Skip to content

[repo-status] Daily Status Report – June 2, 2026Β #13323

@github-actions

Description

@github-actions

🌟 Apache CloudStack – Daily Status Report

Generated: June 2, 2026


πŸš€ Recent Releases

Release Date Type
4.22.1.0 (LTS) May 26, 2026 Maintenance
4.22.0.1 (LTS Security) May 8, 2026 Security (7 CVEs patched)
4.20.3.0 (LTS) Apr 17, 2026 Maintenance

Great momentum with two LTS releases shipped in the past month! πŸŽ‰


πŸ”€ Pull Request Activity

βœ… Recently Merged

  • #13210 – Convert command's timeout for snapshots commands (erikbocks)
  • #13278 – Update GitHub AW actions (vishesh92)
  • #13215 – Bump GitHub Actions dependencies (dependabot)
  • #13050 – FlashArray: fall back to array capacity when pod has no quota (genegr)
  • #13238 – Docs: note MariaDB support in README (robertsilen)
  • #13078 – fix(linstor): surface ambiguous template fallbacks and legacy orphan cleanup (jmsperu)
  • #13021 – Fix the validation of CPVMs states in multiple zones (Tonitzpp)

πŸ”₯ Hot PRs (Active Today)

  • #13322 – Deduplicate Sonar CI GitHub workflow (Pearl1594)
  • #13321 – UI support for the scaleSystemVm API (gruckbit)
  • #13320 – Stop role from auto-changing on manual account creation (gp-santos)
  • #13319 – Fix KVM live volume migration command payload (vanquyen020920)
  • #13293 – Add draft project security threat-model document (potiuk)
  • #13236 – Introduce Quota resource statement API (winterhazel)
  • #13140 – Add code coverage grading workflow (Pearl1594)

πŸ—οΈ Big Features In Progress

  • #12711 – πŸ”‘ Key Management Service (KMS) (vishesh92)
  • #13033 – πŸ” Keycloak OAuth provider (tazouxme)
  • #12991 – πŸ’Ύ Backup: Veeam KVM integration (shwstppr)
  • #12758 – πŸ“¦ New backup provider: KBOSS (JoaoJandre)
  • #13032 – 🌐 Network Extension: Orchestrate external network devices (weizhouapache)
  • #13015 – πŸ—‘οΈ Soft delete for port forwarding, load balancing & firewall rules (bernardodemarco)
  • #12124 – Dell EMC ECS Object Storage plugin (mhkadhum)

πŸ›‘οΈ Security Watch

A wave of security vulnerability reports has been filed (#13296–#13311), covering:

  • Plaintext credential exposure in IPMI, SSH, CIFS, and KVM helpers
  • Keystore/SSL private key exposure in logs
  • VM user-data and VNC password leaks in various subsystems

⚠️ Maintainers: These reports need triage and prioritization. Many appear to be part of a coordinated responsible disclosure effort β€” consider batching fixes in an upcoming security release.


πŸ“Š Project Highlights

  • πŸ”§ CI/CD improvements active (Sonar deduplication, code coverage grading)
  • πŸ“ Security threat model document being drafted β€” great proactive step!
  • πŸ”Œ Plugin ecosystem expanding: KMS, Keycloak OAuth, Veeam, KBOSS, Dell EMC ECS β€” the integrations pipeline is vibrant

βœ… Recommended Next Steps

  1. Triage the new security vulnerability reports (#13296–#13311) β€” assign owners and set target milestones
  2. Review and merge the KVM live migration fix (#13319) β€” appears to be a straightforward bugfix
  3. Progress the security threat model (#13293) β€” community input welcome
  4. Code coverage workflow (#13140) β€” valuable for long-term quality; encourage review
  5. Plan 4.22.2.0 / 4.20.4.0 cadence given the active security report backlog

Keep up the great work, contributors! πŸ’ͺ The project is active, healthy, and growing fast.

Generated by Repo Status Β· sonnet46 558.1K Β· β—·

Add this agentic workflows to your repo

To install this agentic workflow, run

gh aw add githubnext/agentics/workflows/repo-status.md@main

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions