Purpose
A pass over the current 23 open issues and 13 open PRs in cncf/endusers to flag likely duplicates/overlaps, propose consolidations, and set a priority and merge order. All PR numbers/CI states below were verified live via gh pr view/gh issue view at time of writing. No hold-labeled item was merged or modified as part of this triage (per GOVERNANCE.md).
Overlaps and duplicate candidates
Strengthen the static/ asset security gate: discover directories dynamically and block external references in SVGs #754 vs [sec-check] SVG active-content gate does not flag remote resource references, so an imported diagram can hot-link a third-party host #774 /fix(security): gate remote resource references in imported SVG diagrams #775 (PR) — Strengthen the static/ asset security gate: discover directories dynamically and block external references in SVGs #754 ("Strengthen the static/ asset security gate") explicitly consolidates [sec-check] static/ security gate covers a hardcoded directory list, so a new static/ subdirectory is ungated with no CI signal #697 and [sec-check] SVG gate has no external-reference check: an imported diagram can hot-link a third-party host from the site origin #745 , and one of its two goals — "extend the SVG gate to reject external URL references" — is the same fix PR fix(security): gate remote resource references in imported SVG diagrams #775 delivers for [sec-check] SVG active-content gate does not flag remote resource references, so an imported diagram can hot-link a third-party host #774 . Once fix(security): gate remote resource references in imported SVG diagrams #775 merges, Strengthen the static/ asset security gate: discover directories dynamically and block external references in SVGs #754 should be narrowed to only its remaining goal (dynamic discovery of static/ subdirectories) or split into a new, smaller issue so it isn't left describing already-shipped work.
Automation workflows must validate and format what they generate before committing #755 vs PR test: guard regenerate-format-validate-test ordering for data-generating automation jobs #758 — PR test: guard regenerate-format-validate-test ordering for data-generating automation jobs #758 adds a contract test that guards the "regenerate → format → validate → test" ordering Automation workflows must validate and format what they generate before committing #755 asks for, it does not reorder the four automation workflows ([quality] Import job never runs check:format, so every architecture import PR carries 16 unformatted files #713 , [sec-check] refresh-community-people.yml commits third-party profile data without running validate:community-people #736 , [quality] automation workflows run test:unit before regenerating the data it guards #738 , [sec-check] deploy-gh-pages.yml publishes after running only 4 of 10 data validators #740 ) that Automation workflows must validate and format what they generate before committing #755 is about. Merging test: guard regenerate-format-validate-test ordering for data-generating automation jobs #758 will make CI red for those workflows (that's the point — it turns the gap into a visible failure) but must not be read as closing Automation workflows must validate and format what they generate before committing #755 ; the actual workflow-ordering fix is still unwritten.
[ci-maintainer] Automated import PRs run no CI: GITHUB_TOKEN-created PRs do not trigger pull_request workflows #721 vs chore: refresh community profiles #763 / chore: import latest reference architectures #681 (PRs) — [ci-maintainer] Automated import PRs run no CI: GITHUB_TOKEN-created PRs do not trigger pull_request workflows #721 ("Automated import PRs run no CI") is not theoretical: both open automation PRs (chore: refresh community profiles #763 refresh-community-people, chore: import latest reference architectures #681 import-architectures) are currently mergeStateStatus: BLOCKED because branch protection is waiting on a Validate repository check that GITHUB_TOKEN-authored PRs never trigger. These two PRs are live evidence for [ci-maintainer] Automated import PRs run no CI: GITHUB_TOKEN-created PRs do not trigger pull_request workflows #721 and are stuck until it's fixed (or a maintainer manually re-runs/approves).
[quality] site search indexes only the blog: docsRouteBasePath default does not match docs routeBasePath #769 vs PR test: cover the local site search end to end #771 — [quality] /search and the local search index have no end-to-end coverage #770 (search e2e coverage, closed by PR test: cover the local site search end to end #771 ) and [quality] site search indexes only the blog: docsRouteBasePath default does not match docs routeBasePath #769 (site search indexes only the blog, a real product bug) were discovered together. Confirm whether test: cover the local site search end to end #771 's new spec asserts today's broken behavior (docs pages missing from the index) — if so it will need a follow-up once [quality] site search indexes only the blog: docsRouteBasePath default does not match docs routeBasePath #769 lands, or should be written against the fixed behavior with [quality] site search indexes only the blog: docsRouteBasePath default does not match docs routeBasePath #769 as a blocking dependency.
[quality] Two unreachable defensive sub-expressions permanently cap source region coverage #700 references PRs test(import-architectures): cover the seven uncovered sub-line regions #678 , test(svg-active-content): cover single-quoted and unquoted attribute values #680 , test(fetch-community-people): cover the four uncovered sub-line regions #686 , test(validators): cover the seven uncovered fallback-label regions #688 , test(collectors): cover the six uncovered sub-line fallback regions #693 as already covering every other uncovered source region. All five of those branches now have closed (not merged) PRs — the closures were part of today's branch cleanup. [quality] Two unreachable defensive sub-expressions permanently cap source region coverage #700 needs re-verification: the coverage gaps it defers to may no longer be closed by anything, so its "these two are the only remainder" claim should be re-checked before anyone assumes the two named sub-expressions are truly the only gap left.
Consolidation candidates
Documentation cluster : [guide] CONTRIBUTING says data/projects-born.json has no validation script — validate:projects-born now exists and gates CI #776 , [guide] E2E suite is invisible to contributors: no doc mentions test:e2e, the build prerequisite, or Playwright browser install #764 , [guide] AGENTS.md intro claims the site is hosted at endusers.cncf.io — domain is a pending DNS cutover, actual deploy is cncf.github.io/endusers #757 , [guide] Coverage gate undocumented: CI runs test:unit:coverage:check (97%/99% thresholds) but docs tell contributors to run test:unit #682 are all small, independent inaccuracies in CONTRIBUTING.md/AGENTS.md (stale validator claims, missing e2e mention, wrong hosting domain, wrong coverage command). None has a PR yet. Recommend one combined "docs accuracy sweep" PR/issue instead of four separate small diffs to the same two files — reduces review overhead and merge-conflict risk from touching CONTRIBUTING.md four times in parallel.
E2E coverage initiative : [quality] Awards timeline has no end-to-end coverage beyond a year-badge count #781 /test: cover the awards timeline end to end #782 , [quality] Blog routes have no end-to-end coverage: /blog, post permalinks, tag and author pages, and the RSS/Atom feeds #779 /test: cover the blog routes end to end #780 , [quality] /metrics has no end-to-end coverage for its browser-only behaviour (bar widths, disclosure, SVG geometry) #777 /test: cover the metrics dashboard end to end #778 , [quality] No end-to-end coverage for the case-studies filter toolbar (src/components/CaseStudies) #772 /test: cover the case studies filter toolbar end to end #773 , [quality] /search and the local search index have no end-to-end coverage #770 /test: cover the local site search end to end #771 , [quality] Primary navbar has no end-to-end coverage #765 /test: cover the primary navbar end to end #766 , [quality] src/theme/Footer/index.js renders on every route with zero end-to-end coverage #761 /test: cover the site footer end to end #762 , [quality] Reference architecture detail pages have no end-to-end coverage #759 /test: cover reference architecture detail pages end to end #760 are eight instances of the same pattern (route/component has no e2e coverage → add a Playwright spec). Each PR claims disjoint files and all are green/CLEAN, so they don't need to be merged as one PR, but they should be tracked as one initiative and gated on [quality] Playwright e2e suite is never run in CI — tests/e2e/smoke.spec.js has no workflow #672 (see below) rather than reviewed as eight unrelated PRs.
Priority triage
P0 — correctness/security, blocking, no PR yet
P1 — ready to merge (green CI, hold-gated, awaiting maintainer review)
P1 — infra prerequisite for the e2e initiative, no PR yet
P2 — ready to merge (green CI, hold-gated), gate on #672 landing first
test: cover the awards timeline end to end #782 (closes [quality] Awards timeline has no end-to-end coverage beyond a year-badge count #781 ), test: cover the blog routes end to end #780 (closes [quality] Blog routes have no end-to-end coverage: /blog, post permalinks, tag and author pages, and the RSS/Atom feeds #779 ), test: cover the metrics dashboard end to end #778 (closes [quality] /metrics has no end-to-end coverage for its browser-only behaviour (bar widths, disclosure, SVG geometry) #777 ), test: cover the case studies filter toolbar end to end #773 (closes [quality] No end-to-end coverage for the case-studies filter toolbar (src/components/CaseStudies) #772 ), test: cover the local site search end to end #771 (closes [quality] /search and the local search index have no end-to-end coverage #770 , coordinate with [quality] site search indexes only the blog: docsRouteBasePath default does not match docs routeBasePath #769 ), test: cover the primary navbar end to end #766 (closes [quality] Primary navbar has no end-to-end coverage #765 ), test: cover the site footer end to end #762 (closes [quality] src/theme/Footer/index.js renders on every route with zero end-to-end coverage #761 ), test: cover reference architecture detail pages end to end #760 (closes [quality] Reference architecture detail pages have no end-to-end coverage #759 )
P2 — automation correctness, partial fix only
P2 — blocked automated data PRs, unblocks once #721 is fixed
P3 — lower-risk cleanup, no PR yet
P4 — non-technical / long-horizon
Suggested merge order
fix(security): gate every published architecture page, not just cataloged ones #768 (closes [sec-check] Active-content gate is driven by the catalog, so an orphan docs/architectures/*.md is published unscanned #767 ) — high-severity security gate, ready, no dependencies
fix(security): gate remote resource references in imported SVG diagrams #775 (closes [sec-check] SVG active-content gate does not flag remote resource references, so an imported diagram can hot-link a third-party host #774 ) — security gate, ready, no dependencies
[quality] Playwright e2e suite is never run in CI — tests/e2e/smoke.spec.js has no workflow #672 — wire Playwright into CI (no PR yet; write before merging more specs into a suite nothing runs)
test: cover the awards timeline end to end #782 , test: cover the blog routes end to end #780 , test: cover the metrics dashboard end to end #778 , test: cover the case studies filter toolbar end to end #773 , test: cover the local site search end to end #771 , test: cover the primary navbar end to end #766 , test: cover the site footer end to end #762 , test: cover reference architecture detail pages end to end #760 — e2e coverage, any order, once [quality] Playwright e2e suite is never run in CI — tests/e2e/smoke.spec.js has no workflow #672 is merged so they immediately execute in CI
test: guard regenerate-format-validate-test ordering for data-generating automation jobs #758 — automation-ordering guard test (expect it to go red against current workflows; that's the intended signal for Automation workflows must validate and format what they generate before committing #755 )
Fix for Automation workflows must validate and format what they generate before committing #755 (workflow ordering) and [ci-maintainer] Automated import PRs run no CI: GITHUB_TOKEN-created PRs do not trigger pull_request workflows #721 (CI on token-authored PRs) — once [ci-maintainer] Automated import PRs run no CI: GITHUB_TOKEN-created PRs do not trigger pull_request workflows #721 lands, retry/re-approve chore: refresh community profiles #763 and chore: import latest reference architectures #681
Remaining P0/P3 items ([scanner] MDX active-content gate bypass: 4-space/tab-indented fence opener blanks live script content past findActiveContent #689 , [quality] site search indexes only the blog: docsRouteBasePath default does not match docs routeBasePath #769 , Strengthen the static/ asset security gate: discover directories dynamically and block external references in SVGs #754 , [quality] Two unreachable defensive sub-expressions permanently cap source region coverage #700 , doc cluster) as follow-up PRs
Notes on method
Derived from gh issue list --repo cncf/endusers --state open (23 issues), gh pr list --repo cncf/endusers --state open (13 PRs, including #782 which is very recent), each PR's mergeStateStatus/statusCheckRollup, and cross-referencing issue/PR bodies for explicit "Closes #NNN" links and consolidation notes. No hold-labeled issue or PR was modified.
Purpose
A pass over the current 23 open issues and 13 open PRs in cncf/endusers to flag likely duplicates/overlaps, propose consolidations, and set a priority and merge order. All PR numbers/CI states below were verified live via
gh pr view/gh issue viewat time of writing. Nohold-labeled item was merged or modified as part of this triage (perGOVERNANCE.md).Overlaps and duplicate candidates
static/subdirectories) or split into a new, smaller issue so it isn't left describing already-shipped work.refresh-community-people, chore: import latest reference architectures #681import-architectures) are currentlymergeStateStatus: BLOCKEDbecause branch protection is waiting on aValidate repositorycheck that GITHUB_TOKEN-authored PRs never trigger. These two PRs are live evidence for [ci-maintainer] Automated import PRs run no CI: GITHUB_TOKEN-created PRs do not trigger pull_request workflows #721 and are stuck until it's fixed (or a maintainer manually re-runs/approves).Consolidation candidates
CONTRIBUTING.md/AGENTS.md(stale validator claims, missing e2e mention, wrong hosting domain, wrong coverage command). None has a PR yet. Recommend one combined "docs accuracy sweep" PR/issue instead of four separate small diffs to the same two files — reduces review overhead and merge-conflict risk from touchingCONTRIBUTING.mdfour times in parallel.CLEAN, so they don't need to be merged as one PR, but they should be tracked as one initiative and gated on [quality] Playwright e2e suite is never run in CI — tests/e2e/smoke.spec.js has no workflow #672 (see below) rather than reviewed as eight unrelated PRs.Priority triage
P0 — correctness/security, blocking, no PR yet
BLOCKED(two live PRs affected today)P1 — ready to merge (green CI,
hold-gated, awaiting maintainer review)P1 — infra prerequisite for the e2e initiative, no PR yet
P2 — ready to merge (green CI,
hold-gated), gate on #672 landing firstP2 — automation correctness, partial fix only
P2 — blocked automated data PRs, unblocks once #721 is fixed
P3 — lower-risk cleanup, no PR yet
P4 — non-technical / long-horizon
docs/community/members.mdheading is still "Member Directory") but old enough to need a fresh confirmation it's still wanted before scopingSuggested merge order
Notes on method
Derived from
gh issue list --repo cncf/endusers --state open(23 issues),gh pr list --repo cncf/endusers --state open(13 PRs, including #782 which is very recent), each PR'smergeStateStatus/statusCheckRollup, and cross-referencing issue/PR bodies for explicit "Closes #NNN" links and consolidation notes. Nohold-labeled issue or PR was modified.