DevOps Engineer passionate about Cloud Infrastructure, Kubernetes, and Automation. Building open-source tools for the DevOps community.
Follow for new Kubernetes operators, GitHub Actions, and OSS contribution updates.
| Project | Description | Stars |
|---|---|---|
| compress-decompress | GitHub Action for file compression/decompression | |
| network-policy-generator | Kubernetes operator that generates NetworkPolicy from a CRD | |
| cicd-monitoring | Production-ready CI/CD & monitoring stack for AWS/GCP/on-prem Kubernetes | |
| kube-ctx | Single-binary kubectx/kubens replacement with per-terminal context isolation, production guards, and a built-in fuzzy picker | |
| helios-lb | Kubernetes controller providing bare-metal LoadBalancer IP allocation (MetalLB-style) | |
| k8s-namespace-sync | Kubernetes controller that syncs Secrets/ConfigMaps across namespaces | |
| git-bridge | Multi-provider Git mirror: CodeCommit, GitLab, GitHub any-to-any with webhooks & SQS |
Contributions to external open-source projects.
| Project | PR | Contribution |
|---|---|---|
| apache/airflow | #67675 | Gateway API HTTPRoute support for the API server |
| elastic/elasticsearch | #151614 | S3 snapshot repository: EKS Pod Identity credential support |
| go-gitea/gitea | #38863 | Stream bundle downloads instead of writing a repo-sized temp file to disk first |
| k3s-io/k3s | #14516 | Add advertise-address to the SANs before generating the apiserver serving certificate |
| pulumi/pulumi | #24939 | Lock the cleanup and clone or pull of the shared templates directory, so concurrent pulumi new runs no longer delete each other's in-progress clone |
| prometheus-operator/prometheus-operator | #8728 | Add spec.retentionPercentage to the Prometheus CRD for percentage-based TSDB retention (Prometheus >= v3.11.0) |
| projectcalico/calico | #13979 | Accept the full 4-byte AS number range (RFC 4893) in the BGPConfiguration, BGPPeer and BGPFilter CRD schemas |
| open-telemetry/opentelemetry-collector-contrib | #49146 | Add opt-in TLS support to the memcached receiver |
| nginx/nginx-gateway-fabric | #5392 | Add GEP-713 Programmed status condition to custom policies |
| getmoto/moto | #10062 | Add EC2 snapshot tiering APIs (archive / describe-status / restore) |
| anchore/grype | #3519 | Add vulnerable version ranges to the CycloneDX output format |
| tektoncd/pipeline | #10548 | Filter ResolutionRequests by the resolver's own label selector on leader promotion, so one resolver no longer fails requests owned by another |
| fluxcd/flux2 | #5975 | Add an opt-in version-file input to the Flux CLI GitHub Action |
| kubernetes-sigs/kueue | #12736 | Fix a data race on the ClusterQueue sticky workload between the Visibility API snapshot and preemption requeue |
| external-secrets/external-secrets | #6481 | Scope the ESO cert-controller ClusterRole to least-privilege in the Helm chart |
| vectordotdev/vector | #25607 | Add a host_metrics temperature collector via sysinfo Components |
| argoproj-labs/terraform-provider-argocd | #920 | Restore project role policy validation lost in the plugin-framework migration, sourcing the allowed resources from Argo CD's exported project-scoped set |
View all contributions (242)
| Project | PR | Contribution | Status |
|---|---|---|---|
| prometheus-community/helm-charts | #7060 | Add opt-in Gateway API HTTPRoute support to the alertmanager-snmp-notifier chart | ✅ Merged |
| nextcloud/helm | #868 | Fixed Argo CD drift on the generated HTTPRoute by rendering explicit group/kind in backendRefs | ✅ Merged |
| BorisPolonsky/dify-helm | #419 | Add opt-in Gateway API HTTPRoute support to the Dify Helm chart | ✅ Merged |
| goharbor/harbor-helm | #2386 | Fixed HTTPRoute rendering crash on empty default parentRefs/hosts in the Harbor Helm chart (Gateway API expose.type=route) | ✅ Merged |
| nextcloud/helm | #866 | Add CalDAV/CardDAV service-discovery redirects to the Gateway API HTTPRoute (fix backendRefs conflict with RequestRedirect) | ✅ Merged |
| prometheus-community/helm-charts | #7032 | Add Gateway API HTTPRoute support to the prom-label-proxy chart | ✅ Merged |
| prometheus-community/helm-charts | #7031 | Add Gateway API HTTPRoute support to the jiralert chart | ✅ Merged |
| prometheus-community/helm-charts | #7029 | Add Gateway API HTTPRoute support to the prometheus-pingmesh-exporter chart | ✅ Merged |
| prometheus-community/helm-charts | #7028 | Add Gateway API HTTPRoute support to the prometheus-fastly-exporter chart | ✅ Merged |
| prometheus-community/helm-charts | #7024 | Add Gateway API HTTPRoute support to the prometheus-snmp-exporter chart | ✅ Merged |
| prometheus-community/helm-charts | #7022 | Add Gateway API HTTPRoute support to the prometheus-json-exporter chart | ✅ Merged |
| padok-team/burrito | #927 | Add opt-in Gateway API HTTPRoute support to the Burrito Helm chart | ✅ Merged |
| pgadmin-org/pgadmin4 | #10095 | Add opt-in Gateway API HTTPRoute template to the pgAdmin Helm chart | ✅ Merged |
| apache/airflow | #68552 | Improve API server HTTPRoute config based on review feedback | ✅ Merged |
| firefly-iii/kubernetes | #117 | firefly-iii chart Gateway API HTTPRoute support | ✅ Merged |
| pajikos/home-assistant-helm-chart | #178 | Add Gateway API HTTPRoute support to the home-assistant Helm chart | ✅ Merged |
| apache/amoro | #4243 | Add Gateway API HTTPRoute support to the Amoro Helm chart | ✅ Merged |
| argoproj/argo-helm | #3914 | argo-rollouts dashboard Gateway API HTTPRoute support | ✅ Merged |
| open-telemetry/opentelemetry-helm-charts | #2246 | collector Gateway API HTTPRoute support | ✅ Merged |
| jaegertracing/helm-charts | #758 | Query UI HTTPRoute support | ✅ Merged |
| falcosecurity/charts | #1026 | falcosidekick HTTPRoute support | ✅ Merged |
| prometheus-community/helm-charts | #6961 | blackbox-exporter HTTPRoute support | ✅ Merged |
| apache/gravitino | #11308 | Gateway API HTTPRoute in Helm charts | ✅ Merged |
| prometheus-community/helm-charts | #6958 | alertmanager HTTPRoute support | ✅ Merged |
| apache/airflow | #67675 | Gateway API HTTPRoute for API server | ✅ Merged |
| nocodb/nocodb | #14272 | Add opt-in Gateway API HTTPRoute support to the Helm chart | 🔵 Review |
| community-charts/helm-charts | #537 | Opt-in Gateway API HTTPRoute for actualbudget chart | 🔵 Review |
| community-charts/helm-charts | #534 | Add opt-in Gateway API HTTPRoute support to the n8n Helm chart | 🔵 Review |
| community-charts/helm-charts | #533 | Opt-in Gateway API HTTPRoute for the MLflow chart, with hostnames auto-merged into the server security-middleware allowed-hosts/CORS | 🔵 Review |
| keephq/helm-charts | #198 | Add opt-in Gateway API HTTPRoute support to the Keep Helm chart (closes #183) | 🔵 Review |
| opensearch-project/opensearch-k8s-operator | #1441 | Add Gateway API HTTPRoute support to the opensearch-cluster Helm chart | 🔵 Review |
| prometheus-community/helm-charts | #7030 | Add Gateway API HTTPRoute support to the prometheus-yet-another-cloudwatch-exporter chart | 🔵 Review |
| prometheus-community/helm-charts | #7027 | Add Gateway API HTTPRoute support to the prometheus-couchdb-exporter chart | 🔵 Review |
| prometheus-community/helm-charts | #7026 | Add Gateway API HTTPRoute support to the prometheus-cloudwatch-exporter chart | 🔵 Review |
| prometheus-community/helm-charts | #7025 | Add Gateway API HTTPRoute support to the prometheus-statsd-exporter chart | 🔵 Review |
| Project | PR | Contribution | Status |
|---|---|---|---|
| lima-vm/lima | #5554 | Let the krunkit driver take over a disk lock left behind by the same instance, as vz and qemu already do, so an instance that stopped uncleanly can start again with its additional disks | ✅ Merged |
| pulumi/pulumi | #24939 | Take a file lock around the cleanup and clone or pull of the shared templates directory, so concurrent pulumi new runs no longer delete each other's in-progress clone or collide cloning into it |
✅ Merged |
| crowdsecurity/crowdsec | #4712 | Drop the Prometheus series of machines and bouncers deleted with cscli on the LAPI flush tick, so heartbeat alerts stop firing for clients that no longer exist | ✅ Merged |
| abiosoft/colima | #1642 | Recover from HTTP 416 when resuming a cached download so an interrupted colima start no longer fails until the cache is deleted |
✅ Merged |
| anchore/syft | #5321 | Fix a crash when cataloging ELF files with a truncated dynamic section by reading dynamic tags through debug/elf DynValue | ✅ Merged |
| falcosecurity/falcosidekick | #1446 | Close the syslog output connection after each event so every Falco alert no longer leaks a socket and file descriptor | ✅ Merged |
| fluent/fluent-operator | #2063 | Add autoExtractTimestamp to the Fluent Bit Splunk output CRD so Splunk extracts event timestamps via HEC auto_extract_timestamp | ✅ Merged |
| argoproj-labs/gitops-promoter | #2056 | Release the old Secret finalizer when an ScmProvider or ClusterScmProvider secretRef changes | ✅ Merged |
| nginx/nginx-gateway-fabric | #5953 | Fix a control plane panic on a BackendTLSPolicy with an empty caCertificateRefs list | ✅ Merged |
| oras-project/oras | #2174 | Drop an index's own child manifests from the referrers a registry without Referrers API support reports for it, so oras cp -r copies the root index instead of failing to tag it |
✅ Merged |
| projectcalico/calico | #13979 | Accept the full 4-byte AS number range (RFC 4893) in the BGPConfiguration, BGPPeer and BGPFilter CRD schemas | ✅ Merged |
| databus23/helm-diff | #1074 | Skip Helm hooks in the --take-ownership ownership check, so unchanged hooks stop showing up as ownership changes and a leftover test hook no longer fails the diff |
✅ Merged |
| kubevela/pkg | #140 | Stop the cuex function-call error from printing an empty path and leaking a cue/format failure in place of the value | ✅ Merged |
| kubernetes-sigs/external-dns | #6709 | Reduce ApplyChanges cyclomatic complexity in the Exoscale provider (26 to 6) | ✅ Merged |
| kubernetes-sigs/kwok | #1749 | Buffer net.Tunnel's copy-result channel so both goroutines can exit, instead of leaking up to two per interrupted kubectl exec / kubectl port-forward |
✅ Merged |
| zalando/skipper | #4201 | Add an optional response status condition to the logBody filter, so a request body can be logged only for failing responses | ✅ Merged |
| k3s-io/k3s | #14516 | Add advertise-address to SANs before generating apiserver cert | ✅ Merged |
| go-gitea/gitea | #38863 | Stream bundle downloads instead of writing a repo-sized temp file to disk first | ✅ Merged |
| tektoncd/pipeline | #10548 | Filter ResolutionRequests by the resolver's own label selector on leader promotion, so one resolver no longer fails requests owned by another | ✅ Merged |
| argoproj-labs/terraform-provider-argocd | #920 | Restore project role policy validation lost in the plugin-framework migration, sourcing the allowed resources from Argo CD's exported project-scoped set | ✅ Merged |
| reviewdog/action-shellcheck | #102 | Fix word-splitting so shell file paths containing spaces are linted instead of silently skipped | ✅ Merged |
| prometheus-operator/prometheus-operator | #8728 | Add spec.retentionPercentage to the Prometheus CRD for percentage-based TSDB retention (Prometheus >= v3.11.0) | ✅ Merged |
| kubernetes-sigs/kueue | #13428 | Automated cherry pick of #12797: Keep the sticky workload consistent during ClusterQueue heap and snapshot sorts | ✅ Merged |
| argoproj-labs/terraform-provider-argocd | #912 | Add gitea labels filter to the application_set pull_request generator | ✅ Merged |
| groundhog2k/helm-charts | #1521 | Add Prometheus metrics and ServiceMonitor support to the mongodb chart (mongodb_exporter sidecar) | ✅ Merged |
| clouddrove/smurf | #473 | Return a non-zero exit code when stf apply/destroy is declined at the approval prompt |
✅ Merged |
| terraform-redhat/terraform-provider-rhcs | #1273 | Drop the vestigial terraform-plugin-sdk/v2 direct dependency by reimplementing LogLevel() locally (adds first unit tests to the logging package) | ✅ Merged |
| external-secrets/external-secrets | #6675 | Add opt-in schedulerName and runtimeClassName to the Helm chart pods | ✅ Merged |
| element-hq/ess-helm | #1461 | Add schedulerName and runtimeClassName support to matrix-stack component workloads | ✅ Merged |
| kubernetes-sigs/kubespray | #13370 | cilium: wire the scrape port variables into the Helm values template so they stop being no-ops | ✅ Merged |
| rancher/dynamiclistener | #315 | Guard the queuedSecret field with a mutex to fix a data race in the Kubernetes storage controller | ✅ Merged |
| restatedev/sdk-go | #161 | Fix data race between Drain and concurrent Read on the request stream | ✅ Merged |
| kubernetes-sigs/kubebuilder | #5864 | Authenticate pinact with GITHUB_TOKEN in the workflow-lint CI job to avoid GitHub API rate limits (#5817) | ✅ Merged |
| open-telemetry/opentelemetry-helm-charts | #2299 | Add opt-in crds.annotations to the opentelemetry-operator chart so CRDs can carry helm.sh/resource-policy: keep and survive helm uninstall |
✅ Merged |
| temporalio/helm-charts | #949 | Add schedulerName/runtimeClassName/priorityClassName to Temporal server/web/admintools pods | ✅ Merged |
| terraform-google-modules/terraform-google-kubernetes-engine | #2617 | Fixed add_shadow_firewall_rules requiring add_cluster_firewall_rules (null cluster_subnet_cidr plan error) | ✅ Merged |
| element-hq/ess-helm | #1442 | Add affinity support to component workloads | ✅ Merged |
| stakater/Reloader | #1181 | Add runtimeClassName and schedulerName support to the Reloader Helm chart deployment | ✅ Merged |
| kubeshark/kubeshark | #1949 | Opt-in Prometheus Operator ServiceMonitor for the Helm chart's metrics services | ✅ Merged |
| open-telemetry/opentelemetry-go-contrib | #9238 | Fix otelslog dropping error attributes nested inside a slog.Group | ✅ Merged |
| apache/gravitino | #11917 | Add opt-in topologySpreadConstraints support to Gravitino/Iceberg-REST/Lance-REST Helm charts | ✅ Merged |
| open-feature/go-sdk | #522 | Guard memprovider Resolve against a non-nil pointer to a nil ContextEvaluator func (panic fix) | ✅ Merged |
| kubernetes-sigs/descheduler | #1892 | Added opt-in hostUsers (user-namespace sharing) to the descheduler Helm chart | ✅ Merged |
| terraform-docs/terraform-docs | #947 | Render explicit null variable defaults as null (not "") in tfvars hcl output | ✅ Merged |
| element-hq/ess-helm | #1438 | Add priorityClassName support to matrix-stack component workloads | ✅ Merged |
| kubernetes-sigs/kueue | #12797 | Fix non-transitive ClusterQueue sort when the sticky workload changes mid-sort | ✅ Merged |
| open-telemetry/opentelemetry-go-contrib | #9229 | Fix otelslog data race corrupting log attributes via shared kvBuffer (closes #9046) | ✅ Merged |
| valkey-io/valkey-helm | #218 | Add optional priorityClassName to the valkey-operator Deployment | ✅ Merged |
| kubernetes-sigs/kueue | #12796 | Fix data race on stickyWorkload between Snapshot and RequeueIfNotPresent | ✅ Merged |
| supabase-community/supabase-kubernetes | #214 | Add configurable Prometheus ServiceMonitor support to the Supabase Helm chart | ✅ Merged |
| ory/k8s | #888 | Completed the PodDisruptionBudget namespace fix across the remaining Ory Helm charts (kratos, hydra-maester, oathkeeper-maester) | ✅ Merged |
| valkey-io/valkey-helm | #217 | Add configurable health probes (startup/liveness/readiness) to the Valkey chart | ✅ Merged |
| kubernetes-sigs/kueue | #12736 | Fixed a data race on the ClusterQueue sticky workload between the Visibility API snapshot and preemption requeue (self-synchronizing mutex). | ✅ Merged |
| guerzon/vaultwarden | #234 | Add opt-in topologySpreadConstraints to the vaultwarden Helm chart pod spec | ✅ Merged |
| kubernetes-sigs/descheduler | #1890 | Add opt-in schedulerName and runtimeClassName to the descheduler Helm chart | ✅ Merged |
| elastic/docs-content | #7182 | Documented EKS Pod Identity setup for the S3 snapshot repository | ✅ Merged |
| inference-gateway/cli | #713 | Guard Tree tool gitignore cache and screenshot rate-limit against concurrent-map data races | ✅ Merged |
| istio/istio | #60723 | Add terminationGracePeriodSeconds option to the istiod Helm chart | ✅ Merged |
| terraform-aws-modules/terraform-aws-eks | #3726 | Fix the FAQ example so case 2 sets attach_cluster_primary_security_group = false (the two opposite remedies previously showed the same example); fixes #3724 |
✅ Merged |
| valkey-io/valkey-helm | #197 | Add aggregated admin/editor/viewer ClusterRoles to the valkey-operator chart | ✅ Merged |
| valkey-io/valkey-helm | #196 | Add optional Prometheus ServiceMonitor to the valkey-operator chart | ✅ Merged |
| actions-rust-lang/setup-rust-toolchain | #96 | Add cache-targets passthrough to rust-cache | ✅ Merged |
| redpanda-data/helm-charts | #1756 | kminion chart: add opt-in extraEnvFrom for Secret/ConfigMap env injection (Deployment + DaemonSet) | ✅ Merged |
| metallb/metallb | #3079 | Avoid stale resourceVersion errors in ServiceL2Status and ServiceBGPStatus reconcile | ✅ Merged |
| valkey-io/valkey-helm | #195 | Add optional topologySpreadConstraints to the valkey-operator chart Deployment | ✅ Merged |
| VictoriaMetrics/helm-charts | #3016 | Add runtimeClassName option to pod specs across all VictoriaMetrics charts | ✅ Merged |
| woodpecker-ci/helm | #498 | Add topologySpreadConstraints to the Woodpecker server (parity with the agent) | ✅ Merged |
| argoproj/argo-helm | #3943 | Add envFrom to the argo-workflows controller and argo-server containers | ✅ Merged |
| goauthentik/helm | #483 | Add server.automountServiceAccountToken to the authentik Helm chart (server-pod parity with the worker setting) | ✅ Merged |
| kubernetes-sigs/headlamp | #6148 | Replace the any return type of KubeObject.apiList with a typed value in the Headlamp Kubernetes dashboard frontend |
✅ Merged |
| redpanda-data/helm-charts | #1754 | Add opt-in topologySpreadConstraints to the kminion Helm chart (Deployment and DaemonSet) | ✅ Merged |
| kubernetes-sigs/descheduler | #1885 | Add an opt-in PodDisruptionBudget to the descheduler Helm chart (Deployment mode) | ✅ Merged |
| longhorn/longhorn | #13378 | Add an opt-in PodDisruptionBudget to the Longhorn UI Deployment in the Helm chart | ✅ Merged |
| kedacore/charts | #881 | Make the KEDA operator gRPC metrics service port configurable (#511) | ✅ Merged |
| anchore/grype | #3519 | Add vulnerable version ranges to the CycloneDX output format (closes #3512) | ✅ Merged |
| amacneil/dbmate | #803 | Add --wait-interval flag and DBMATE_WAIT_INTERVAL env var to configure the delay between connection attempts for --wait |
✅ Merged |
| metallb/metallb | #3076 | Remove deprecated metallb.universe.tf managed annotation lingering on Services after upgrade | ✅ Merged |
| fluent/fluentd | #5390 | Add umask option to the directive | ✅ Merged |
| kudobuilder/kuttl | #694 | Fix flaky integration test by randomizing namespace (prevents -count collision) | ✅ Merged |
| kedacore/charts | #880 | Add an opt-in hostUsers field to the KEDA operator, metrics server and webhooks pods (user namespaces) | ✅ Merged |
| stern/stern | #373 | Support nested-field extraction via dot notation in extractJSONParts/tryExtractJSONParts template funcs (closes #343) | ✅ Merged |
| jenkins-infra/helm-charts | #1972 | Add an opt-in PodDisruptionBudget to the httpd Helm chart | ✅ Merged |
| vmware-tanzu/helm-charts | #740 | Add optional PodDisruptionBudget to the Velero Helm chart | ✅ Merged |
| pypa/pipx | #1842 | Add --dry-run flag to pipx ensurepath to preview PATH changes without modifying any shell config |
✅ Merged |
| open-telemetry/opentelemetry-collector-contrib | #49146 | Add opt-in TLS support to the memcached receiver | ✅ Merged |
| elastic/elasticsearch | #151614 | S3 snapshot repository: EKS Pod Identity credential support | ✅ Merged |
| mindersec/minder | #6520 | Resolve OCI artifact created time from the image config instead of the time.Now() fallback (closes #6490) | ✅ Merged |
| open-policy-agent/conftest | #1355 | Add --github-hide-passed flag to skip passing files in the GitHub outputter (closes #1315) |
✅ Merged |
| dragonflydb/dragonfly-operator | #550 | Add optional PodDisruptionBudget to the operator Helm chart | ✅ Merged |
| external-secrets/external-secrets | #6481 | Scoped External Secrets Operator cert-controller ClusterRole to least-privilege (resourceNames-pinned write access) in the Helm chart | ✅ Merged |
| opentofu/setup-opentofu | #121 | Verify the downloaded OpenTofu CLI against the release's published SHA256SUMS by default (closes #117) | ✅ Merged |
| open-telemetry/opentelemetry-helm-charts | #2258 | Honor schedulerName in daemonset and statefulset collector modes | ✅ Merged |
| vectordotdev/vector | #25607 | Add a host_metrics temperature collector via sysinfo Components | ✅ Merged |
| jaegertracing/helm-charts | #761 | Restore extraVolumes/extraVolumeMounts on the all-in-one deployment | ✅ Merged |
| helm/chart-testing-action | #210 | Report a clear error when blob verification fails | ✅ Merged |
| nginx/nginx-gateway-fabric | #5392 | Add GEP-713 Programmed status condition to custom policies | ✅ Merged |
| helm/chart-testing | #841 | Honor --release-name instead of generating one |
✅ Merged |
| yannh/kubeconform | #356 | Avoid SIGSEGV panic on null-decoding schema | ✅ Merged |
| meshery/meshery | #19835 | Fix typos, function names & license header | ✅ Merged |
| pulumi/pulumi | #24995 | Redact secret values as [secret] in invalid input diagnostics unless --show-secrets is passed, so a provider Check failure, the pulumi import warning or a Construct or Call input error no longer prints them in plaintext |
🔵 Review |
| wailsapp/wails | #6212 | Mark dependencies that only the local check finds as installed in the v2 wails doctor on Linux, so npm is no longer reported missing when the package manager does not list it, for example in a container image with the apt lists removed |
🔵 Review |
| goss-org/goss | #1136 | Stop a not around an or from panicking when no child matched, so a missing gjson path or an erroring child such as have-key against a string reports the failure instead of crashing goss |
🔵 Review |
| hashicorp/packer | #13716 | Keep PACKER_GITHUB_API_TOKEN on redirected requests, so installing a plugin whose GitHub repository was renamed or transferred no longer falls back to the anonymous rate limit and blocks the plugins installed after it |
🔵 Review |
| pulumi/pulumi | #24986 | Fall back to the unprefixed version tag when a Git-sourced plugin has no v tag, so pulumi package and pulumi plugin install can download plugins from repositories that tag releases as plain 1.0.0 |
🔵 Review |
| distribution/distribution | #4995 | Return 400 NAME_INVALID instead of 500 UNKNOWN for repository names longer than 255 characters, and stop the registry dispatcher's early returns from writing the error response twice | 🔵 Review |
| git-lfs/git-lfs | #6356 | Pass <transport>://<address> remote helper URLs through unchanged, as Git does, instead of misreading them as SSH endpoints for a host named after the transport |
🔵 Review |
| trufflesecurity/trufflehog | #5378 | Strip the calling hook's repo-local Git variables from the git clone TruffleHog runs, so a pre-commit hook running trufflehog git file://. no longer turns git commit -a into an empty commit |
🔵 Review |
| go-gitea/gitea | #39519 | Stable repo list pagination with an id tiebreaker | 🔵 Review |
| photoprism/photoprism | #5872 | Pass OpenAI-compatible model IDs through unchanged, so a colon in the ID (a GGUF quant suffix or an ft: fine-tune) is no longer read as a version separator and cut off before the request |
🔵 Review |
| tailscale/tailscale | #21526 | Reject a tailscale set --relay-server-port value that magicsock is already bound to, so the edit fails with an error instead of leaving a peer relay that silently never starts |
🔵 Review |
| rclone/rclone | #10000 | Shut down the rc and metrics servers in the parent before rclone mount --daemon daemonizes, so the daemon child can bind the same --rc address instead of exiting with address already in use |
🔵 Review |
| slackhq/nebula | #1902 | Parse tun.unsafe_routes mtu, metric and gateway weight like install, so quoted values are honored and float, bool or empty ones no longer panic, also on SIGHUP reload |
🔵 Review |
| getsops/sops | #2305 | Skip files that match no destination rule in sops publish --recursive instead of aborting the walk, and give empty or invalid destination rules their own error |
🔵 Review |
| grpc-ecosystem/grpc-gateway | #7419 | Normalize CRLF line endings in proto comments so both OpenAPI generators split the summary from the description instead of making the whole comment the summary | 🔵 Review |
| grafana/loki | #24775 | Stop counting a compaction run canceled by shutdown or compactor handover as a failure in the compaction and retention operation metrics | 🔵 Review |
| prometheus-community/helm-charts | #7310 | Point the couchdb-exporter probes at /status, since image v28 answers / with 404 and the pod never became ready | 🔵 Review |
| kubernetes-sigs/kustomize | #6287 | Stop kustomize edit from duplicating # lines inside YAML block scalars by tracking block scalar indentation |
🔵 Review |
| dapr/cli | #1710 | Send the DAPR_API_TOKEN header on workflow gRPC calls so list, history, purge and rerun work against token-secured sidecars | 🔵 Review |
| kubernetes-csi/external-snapshotter | #1489 | csi-snapshotter: stop the sidecar's own VolumeGroupSnapshotContent writes from bypassing the requeue backoff and flooding the driver with CreateVolumeGroupSnapshot calls | 🔵 Review |
| zalando/postgres-operator | #3189 | Delete cluster services with background propagation so the replica service's EndpointSlices are not orphaned | 🔵 Review |
| istio/istio | #61851 | Honor verifyCertificateHash and verifyCertificateSpki on file-mounted Gateway and Sidecar server certs | 🔵 Review |
| open-telemetry/opentelemetry-operator | #5628 | Add imagePullSecrets to the OpenTelemetryCollector and TargetAllocator CRs so their pods can pull images from private registries | 🔵 Review |
| nginx/nginx-gateway-fabric | #5951 | Remove BackendTLSPolicy validation already enforced by the Gateway API CRD schema and CEL rules | 🔵 Review |
| antrea-io/antrea | #8436 | Escape user-supplied L7 NetworkPolicy host / path / sni patterns in generated Suricata rules, so a quote or semicolon can no longer close content: early and inject extra rule keywords |
🔵 Review |
| woodpecker-ci/woodpecker | #7158 | Wait for the pod informer's cache sync before WaitStep's deleted-pod guard in the Kubernetes backend, so a service pod deleted at teardown no longer hangs the workflow until its timeout | 🔵 Review |
| mariadb-operator/mariadb-operator | #1907 | Enforce the PhysicalBackup timeout through the Job's activeDeadlineSeconds so timed out backups are reported as failed instead of Success, and never bootstrap replicas from a failed backup |
🔵 Review |
| k8ssandra/k8ssandra-operator | #1795 | Use a non-controller owner reference for telemetry ServiceMonitors so they can be created on OpenShift without cassandradatacenters/finalizers RBAC |
🔵 Review |
| rancher/cluster-api-provider-rke2 | #1047 | Keep the node's configured SELinux mode during Ignition bootstrap instead of forcing enforcing after setenforce 0, so permissive nodes (Flatcar default) stay permissive |
🔵 Review |
| tektoncd/cli | #3245 | Make tkn task/pipeline sign add only the signature annotation instead of rewriting the whole YAML document (also stops the invalid resources: {} injection) | 🔵 Review |
| cert-manager/cert-manager | #9353 | Fail over to the next configured DNS server when an ACME HTTP-01 self-check nameserver does not respond | 🔵 Review |
| cilium/cilium | #48540 | gateway-api: stop the X-Forwarded-Proto guard from silently disabling an HTTPRoute RequestRedirect whose scheme matches the listener | 🔵 Review |
| cert-manager/cert-manager | #9305 | Reject Certificate renewal windows that can never be reached within the certificate lifetime, in the admission webhook | 🔵 Review |
| containerd/nerdctl | #5174 | Only mark a container explicitly stopped when the signal actually stops it, so nerdctl kill --signal=HUP no longer disables a --restart=always policy |
🔵 Review |
| kubernetes-csi/external-resizer | #610 | csi-resizer: report a VolumeAttributesClass the driver cannot apply as an event on the PVC, instead of silently ignoring it | 🔵 Review |
| envoyproxy/gateway | #9860 | Fix the always-zero watchable_depth control-plane gauge by recording the coalesced update backlog | 🔵 Review |
| terraform-docs/terraform-docs | #955 | Link built-in provider resources (terraform_data, terraform_remote_state) to the Terraform language docs instead of a dead registry URL | 🔵 Review |
| opencost/opencost | #4002 | Cost native sidecar containers (restartPolicy: Always init containers) instead of omitting them from pod cost | 🔵 Review |
| external-secrets/external-secrets | #6830 | Oracle provider: return NoSecretErr on a missing vault secret so ExternalSecret deletionPolicy applies | 🔵 Review |
| argoproj/argo-workflows | #16610 | Add preferred type to retry nodeAntiAffinity. Fixes #13969 | 🔵 Review |
| actions/stale | #1357 | Add opt-in exempt-issues-with-open-linked-pr so issues with a closing PR aren't marked stale | 🔵 Review |
| dorny/paths-filter | #323 | Scope the merge-base commit count to the base and head refs so a broken unrelated ref cannot fail the job | 🔵 Review |
| gruntwork-io/terragrunt | #6572 | Add overwrite_terragrunt_or_skip value for generate block if_exists, gated behind an experiment | 🔵 Review |
| prometheus-operator/prometheus-operator | #8729 | Add httpHeaders field to ServiceMonitor and PodMonitor endpoints for custom scrape HTTP headers (Prometheus >= 2.55.0) | 🔵 Review |
| aws/karpenter-provider-aws | #9454 | Surface EC2 request rejections (e.g. InvalidBlockDeviceMapping) on the EC2NodeClass validation condition instead of retrying them as authorization errors | 🔵 Review |
| integrations/terraform-provider-github | #3570 | Include explicitly-configured false booleans on github_organization_settings create (fixes GetOk false/unset ambiguity) | 🔵 Review |
| terraform-aws-modules/terraform-aws-wafv2 | #10 | Fix ip_set_forwarded_ip_config being dropped in nested WAFv2 statement blocks | 🔵 Review |
| keephq/helm-charts | #199 | Add opt-in PodDisruptionBudget support for HA components (backend/frontend/websocket) to the Keep Helm chart | 🔵 Review |
| carvel-dev/kapp-controller | #1844 | Fix concurrent map iteration/write panic in AppRefTracker under high reconciliation concurrency | 🔵 Review |
| prometheus-community/helm-charts | #7108 | prometheus-adapter chart: add optional schedulerName and runtimeClassName to the Deployment | 🔵 Review |
| anchore/scan-action | #726 | Add glob pattern support to the scan-action sbom input (expands to exactly one SBOM file) |
🔵 Review |
| terraform-google-modules/terraform-google-composer | #203 | Fixed cloud_data_lineage_integration=false being a no-op (nullable var so it can be explicitly disabled) | 🔵 Review |
| terraform-aws-modules/terraform-aws-dynamodb-table | #123 | Add opt-in standalone GSI management (aws_dynamodb_global_secondary_index) for independent index lifecycle | 🔵 Review |
| argoproj/argo-cd | #28584 | Add skip schema validation toggle to Application parameters editor (#5111) | 🔵 Review |
| terraform-aws-modules/terraform-aws-lambda | #762 | Clarify lambda_role is ignored when create_role is true (docs) | 🔵 Review |
| kyverno/kyverno | #16428 | Add opt-in schedulerName and runtimeClassName to the Kyverno controller Helm chart | 🔵 Review |
| fyrash/fyra-cli | #1 | Warn when secret files are excluded from the push | 🔵 Review |
| terraform-aws-modules/terraform-aws-eventbridge | #203 | Gate the EventBridge log delivery source on configured log delivery (fixes orphan aws_cloudwatch_log_delivery_source); fixes #201 | 🔵 Review |
| terraform-aws-modules/terraform-aws-msk-kafka-cluster | #69 | Restore broker log delivery for MSK Express brokers | 🔵 Review |
| terraform-aws-modules/terraform-aws-iam | #651 | Add opt-in ebs_csi_volume_tagging variable so the EBS CSI driver can tag existing volumes (enables VolumeAttributesClass); fixes #649 |
🔵 Review |
| argoproj/argo-cd | #28406 | Persist Applications search bar text across navigation (view preferences) | 🔵 Review |
| kubereboot/charts | #141 | Add opt-in topologySpreadConstraints to the kured chart DaemonSet | 🔵 Review |
| kedacore/charts | #882 | Per-component Deployment labels/annotations for KEDA pods | 🔵 Review |
| ray-project/kuberay | #4934 | Add optional PodDisruptionBudget to the ray-cluster Helm chart | 🔵 Review |
| vapor/vapor | #3475 | Add typed Retry-After HTTP header accessor | 🔵 Review |
| tj-actions/changed-files | #2884 | Hardened README to recommend injection-safe consumption of the changed-files list (JSON + bash array + -- separator). |
🔵 Review |
| dexidp/dex | #4831 | Add EdDSA (Ed25519) signing algorithm support to the local token signer | 🔵 Review |
| hashicorp/setup-terraform | #561 | Verify the downloaded Terraform CLI against HashiCorp's signed SHA256SUMS before install (closes #556) | 🔵 Review |
| hashicorp/terraform-provider-kubernetes | #2905 | Add env_from_map provider-defined function |
🔵 Review |
| percona/percona-helm-charts | #862 | pmm gRPC ClusterIP nodePort fix | 🔵 Review |
| meshery/meshery | #19866 | Fix export flag validation + tests | 🔵 Review |
| dependabot/dependabot-core | #15199 | Identify Dependabot commits by author name | 🔵 Review |
| aquasecurity/trivy | #10770 | Add --color flag for table output |
🔵 Review |
| Project | PR | Contribution | Status |
|---|---|---|---|
| fluxcd/flux2 | #5975 | Add opt-in version-file input to the Flux CLI GitHub Action | ✅ Merged |
| opentofu/setup-opentofu | #131 | Support asdf .tool-versions format in the tofu_version_file input |
✅ Merged |
| buildpacks/github-actions | #428 | Add pack-version-file input and default-on SHA256 download verification to the setup-pack action | ✅ Merged |
| yokawasa/action-setup-kube-tools | #98 | Add a version-file (.tool-versions) input to pin tool versions from a file | ✅ Merged |
| astral-sh/setup-uv | #918 | Add uv.lock as a version-file source so the exact pinned uv version is installed for deterministic CI |
✅ Merged |
| helm/kind-action | #162 | Add version_file input to load the kind version from an asdf .tool-versions or plain version file | ✅ Merged |
| terraform-linters/setup-tflint | #448 | Add a tflint_version_file input to pin the TFLint version from an asdf/mise .tool-versions or plain version file |
✅ Merged |
| astral-sh/ruff-action | #379 | Add uv.lock as a supported version-file format |
✅ Merged |
| Azure/setup-helm | #281 | Add version-file input to read the Helm version from a .tool-versions file |
✅ Merged |
| denoland/setup-deno | #133 | Parse dvm's key=value .dvmrc format in the deno-version-file input | 🔵 Review |
| aquasecurity/setup-trivy | #39 | Add a version-file input to read the Trivy version from a .tool-versions / plain version file |
🔵 Review |
| hashicorp/setup-packer | #177 | Add version-file input to read the Packer version from a .tool-versions file |
🔵 Review |
| extractions/setup-just | #29 | Add just-version-file input to resolve the version from a .tool-versions/plain file |
🔵 Review |
| actions/setup-dotnet | #743 | Add dotnet-version-file input — read the .NET SDK version from a .tool-versions / global.json file (closes #459) |
🔵 Review |
| Project | PR | Contribution | Status |
|---|---|---|---|
| nginx/nginx-gateway-fabric | #5491 | Simplify registerSecretInGatewayConfig to reduce cyclomatic complexity | ✅ Merged |
| nginx/nginx-gateway-fabric | #5480 | Refactor createHTTPFilters to remove gocyclo nolint | ✅ Merged |
| nginx/nginx-gateway-fabric | #5461 | Reduce cyclomatic complexity of the provisioner store's Gateway-resource lookup | ✅ Merged |
| nginx/nginx-gateway-fabric | #5455 | Extract parent ref resolution from bindL7RouteToListeners to remove the gocyclo lint exception | ✅ Merged |
| nginx/nginx-gateway-fabric | #5454 | Simplify getResourceVersionForObject by extracting a name-match helper to remove the gocyclo lint exception | ✅ Merged |
| nginx/nginx-gateway-fabric | #5453 | Simplify registerResourceInGatewayConfig by extracting a get-or-create helper to remove the gocyclo lint exception | ✅ Merged |
| nginx/nginx-gateway-fabric | #5452 | Refactor provisionNginx to remove the gocyclo lint exception by decomposing it into focused helpers | ✅ Merged |
| nginx/nginx-gateway-fabric | #5441 | Refactor addBackendRefsToRules into helpers to drop the gocyclo nolint (#5253) | ✅ Merged |
| nginx/nginx-gateway-fabric | #5440 | Refactor secret deprovisioning to remove gocyclo lint debt (#5253) | ✅ Merged |
| nginx/nginx-gateway-fabric | #5439 | Refactor TLS certificate reference resolver to reduce cyclomatic complexity (gocyclo tech-debt slice of #5253) | ✅ Merged |
| nginx/nginx-gateway-fabric | #5438 | Refactor listener port-conflict resolver to remove a gocyclo exception | ✅ Merged |
| Project | PR | Contribution | Status |
|---|---|---|---|
| losisin/helm-values-schema-json | #360 | Add nullable schema annotation | ✅ Merged |
| losisin/helm-values-schema-json | #359 | Add --bundle-cache-min flag to override min schema cache duration |
✅ Merged |
| losisin/helm-values-schema-json | #357 | Deduplicate bundle flag registration via shared helper | ✅ Merged |
| losisin/helm-values-schema-json | #355 | Add lint subcommand |
✅ Merged |
| losisin/helm-values-schema-json | #354 | Add bundle subcommand |
✅ Merged |
| losisin/helm-values-schema-json | #365 | Add shorthand for the const and default schema annotations to reuse the field's own YAML value | 🔵 Review |
| Project | PR | Contribution | Status |
|---|---|---|---|
| getmoto/moto | #10068 | Omit unset optional fields from Transfer describe responses | ✅ Merged |
| getmoto/moto | #10067 | Add Kinesis Firehose Iceberg destination support | ✅ Merged |
| getmoto/moto | #10065 | Add AppMesh VirtualGateway and GatewayRoute API support | ✅ Merged |
| getmoto/moto | #10062 | Add EC2 snapshot tiering APIs (archive / describe-status / restore) | ✅ Merged |




