
| tektoncd/cli |
#3245 |
Make tkn task/pipeline sign add only the signature annotation instead of rewriting the whole YAML document (also stops the invalid resources: {} injection) |
🔵 Review |
| cert-manager/cert-manager |
#9353 |
Fail over to the next configured DNS server when an ACME HTTP-01 self-check nameserver does not respond |
🔵 Review |
| kubevela/pkg |
#140 |
Stop the cuex function-call error from printing an empty path and leaking a cue/format failure in place of the value |
🔵 Review |
| cilium/cilium |
#48540 |
gateway-api: stop the X-Forwarded-Proto guard from silently disabling an HTTPRoute RequestRedirect whose scheme matches the listener |
🔵 Review |
| cert-manager/cert-manager |
#9305 |
Reject Certificate renewal windows that can never be reached within the certificate lifetime, in the admission webhook |
🔵 Review |
| containerd/nerdctl |
#5174 |
Only mark a container explicitly stopped when the signal actually stops it, so nerdctl kill --signal=HUP no longer disables a --restart=always policy |
🔵 Review |
| kubernetes-csi/external-resizer |
#610 |
csi-resizer: report a VolumeAttributesClass the driver cannot apply as an event on the PVC, instead of silently ignoring it |
🔵 Review |
| envoyproxy/gateway |
#9860 |
Fix the always-zero watchable_depth control-plane gauge by recording the coalesced update backlog |
🔵 Review |
| terraform-docs/terraform-docs |
#955 |
Link built-in provider resources (terraform_data, terraform_remote_state) to the Terraform language docs instead of a dead registry URL |
🔵 Review |
| opencost/opencost |
#4002 |
Cost native sidecar containers (restartPolicy: Always init containers) instead of omitting them from pod cost |
🔵 Review |
| external-secrets/external-secrets |
#6830 |
Oracle provider: return NoSecretErr on a missing vault secret so ExternalSecret deletionPolicy applies |
🔵 Review |
| argoproj/argo-workflows |
#16610 |
Add preferred type to retry nodeAntiAffinity. Fixes #13969 |
🔵 Review |
| actions/stale |
#1357 |
Add opt-in exempt-issues-with-open-linked-pr so issues with a closing PR aren't marked stale |
🔵 Review |
| dorny/paths-filter |
#323 |
Scope the merge-base commit count to the base and head refs so a broken unrelated ref cannot fail the job |
🔵 Review |
| gruntwork-io/terragrunt |
#6572 |
Add overwrite_terragrunt_or_skip value for generate block if_exists, gated behind an experiment |
🔵 Review |
| prometheus-operator/prometheus-operator |
#8729 |
Add httpHeaders field to ServiceMonitor and PodMonitor endpoints for custom scrape HTTP headers (Prometheus >= 2.55.0) |
🔵 Review |
| aws/karpenter-provider-aws |
#9454 |
Surface EC2 request rejections (e.g. InvalidBlockDeviceMapping) on the EC2NodeClass validation condition instead of retrying them as authorization errors |
🔵 Review |
| integrations/terraform-provider-github |
#3570 |
Include explicitly-configured false booleans on github_organization_settings create (fixes GetOk false/unset ambiguity) |
🔵 Review |
| terraform-aws-modules/terraform-aws-wafv2 |
#10 |
Fix ip_set_forwarded_ip_config being dropped in nested WAFv2 statement blocks |
🔵 Review |
| keephq/helm-charts |
#199 |
Add opt-in PodDisruptionBudget support for HA components (backend/frontend/websocket) to the Keep Helm chart |
🔵 Review |
| carvel-dev/kapp-controller |
#1844 |
Fix concurrent map iteration/write panic in AppRefTracker under high reconciliation concurrency |
🔵 Review |
| prometheus-community/helm-charts |
#7108 |
prometheus-adapter chart: add optional schedulerName and runtimeClassName to the Deployment |
🔵 Review |
| anchore/scan-action |
#726 |
Add glob pattern support to the scan-action sbom input (expands to exactly one SBOM file) |
🔵 Review |
| terraform-google-modules/terraform-google-composer |
#203 |
Fixed cloud_data_lineage_integration=false being a no-op (nullable var so it can be explicitly disabled) |
🔵 Review |
| kubeshark/kubeshark |
#1949 |
Opt-in Prometheus Operator ServiceMonitor for the Helm chart's metrics services |
🔵 Review |
| terraform-aws-modules/terraform-aws-dynamodb-table |
#123 |
Add opt-in standalone GSI management (aws_dynamodb_global_secondary_index) for independent index lifecycle |
🔵 Review |
| argoproj/argo-cd |
#28584 |
Add skip schema validation toggle to Application parameters editor (#5111) |
🔵 Review |
| terraform-aws-modules/terraform-aws-lambda |
#762 |
Clarify lambda_role is ignored when create_role is true (docs) |
🔵 Review |
| kyverno/kyverno |
#16428 |
Add opt-in schedulerName and runtimeClassName to the Kyverno controller Helm chart |
🔵 Review |
| fyrash/fyra-cli |
#1 |
Warn when secret files are excluded from the push |
🔵 Review |
| terraform-aws-modules/terraform-aws-lambda |
#761 |
Add region variable to alias submodule for AWS provider v6 resource-level region |
🔵 Review |
| terraform-aws-modules/terraform-aws-eventbridge |
#203 |
Gate the EventBridge log delivery source on configured log delivery (fixes orphan aws_cloudwatch_log_delivery_source); fixes #201 |
🔵 Review |
| terraform-aws-modules/terraform-aws-msk-kafka-cluster |
#69 |
Restore broker log delivery for MSK Express brokers |
🔵 Review |
| terraform-aws-modules/terraform-aws-iam |
#651 |
Add opt-in ebs_csi_volume_tagging variable so the EBS CSI driver can tag existing volumes (enables VolumeAttributesClass); fixes #649 |
🔵 Review |
| argoproj/argo-cd |
#28406 |
Persist Applications search bar text across navigation (view preferences) |
🔵 Review |
| kubereboot/charts |
#141 |
Add opt-in topologySpreadConstraints to the kured chart DaemonSet |
🔵 Review |
| kedacore/charts |
#882 |
Per-component Deployment labels/annotations for KEDA pods |
🔵 Review |
| ray-project/kuberay |
#4934 |
Add optional PodDisruptionBudget to the ray-cluster Helm chart |
🔵 Review |
| vapor/vapor |
#3475 |
Add typed Retry-After HTTP header accessor |
🔵 Review |
| tj-actions/changed-files |
#2884 |
Hardened README to recommend injection-safe consumption of the changed-files list (JSON + bash array + -- separator). |
🔵 Review |
| dexidp/dex |
#4831 |
Add EdDSA (Ed25519) signing algorithm support to the local token signer |
🔵 Review |
| hashicorp/setup-terraform |
#561 |
Verify the downloaded Terraform CLI against HashiCorp's signed SHA256SUMS before install (closes #556) |
🔵 Review |
| hashicorp/terraform-provider-kubernetes |
#2905 |
Add env_from_map provider-defined function |
🔵 Review |
| percona/percona-helm-charts |
#862 |
pmm gRPC ClusterIP nodePort fix |
🔵 Review |
| meshery/meshery |
#19866 |
Fix export flag validation + tests |
🔵 Review |
| dependabot/dependabot-core |
#15199 |
Identify Dependabot commits by author name |
🔵 Review |
| aquasecurity/trivy |
#10770 |
Add --color flag for table output |
🔵 Review |