Skip to content

Triage: open issue/PR overlaps, consolidation candidates, and merge order (2026-09-28) #783

Description

@mrbobbytables

Purpose

A pass over the current 23 open issues and 13 open PRs in cncf/endusers to flag likely duplicates/overlaps, propose consolidations, and set a priority and merge order. All PR numbers/CI states below were verified live via gh pr view/gh issue view at time of writing. No hold-labeled item was merged or modified as part of this triage (per GOVERNANCE.md).

Overlaps and duplicate candidates

  1. Strengthen the static/ asset security gate: discover directories dynamically and block external references in SVGs #754 vs [sec-check] SVG active-content gate does not flag remote resource references, so an imported diagram can hot-link a third-party host #774/fix(security): gate remote resource references in imported SVG diagrams #775 (PR) — Strengthen the static/ asset security gate: discover directories dynamically and block external references in SVGs #754 ("Strengthen the static/ asset security gate") explicitly consolidates [sec-check] static/ security gate covers a hardcoded directory list, so a new static/ subdirectory is ungated with no CI signal #697 and [sec-check] SVG gate has no external-reference check: an imported diagram can hot-link a third-party host from the site origin #745, and one of its two goals — "extend the SVG gate to reject external URL references" — is the same fix PR fix(security): gate remote resource references in imported SVG diagrams #775 delivers for [sec-check] SVG active-content gate does not flag remote resource references, so an imported diagram can hot-link a third-party host #774. Once fix(security): gate remote resource references in imported SVG diagrams #775 merges, Strengthen the static/ asset security gate: discover directories dynamically and block external references in SVGs #754 should be narrowed to only its remaining goal (dynamic discovery of static/ subdirectories) or split into a new, smaller issue so it isn't left describing already-shipped work.
  2. Automation workflows must validate and format what they generate before committing #755 vs PR test: guard regenerate-format-validate-test ordering for data-generating automation jobs #758 — PR test: guard regenerate-format-validate-test ordering for data-generating automation jobs #758 adds a contract test that guards the "regenerate → format → validate → test" ordering Automation workflows must validate and format what they generate before committing #755 asks for, it does not reorder the four automation workflows ([quality] Import job never runs check:format, so every architecture import PR carries 16 unformatted files #713, [sec-check] refresh-community-people.yml commits third-party profile data without running validate:community-people #736, [quality] automation workflows run test:unit before regenerating the data it guards #738, [sec-check] deploy-gh-pages.yml publishes after running only 4 of 10 data validators #740) that Automation workflows must validate and format what they generate before committing #755 is about. Merging test: guard regenerate-format-validate-test ordering for data-generating automation jobs #758 will make CI red for those workflows (that's the point — it turns the gap into a visible failure) but must not be read as closing Automation workflows must validate and format what they generate before committing #755; the actual workflow-ordering fix is still unwritten.
  3. [ci-maintainer] Automated import PRs run no CI: GITHUB_TOKEN-created PRs do not trigger pull_request workflows #721 vs chore: refresh community profiles #763 / chore: import latest reference architectures #681 (PRs) — [ci-maintainer] Automated import PRs run no CI: GITHUB_TOKEN-created PRs do not trigger pull_request workflows #721 ("Automated import PRs run no CI") is not theoretical: both open automation PRs (chore: refresh community profiles #763 refresh-community-people, chore: import latest reference architectures #681 import-architectures) are currently mergeStateStatus: BLOCKED because branch protection is waiting on a Validate repository check that GITHUB_TOKEN-authored PRs never trigger. These two PRs are live evidence for [ci-maintainer] Automated import PRs run no CI: GITHUB_TOKEN-created PRs do not trigger pull_request workflows #721 and are stuck until it's fixed (or a maintainer manually re-runs/approves).
  4. [quality] site search indexes only the blog: docsRouteBasePath default does not match docs routeBasePath #769 vs PR test: cover the local site search end to end #771 — [quality] /search and the local search index have no end-to-end coverage #770 (search e2e coverage, closed by PR test: cover the local site search end to end #771) and [quality] site search indexes only the blog: docsRouteBasePath default does not match docs routeBasePath #769 (site search indexes only the blog, a real product bug) were discovered together. Confirm whether test: cover the local site search end to end #771's new spec asserts today's broken behavior (docs pages missing from the index) — if so it will need a follow-up once [quality] site search indexes only the blog: docsRouteBasePath default does not match docs routeBasePath #769 lands, or should be written against the fixed behavior with [quality] site search indexes only the blog: docsRouteBasePath default does not match docs routeBasePath #769 as a blocking dependency.
  5. [quality] Two unreachable defensive sub-expressions permanently cap source region coverage #700 references PRs test(import-architectures): cover the seven uncovered sub-line regions #678, test(svg-active-content): cover single-quoted and unquoted attribute values #680, test(fetch-community-people): cover the four uncovered sub-line regions #686, test(validators): cover the seven uncovered fallback-label regions #688, test(collectors): cover the six uncovered sub-line fallback regions #693 as already covering every other uncovered source region. All five of those branches now have closed (not merged) PRs — the closures were part of today's branch cleanup. [quality] Two unreachable defensive sub-expressions permanently cap source region coverage #700 needs re-verification: the coverage gaps it defers to may no longer be closed by anything, so its "these two are the only remainder" claim should be re-checked before anyone assumes the two named sub-expressions are truly the only gap left.

Consolidation candidates

Priority triage

P0 — correctness/security, blocking, no PR yet

P1 — ready to merge (green CI, hold-gated, awaiting maintainer review)

P1 — infra prerequisite for the e2e initiative, no PR yet

P2 — ready to merge (green CI, hold-gated), gate on #672 landing first

P2 — automation correctness, partial fix only

P2 — blocked automated data PRs, unblocks once #721 is fixed

P3 — lower-risk cleanup, no PR yet

P4 — non-technical / long-horizon

Suggested merge order

  1. fix(security): gate every published architecture page, not just cataloged ones #768 (closes [sec-check] Active-content gate is driven by the catalog, so an orphan docs/architectures/*.md is published unscanned #767) — high-severity security gate, ready, no dependencies
  2. fix(security): gate remote resource references in imported SVG diagrams #775 (closes [sec-check] SVG active-content gate does not flag remote resource references, so an imported diagram can hot-link a third-party host #774) — security gate, ready, no dependencies
  3. [quality] Playwright e2e suite is never run in CI — tests/e2e/smoke.spec.js has no workflow #672 — wire Playwright into CI (no PR yet; write before merging more specs into a suite nothing runs)
  4. test: cover the awards timeline end to end #782, test: cover the blog routes end to end #780, test: cover the metrics dashboard end to end #778, test: cover the case studies filter toolbar end to end #773, test: cover the local site search end to end #771, test: cover the primary navbar end to end #766, test: cover the site footer end to end #762, test: cover reference architecture detail pages end to end #760 — e2e coverage, any order, once [quality] Playwright e2e suite is never run in CI — tests/e2e/smoke.spec.js has no workflow #672 is merged so they immediately execute in CI
  5. test: guard regenerate-format-validate-test ordering for data-generating automation jobs #758 — automation-ordering guard test (expect it to go red against current workflows; that's the intended signal for Automation workflows must validate and format what they generate before committing #755)
  6. Fix for Automation workflows must validate and format what they generate before committing #755 (workflow ordering) and [ci-maintainer] Automated import PRs run no CI: GITHUB_TOKEN-created PRs do not trigger pull_request workflows #721 (CI on token-authored PRs) — once [ci-maintainer] Automated import PRs run no CI: GITHUB_TOKEN-created PRs do not trigger pull_request workflows #721 lands, retry/re-approve chore: refresh community profiles #763 and chore: import latest reference architectures #681
  7. Remaining P0/P3 items ([scanner] MDX active-content gate bypass: 4-space/tab-indented fence opener blanks live script content past findActiveContent #689, [quality] site search indexes only the blog: docsRouteBasePath default does not match docs routeBasePath #769, Strengthen the static/ asset security gate: discover directories dynamically and block external references in SVGs #754, [quality] Two unreachable defensive sub-expressions permanently cap source region coverage #700, doc cluster) as follow-up PRs

Notes on method

Derived from gh issue list --repo cncf/endusers --state open (23 issues), gh pr list --repo cncf/endusers --state open (13 PRs, including #782 which is very recent), each PR's mergeStateStatus/statusCheckRollup, and cross-referencing issue/PR bodies for explicit "Closes #NNN" links and consolidation notes. No hold-labeled issue or PR was modified.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions