Open PRs (243)

Resolution:

Average age: 298.2d, Avg wait: 75.8d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
9171 Allow configuring concatenation key order for CombinedPEM output format (#7766)
3wk 8h 19d
size/L
release-note
area/api
kind/feature
dco-signoff: yes
ok-to-test
area/deploy
author-last
commented
new-commits
recv
9321 [release-1.21] fix(e2e): give each SelfSigned CSR spec its own Secret 10h 9h 9h
release-note-none
size/S
dco-signoff: yes
area/testing
kind/flake
assigned
assignee-updated
commented
member-last
send
unreviewed
9317 chore(deps): update module google.golang.org/grpc to v1.83.2 [security] (release-1.21) 18h 13h 18h
release-note-none
approved
lgtm
size/S
kind/cleanup
dco-signoff: yes
area/testing
ok-to-test
dependencies
approved
contributor-last
recv
recv-q
similar
9316 chore(deps): update module google.golang.org/grpc to v1.83.2 [security] (release-1.20) 23h 13h 23h
release-note-none
approved
lgtm
size/S
kind/cleanup
dco-signoff: yes
area/testing
ok-to-test
dependencies
approved
contributor-last
recv
recv-q
similar
9306 ingress-shim: de-duplicate SANs after annotations are merged 1d 18h 18h
release-note
needs-rebase
kind/bug
needs-ok-to-test
size/M
dco-signoff: yes
commented
member-last
reviewed-with-comment
send
9292 [release-1.21] fix(acme/ari): adding cert id to status 2d 19h 19h
release-note
size/XL
area/api
kind/bug
dco-signoff: yes
tide/merge-method-squash
area/deploy
assigned
assignee-updated
commented
member-last
unreviewed
9305 fix(webhook): validate that renewal windows are reachable within the certificate lifetime 1d 22h 22h
size/L
release-note
kind/bug
needs-ok-to-test
dco-signoff: yes
collaborator-last
commented
send
unreviewed
9302 certificate-shim: compare ipAddresses in certNeedsUpdate 1d 1d 1d
size/L
release-note
do-not-merge/hold
kind/bug
needs-ok-to-test
dco-signoff: yes
commented
contributor-last
new-commits
recv
9207 Fix HTTP01 self-check to respect context cancellation 13d 1d 2d
release-note
kind/bug
needs-ok-to-test
size/M
area/acme
dco-signoff: yes
area/acme/dns01
area/acme/http01
commented
contributor-last
recv
reviewed-with-comment
8722 fix(dns): propagate caBundle to acmeDNS solver, add per-solver override 4mo 1d 4mo
release-note
area/api
kind/bug
kind/feature
needs-ok-to-test
size/XXL
area/acme
dco-signoff: yes
area/acme/dns01
area/deploy
recv
recv-q
unreviewed
9294 Fix ec parameters parsing with unit test 2d 1d 2d
release-note
kind/bug
size/M
dco-signoff: yes
ok-to-test
contributor-last
recv
recv-q
reviewed-with-comment
similar
8529 fix: schedule readiness re-evaluation at certificate expiry time
6mo 1d 1d
size/L
release-note
approved
kind/bug
dco-signoff: yes
area/testing
ok-to-test
commented
member-last
reviewed-with-comment
send
9256 Deflake the Certificate foreground deletion e2e tests 7d 1d 1d
release-note-none
size/S
dco-signoff: yes
area/testing
kind/flake
commented
member-last
reviewed-with-comment
send
similar
9287 fix(certificates): recover from a CertificateRequest with a failureTime but no Ready condition 3d 1d 3d
release-note
kind/bug
needs-ok-to-test
size/XXL
dco-signoff: yes
area/testing
contributor-last
recv
recv-q
similar
unreviewed
8734 Fix: include annotations derived from ingress in certificate reconciliation loop 4mo 2d 3mo
size/L
do-not-merge/release-note-label-needed
kind/bug
needs-ok-to-test
dco-signoff: yes
commented
contributor-last
recv
reviewed-with-comment
8935 feat(metrics): instrument Vault issuer Sign() requests 2mo 2d 2mo
release-note
kind/feature
needs-ok-to-test
size/M
area/vault
dco-signoff: yes
area/monitoring
author-last
recv
recv-q
similar
unreviewed
9285 Add design: publish the ACME webhook API as its own Go module 4d 4d
size/L
release-note-none
kind/design
dco-signoff: yes
contributor-last
recv-q
unreviewed
9109 Fix nil pointer panic on renewal-window errors in the trigger controller
4wk 4d 4d
size/L
release-note
kind/bug
dco-signoff: yes
commented
member-last
reviewed-with-comment
9079 Use %w for error wrapping instead of %s with err.Error()
6wk 4d 4d
release-note-none
kind/cleanup
needs-ok-to-test
size/M
area/acme
dco-signoff: yes
area/acme/dns01
commented
member-last
reviewed-with-comment
send
9284 Add design: reuse Venafi access tokens across reconciles 4d 4d
size/L
release-note-none
do-not-merge/work-in-progress
kind/design
dco-signoff: yes
contributor-last
draft
recv-q
unreviewed
9283 Add design: disable the ACME HTTP-01 solver and drop its RBAC 4d 4d
size/L
release-note-none
do-not-merge/work-in-progress
kind/design
dco-signoff: yes
contributor-last
draft
recv-q
unreviewed
5447 Allow extra DNS-01 propagation time to be configured
4y 4d 1y
release-note
needs-rebase
size/S
lifecycle/frozen
kind/feature
area/acme
dco-signoff: yes
ok-to-test
area/acme/dns01
commented
contributor-last
recv-q
send
unreviewed
7236 Route53: Allow STS token to be refreshed by the AWS client if necessary 2y 4d 4wk
release-note
size/XL
needs-rebase
area/api
kind/bug
kind/feature
area/acme
dco-signoff: yes
area/acme/dns01
area/deploy
commented
contributor-last
recv-q
reviewed-with-comment
7382 Implement a single package for controlling cert-manager RNG
3
2y 4d 1y
size/L
release-note
needs-rebase
do-not-merge/hold
kind/feature
area/acme
dco-signoff: yes
area/testing
commented
contributor-last
recv-q
send
unreviewed
7437 fix: annotate account private key secrets 2y 4d 2y
release-note
needs-rebase
size/S
area/api
kind/feature
area/acme
dco-signoff: yes
ok-to-test
commented
contributor-last
recv
recv-q
unreviewed
7449 WIP: reconcile issuers using issuer-lib 2y 4d 1y
release-note-none
needs-rebase
area/api
do-not-merge/work-in-progress
kind/cleanup
size/XXL
area/acme
area/ca
area/vault
dco-signoff: yes
area/testing
area/deploy
commented
contributor-last
recv-q
unreviewed
7614 Lower the minimum certificate duration from 1 hour to 5 minutes 2y 4d 2y
release-note
needs-rebase
size/S
area/api
kind/feature
dco-signoff: yes
ok-to-test
contributor-last
recv
recv-q
unreviewed
7718 Switch to makefile modules completely (part 1) 1y 4d 9mo
release-note-none
needs-rebase
area/api
kind/cleanup
size/XXL
area/acme
dco-signoff: yes
area/testing
area/deploy
cybr
commented
contributor-last
new-commits
recv-q
send
7805 feat: refactor challenge controller to be entirely non blocking 1y 4d 10mo
release-note
needs-rebase
area/api
kind/bug
size/XXL
area/acme
dco-signoff: yes
area/testing
area/acme/dns01
area/acme/http01
area/deploy
cybr
commented
contributor-last
new-commits
recv-q
send
7897 wip: add retry mechanism for challenge solver whenever we detect unauthorized error
1y 4d 10mo
size/XL
release-note-none
needs-rebase
area/api
do-not-merge/work-in-progress
area/acme
dco-signoff: yes
area/testing
ok-to-test
area/acme/dns01
area/monitoring
area/deploy
needs-kind
commented
contributor-last
recv
recv-q
reviewed-with-comment
8220 Add predicate filtering to queuing handler
10mo 4d 9mo
size/XL
release-note-none
needs-rebase
area/acme
dco-signoff: yes
area/acme/dns01
needs-kind
commented
contributor-last
recv-q
send
unreviewed
8263 fix: dont copy `kapp.k14s.io` annotations from Ingress to created resources
9mo 4d 9mo
size/XS
release-note
needs-rebase
kind/feature
dco-signoff: yes
ok-to-test
commented
contributor-last
recv-q
send
unreviewed
8339 feat(pkcs12): Add flag to specify pkcs12 keystore alias 9mo 4d 9mo
size/L
release-note
needs-rebase
area/api
kind/design
kind/feature
area/acme
dco-signoff: yes
area/testing
area/acme/dns01
area/acme/http01
area/deploy
contributor-last
recv
recv-q
unreviewed
8379 acmechallenges: stabilize solver resource names 8mo 4d 8mo
size/XS
release-note
needs-rebase
kind/bug
area/acme
dco-signoff: yes
ok-to-test
commented
contributor-last
recv
recv-q
unreviewed
8480 Add Subject Key Identifier (SKI) to issued certificates
3
7mo 4d 7mo
size/L
release-note
needs-rebase
kind/feature
dco-signoff: yes
area/testing
ok-to-test
commented
contributor-last
new-commits
recv
recv-q
8536 Re-enable the ListenerSet e2e tests 6mo 4d 6mo
release-note-none
needs-rebase
do-not-merge/hold
kind/cleanup
size/XXL
dco-signoff: yes
area/testing
commented
contributor-last
new-commits
recv-q
send
8823 Add `--metric-static-labels` flag to attach custom labels to certificate Prometheus metrics. 3mo 4d 3mo
size/L
release-note
needs-rebase
area/api
kind/feature
dco-signoff: yes
area/testing
ok-to-test
area/monitoring
commented
contributor-last
recv
recv-q
reviewed-with-comment
9224 Only consume next private key Secrets owned by the Certificate 9d 4d 4d
release-note
size/XL
kind/bug
dco-signoff: yes
area/testing
commented
member-last
reviewed-with-comment
9049 Add opt-in Gateway wildcard hostname deduplication 7wk 5d 7wk
size/L
release-note
needs-rebase
kind/feature
needs-ok-to-test
dco-signoff: yes
contributor-last
recv
recv-q
reviewed-with-comment
9247 Deflake notAfter assertions in CSR signing tests 8d 5d 5d
size/L
release-note-none
dco-signoff: yes
kind/flake
commented
member-last
reviewed-with-comment
9254 Deflake certificate-shim controller register tests 8d 5d 5d
release-note-none
size/M
dco-signoff: yes
kind/flake
commented
member-last
similar
unreviewed
8187 fix: add case for parsing key with ec parameters 10mo 5d 10mo
size/XS
release-note-none
kind/bug
needs-ok-to-test
lifecycle/rotten
dco-signoff: yes
author-last
changes-requested
recv
recv-q
similar
8504 WIP: Enable KAL 7mo 6d
release-note-none
do-not-merge/work-in-progress
size/M
lifecycle/stale
dco-signoff: yes
needs-kind
contributor-last
recv-q
unreviewed
8457 feat(acme): add support for ECDSA account key algorithm in ACME issuers
3
7mo 6d 3wk
release-note
size/XL
area/api
kind/feature
area/acme
dco-signoff: yes
area/testing
ok-to-test
area/deploy
author-last
commented
recv
reviewed-with-comment
9005 Register Secret event handlers only on informers whose object type they handle 2mo 7d 7d
size/L
release-note
kind/bug
dco-signoff: yes
commented
member-last
reviewed-with-comment
send
9245 Run dynamic authority tests in a synctest bubble 8d 7d 7d
release-note-none
size/S
dco-signoff: yes
kind/flake
commented
member-last
reviewed-with-comment
9241 Recover DynamicAuthority when the CA Secret create race is lost 8d 8d 8d
release-note
kind/bug
size/M
dco-signoff: yes
kind/flake
commented
member-last
reviewed-with-comment
9244 [release-1.21] fix(digitalocean): paginate TXT record lookups in findTxtRecord 8d 8d 8d
size/L
release-note
kind/bug
area/acme
dco-signoff: yes
area/acme/dns01
assigned
assignee-updated
commented
contributor-last
recv-q
unreviewed
9243 Deflake TestDynamicAuthority 8d 8d
release-note-none
size/S
kind/cleanup
dco-signoff: yes
contributor-last
recv-q
unreviewed
8631 fix(acme): detect server URL path changes for account re-registration 5mo 9d 5mo
size/L
do-not-merge/release-note-label-needed
needs-rebase
area/api
kind/bug
needs-ok-to-test
area/acme
dco-signoff: yes
area/testing
area/deploy
contributor-last
recv
recv-q
unreviewed
8527 [WIP]:AddS ML-DSA-65 post-quantum signature algorithm support 6mo 14d 6mo
do-not-merge/release-note-label-needed
size/XL
needs-rebase
area/api
do-not-merge/work-in-progress
kind/feature
needs-ok-to-test
dco-signoff: yes
area/testing
area/deploy
recv
recv-q
unreviewed
8837 reject negative arcs in ParseObjectIdentifier 3mo 15d 16d
release-note
kind/bug
needs-ok-to-test
size/M
dco-signoff: yes
author-last
commented
recv
reviewed-with-comment
8844 reject non-context-specific GeneralName class in UnmarshalSANs 3mo 15d 3mo
release-note-none
needs-ok-to-test
size/M
dco-signoff: yes
needs-kind
author-last
new-commits
recv
recv-q
9149 Experiment: property-based tests with hegel-go 3wk 15d
do-not-merge/release-note-label-needed
needs-rebase
do-not-merge/work-in-progress
size/XXL
dco-signoff: yes
needs-kind
contributor-last
draft
recv-q
similar
unreviewed
9056 fix: don't count terminating HTTP01 solver pods when deciding to create/clean up 7wk 15d 16d
release-note
kind/bug
size/M
area/acme
dco-signoff: yes
ok-to-test
area/acme/http01
assigned
assignee-updated
commented
contributor-last
new-commits
recv
recv-q
9046 Add workqueue keys to controller logs 7wk 16d 16d
size/XS
release-note
kind/cleanup
dco-signoff: yes
ok-to-test
commented
contributor-last
recv-q
reviewed-with-comment
send
9187 DO NOT MERGE: Test tools-cache verify-at-use (makefile-modules#710) 19d 19d 19d
size/L
do-not-merge/release-note-label-needed
needs-rebase
do-not-merge/work-in-progress
do-not-merge/hold
dco-signoff: yes
needs-kind
commented
contributor-last
draft
recv-q
unreviewed
9183 Route53: resume waiting for a pending record change instead of submitting a duplicate 19d 19d 19d
size/L
release-note
kind/bug
area/acme
dco-signoff: yes
area/acme/dns01
commented
member-last
new-commits
8833 make: check the hash at runtime instead of after downloading 3mo 19d 19d
size/L
do-not-merge/release-note-label-needed
needs-rebase
do-not-merge/work-in-progress
dco-signoff: yes
area/testing
area/monitoring
needs-kind
commented
draft
member-last
new-commits
send
8534 feat: add --dns01-timeout flag to make DNS01 provider API timeout configurable 6mo 19d 19d
release-note
area/api
size/M
area/acme
dco-signoff: yes
ok-to-test
area/acme/dns01
needs-kind
commented
member-last
send
unreviewed
9162 Add design: client-side rate limiting and API Priority and Fairness 3wk 3wk
size/L
do-not-merge/release-note-label-needed
kind/design
dco-signoff: yes
contributor-last
recv-q
unreviewed
9159 Honor configured Kubernetes API rate limits 3wk 3wk 3wk
size/L
release-note
do-not-merge/hold
kind/bug
needs-ok-to-test
dco-signoff: yes
changes-requested
contributor-last
recv
recv-q
9150 Accept bundles containing cross-signed certificates in ParseSingleCertificateChain 3wk 3wk 3wk
size/L
release-note
kind/bug
dco-signoff: yes
commented
member-last
reviewed-with-comment
7886 Improve array field characteristics in API 1y 3wk 6mo
size/L
release-note
area/api
do-not-merge/hold
kind/bug
kind/cleanup
lifecycle/stale
dco-signoff: yes
area/deploy
commented
contributor-last
new-commits
9082 test: add regression coverage for deep-subdomain zone lookup (#4749) 6wk 4wk 6wk
release-note-none
size/S
kind/cleanup
needs-ok-to-test
area/acme
dco-signoff: yes
area/acme/dns01
assigned
contributor-last
recv
recv-q
reviewed-with-comment
4835 Making sure per fixture only 1 setup is active at the same time
4y 4wk 4wk
release-note-none
size/S
lifecycle/frozen
kind/bug
dco-signoff: yes
area/testing
assigned
assignee-updated
commented
member-last
reviewed-with-comment
send
9110 Route53: assume the role lazily so the AWS SDK can refresh STS credentials 4wk 4wk 4wk
size/L
release-note
kind/bug
area/acme
dco-signoff: yes
area/acme/dns01
commented
member-last
reviewed-with-comment
9104 fix(pki): reject zoned IPv6 in CSR generation and nil IP in certificate matching 4wk 4wk 4wk
size/L
do-not-merge/release-note-label-needed
needs-ok-to-test
dco-signoff: no
needs-kind
commented
member-last
reviewed-with-comment
send
9013 fix(cainjector): add liveness and readiness probes to cainjector deployment 2mo 4wk 2mo
release-note
area/api
kind/bug
needs-ok-to-test
size/M
dco-signoff: yes
area/deploy
author-last
recv
recv-q
unreviewed
8957 Simplify renewal watcher loop in DynamicSource.Start 2mo 4wk 4wk
release-note-none
kind/cleanup
size/M
dco-signoff: yes
commented
member-last
send
unreviewed
9097 fix(keymanager): preserve current private key secret on stale informer cache 5wk 5wk 5wk
size/L
release-note
needs-ok-to-test
dco-signoff: yes
needs-kind
contributor-last
recv
recv-q
unreviewed
7583 Support for ACME servers that don't finalize within the ACME client finalizer retry window 2y 6wk 5mo
release-note
kind/bug
needs-ok-to-test
size/M
area/acme
dco-signoff: yes
approved
commented
recv-q
send
8438 POC: single cert-manager binary 7mo 6wk
release-note-none
do-not-merge/work-in-progress
kind/feature
size/XXL
lifecycle/stale
dco-signoff: no
contributor-last
draft
recv-q
unreviewed
9053 Add design proposal for DANE/TLSA DNS record management 7wk 7wk 7wk
do-not-merge/release-note-label-needed
size/XL
kind/design
needs-ok-to-test
dco-signoff: yes
recv
recv-q
reviewed-with-comment
8395 Clarify code around DNS01 Self Check 8mo 7wk 6mo
release-note-none
kind/cleanup
size/M
area/acme
dco-signoff: yes
ok-to-test
area/acme/dns01
author-last
commented
new-commits
recv
recv-q
9045 Fix CertificateRequest approval event reason 7wk 7wk 7wk
size/XS
release-note
kind/bug
needs-ok-to-test
dco-signoff: yes
contributor-last
recv
recv-q
similar
unreviewed
8698 fix(digitalocean): resolve DNS01 zones from managed domains 5mo 7wk 4mo
size/L
release-note
needs-rebase
kind/bug
needs-ok-to-test
area/acme
dco-signoff: yes
area/acme/dns01
commented
contributor-last
recv-q
send
unreviewed
9030 feat: validate owner reference 1mo 1mo 1mo
size/L
release-note
kind/feature
needs-ok-to-test
dco-signoff: yes
contributor-last
recv
recv-q
unreviewed
8367 feat(helm) add startupProbe and readinessProbe to cert-manager-controller 8mo 2mo 8mo
release-note-none
kind/feature
needs-ok-to-test
size/M
lifecycle/stale
dco-signoff: yes
area/deploy
commented
contributor-last
recv
recv-q
unreviewed
8968 fix(acmeorders): reschedule Order when concurrent finalize returns 403 with processing ACME order 2mo 2mo 2mo
release-note
kind/bug
needs-ok-to-test
size/M
area/acme
dco-signoff: yes
new-commits
recv
recv-q
8253 refactor(issuer): add shared factory and per-instance registries 9mo 2mo 2mo
size/L
release-note-none
kind/cleanup
dco-signoff: yes
ok-to-test
commented
member-last
reviewed-with-comment
send
7662 Fix the issue of webhook routes generating duplicate operation IDs 1y 2mo 1y
do-not-merge/release-note-label-needed
needs-ok-to-test
size/M
area/acme
lifecycle/rotten
dco-signoff: yes
needs-kind
contributor-last
recv
recv-q
unreviewed
8896 Helm toggle features 2mo 2mo 2mo
size/L
release-note
kind/feature
needs-ok-to-test
dco-signoff: yes
area/deploy
contributor-last
recv
recv-q
unreviewed
8892 add renderMode options for prometheus monitors 2mo 2mo 2mo
release-note
kind/feature
needs-ok-to-test
size/M
dco-signoff: yes
area/deploy
author-last
commented
recv
unreviewed
8262 Bugfix #7388 kid missing issue with Infisical ACME server or any other ACME that requires EAB
9mo 2mo 9mo
size/L
release-note
needs-ok-to-test
lifecycle/stale
area/acme
dco-signoff: yes
needs-kind
commented
contributor-last
recv
unreviewed
8846 fix(selector/dns): normalize dns name before comparing 3mo 2mo 3mo
release-note-none
size/S
kind/bug
needs-ok-to-test
area/acme
dco-signoff: yes
contributor-last
recv
recv-q
unreviewed
8875 docs: add network policy examples for HTTP01 solver pods 2mo 2mo 2mo
release-note
needs-ok-to-test
size/M
dco-signoff: yes
area/deploy
needs-kind
collaborator-last
commented
new-commits
send
similar
7764 Doc: Add leaderElection.namespace recommendation 1y 2mo 1y
size/XS
release-note-none
lifecycle/rotten
dco-signoff: yes
ok-to-test
area/deploy
needs-kind
commented
contributor-last
recv-q
send
unreviewed
8838 Add support for GN and SN in LiteralSubject 3mo 3mo 3mo
release-note
size/S
kind/feature
needs-ok-to-test
dco-signoff: yes
contributor-last
recv
recv-q
unreviewed
8485 Adds Sign API call metric for the Vault issuer. 7mo 3mo 7mo
size/L
release-note
needs-rebase
kind/feature
needs-ok-to-test
dco-signoff: yes
area/monitoring
contributor-last
recv
recv-q
unreviewed
8712 feat(metrics): add Vault Sign() request duration instrumentation 4mo 3mo 4mo
size/L
do-not-merge/release-note-label-needed
needs-rebase
needs-ok-to-test
dco-signoff: yes
area/monitoring
needs-kind
contributor-last
recv
recv-q
similar
unreviewed
8687 Normalize challenge reason in certmanager_certificate_challenge_status metric
5mo 4mo 5mo
size/L
release-note-none
needs-ok-to-test
dco-signoff: yes
needs-kind
author-last
recv
recv-q
reviewed-with-comment
8336 Add global.tolerations to helm chart 9mo 4mo 7mo
release-note
needs-rebase
kind/feature
needs-ok-to-test
size/M
dco-signoff: yes
area/deploy
changes-requested
commented
recv-q
send
8637 fix(helm): roll deployments on config changes (checksum)
5mo 5mo 5mo
do-not-merge/release-note-label-needed
kind/feature
needs-ok-to-test
size/M
dco-signoff: yes
area/deploy
changes-requested
collaborator-last
commented
send
8624 feat: add autoAnnotations support for Gateway-API 5mo 5mo 5mo
size/XS
release-note
do-not-merge/work-in-progress
kind/feature
needs-ok-to-test
dco-signoff: yes
collaborator-last
commented
draft
send
unreviewed
5743 Add MaxPathLen and add EncodeBasicConstraintsInRequest option to Certificate and CertificateRequest resources 3y 5mo 5mo
size/L
release-note
area/api
kind/cleanup
dco-signoff: yes
area/testing
ok-to-test
area/deploy
commented
member-last
reviewed-with-comment
8608 fix: reduce happy-eyeballs fallback delay in Cloudflare DNS provider 6mo 6mo 6mo
size/L
release-note
needs-rebase
kind/bug
needs-ok-to-test
area/acme
dco-signoff: yes
area/testing
area/acme/dns01
contributor-last
recv
recv-q
unreviewed
8594 Fix typo "commonname" in PreferredChain field comment 6mo 6mo 6mo
release-note-none
size/S
area/api
kind/cleanup
needs-ok-to-test
dco-signoff: yes
area/deploy
contributor-last
recv
recv-q
unreviewed
7689 Add Vertical Pod Autoscaler
2
1y 6mo 6mo
size/L
release-note
approved
kind/feature
dco-signoff: yes
ok-to-test
area/deploy
assigned
assignee-updated
changes-requested
collaborator-last
commented
send
2273 chore(deps): update misc npm packages 2d 1h 2d
dco-signoff: yes
size/XL
ok-to-test
dependencies
recv
recv-q
unreviewed
2271 Explain what to do when an application expects ca.crt in the certificate Secret 2d 9h 9h
dco-signoff: yes
lgtm
size/M
approved
commented
contributor-last
recv-q
send
2270 chore(deps): lock file maintenance 3d 9h 3d
dco-signoff: yes
size/XXL
ok-to-test
dependencies
recv
recv-q
unreviewed
2227 fix(deps): update dependency @docsearch/react to v5 4wk 9h 4wk
dco-signoff: yes
size/L
ok-to-test
dependencies
contributor-last
recv
recv-q
unreviewed
2258 docs: add certforge-issuer to external issuers list 7d 6d 7d
size/XS
dco-signoff: yes
commented
member-last
send
similar
unreviewed
2239 Add cmp-issuer to external issuers list 18d 5d 18d
size/XS
dco-signoff: yes
recv
recv-q
similar
unreviewed
2261 v1.21.2: patch release notes 6d 6d
dco-signoff: yes
do-not-merge/hold
do-not-merge/work-in-progress
size/M
draft
recv-q
unreviewed
2260 Add an availability and denial of service section to the threat model 7d 7d
dco-signoff: yes
size/M
recv-q
unreviewed
2256 docs: correct the Gateway API version requirement 8d 7d 8d
dco-signoff: yes
size/M
recv
recv-q
unreviewed
2257 docs: document the Vault issuer caBundleSecretRef field 8d 7d 8d
dco-signoff: yes
size/M
contributor-last
recv
recv-q
reviewed-with-comment
2212 docs: explain installing cert-manager into a different namespace 7wk 7wk 7wk
dco-signoff: yes
size/S
recv
recv-q
similar
unreviewed
2211 docs: clarify the webhook --enable-client-verification flag description 7wk 7wk 7wk
size/XS
dco-signoff: yes
recv
recv-q
unreviewed
1785 Add release-notes generator script and Makefile target 11mo 2mo 5mo
dco-signoff: yes
size/XXL
needs-rebase
commented
contributor-last
new-commits
recv-q
send
2128 Add troubleshooting guide for certificate re-issuance loops 3mo 2mo 3mo
dco-signoff: yes
size/L
needs-rebase
commented
contributor-last
new-commits
recv-q
2188 docs: rename tutorial 'Securing NGINX-ingress' to 'Securing ingress-nginx' 2mo 2mo 2mo
size/XS
dco-signoff: yes
recv
recv-q
unreviewed
2166 netlify: document deploy-preview security for forked pull requests 2mo 2mo 2mo
dco-signoff: yes
size/S
commented
member-last
reviewed-with-comment
2092 docs: add infomaniak third party provider 4mo 2mo 4mo
size/XS
dco-signoff: yes
author-last
recv
recv-q
reviewed-with-comment
2160 docs: document the cert-manager.io/secret-template ingress annotation 2mo 2mo 2mo
size/XS
dco-signoff: yes
recv
recv-q
unreviewed
2159 docs: use stringData in the DigitalOcean DNS01 Secret example 2mo 2mo 2mo
dco-signoff: yes
size/S
recv
recv-q
unreviewed
1909 docs: add ACK RRSA supported AliDNS webhook 8mo 2mo 2mo
size/XS
dco-signoff: yes
changes-requested
commented
contributor-last
recv-q
send
2151 docs: add NetworkPolicy examples for HTTP01 challenges to best-practice page 2mo 2mo 2mo
dco-signoff: yes
size/M
changes-requested
commented
member-last
send
similar
2023 Adds troubleshooting guide for host missmatch error 5mo 2mo 5mo
size/XS
dco-signoff: yes
changes-requested
contributor-last
recv
recv-q
1202 Add section about client cert authentication for vault 3y 4mo 3y
dco-signoff: yes
do-not-merge/work-in-progress
size/M
commented
contributor-last
draft
new-commits
send
1607 Document Log Level settings. Document DNS01 delegation using multiple providers. 2y 6mo 2y
dco-signoff: yes
needs-rebase
size/M
contributor-last
recv
recv-q
unreviewed
1197 doc about new option default-cleanup-policy
3y 4mo 1y
approved
dco-signoff: yes
needs-rebase
size/M
commented
member-last
new-commits
send
1213 Draft of tutorial for Google's Public CA 3y 6mo 3y
dco-signoff: yes
size/L
needs-rebase
ok-to-test
commented
contributor-last
reviewed-with-comment
send
859 Move the meetings and slack information to a separate page
4y 6mo 4y
approved
dco-signoff: yes
needs-rebase
size/M
changes-requested
commented
member-last
send
1724 DRAFT: feat(tutorials): Add Gateway API
1y 6mo 6mo
dco-signoff: yes
size/L
do-not-merge/work-in-progress
author-last
commented
draft
recv
unreviewed
1787 Update Slack links to include both invite and direct channel URLs 11mo 6mo 11mo
size/XS
dco-signoff: yes
cybr
changes-requested
commented
member-last
send
1672 WIP: docs: Add an wrap-up announcement page
1y 6mo 1y
dco-signoff: yes
do-not-merge/work-in-progress
size/M
commented
draft
member-last
new-commits
send
1640 Update issuer.md 2y 6mo 1y
size/XS
dco-signoff: yes
commented
member-last
reviewed-with-comment
send
1602 acme troubleshooting: how to fix errored challenges 2y 6mo 2y
size/XS
dco-signoff: yes
contributor-last
recv
recv-q
reviewed-with-comment
1611 Update webhook troubleshooting documentation to including necessary curl command. 2y 6mo 2y
dco-signoff: yes
size/S
changes-requested
contributor-last
recv
recv-q
1569 wip: update cert-manager logo svg 2y 6mo 1y
dco-signoff: yes
size/L
do-not-merge/work-in-progress
commented
member-last
send
unreviewed
1587 Custom Certificate Support for cert-manager Webhook Endpoint 2y 6mo 2y
dco-signoff: yes
size/S
recv
recv-q
unreviewed
1450 Docker testing and validation 2y 6mo 2y
dco-signoff: yes
needs-rebase
size/M
contributor-last
new-commits
recv
recv-q
1447 Explain how to install cert-manager using ArgoCD
3
2y 6mo 2y
dco-signoff: yes
size/L
commented
contributor-last
recv-q
reviewed-with-comment
send
similar
1419 fix: TLSConfig secretName description 2y 6mo 2y
dco-signoff: yes
needs-rebase
size/S
changes-requested
commented
contributor-last
recv-q
send
1364 WIP: Patch release checklist 2y 6mo
dco-signoff: yes
needs-rebase
do-not-merge/work-in-progress
size/M
contributor-last
recv-q
unreviewed
948 add note to ingress class definition 4y 6mo 3y
dco-signoff: no
size/XS
needs-rebase
needs-ok-to-test
assigned
commented
contributor-last
send
unreviewed
1075 Move Issuer / ClusterIssuer and Certificate resource content to a sub-folder of configuration/ 4y 6mo 2y
approved
dco-signoff: yes
size/L
needs-rebase
changes-requested
commented
member-last
send
790 Update route53.md 4y 6mo 3y
dco-signoff: no
size/XS
needs-rebase
needs-ok-to-test
changes-requested
commented
member-last
send
528 Update "Setting Nameservers for DNS01 Self Check" example 5y 4y 5y
size/XS
dco-signoff: yes
needs-rebase
needs-ok-to-test
contributor-last
recv
unreviewed
290 Add OCI signing as part of existing publish pipeline 4mo 6wk 2mo
dco-signoff: yes
size/XXL
needs-rebase
commented
contributor-last
new-commits
recv-q
send
329 Add script to ping PR authors and issue reporters after a release 2mo 2mo
dco-signoff: yes
size/L
contributor-last
recv-q
unreviewed
43 No more requirement "be in the release folder" to run cmrel, remove the flag --cloudbuild 5y 5y
dco-signoff: yes
approved
size/M
needs-rebase
contributor-last
unreviewed
36 Add the "cmrel update-release-branch" command 5y 5y 5y
dco-signoff: yes
approved
size/M
needs-rebase
do-not-merge/work-in-progress
commented
contributor-last
draft
unreviewed
369 fix(deps): update module cloud.google.com/go/storage to v1.67.0 3d 2d 3d
dco-signoff: yes
size/XS
dependencies
ok-to-test
contributor-last
recv
recv-q
unreviewed
728 Deprioritize resync operations 7mo 8d 6mo
dco-signoff: yes
size/S
ok-to-test
needs-rebase
commented
contributor-last
recv
recv-q
reviewed-with-comment
637 Fix/chartadditional annotations for cli args 11mo 8d 8d
dco-signoff: yes
size/XS
ok-to-test
commented
member-last
reviewed-with-comment
send
885 Adopt shared security-scan workflow and document pre/post-release checks 3wk 8d 3wk
dco-signoff: yes
size/L
do-not-merge/hold
needs-rebase
commented
contributor-last
recv-q
unreviewed
891 Trial: property-based tests with hegel-go 3wk 12d
dco-signoff: yes
size/XL
do-not-merge/work-in-progress
needs-rebase
contributor-last
draft
recv-q
similar
unreviewed
903 fix(istiodcert): name the DNS name that failed validation 16d 16d 16d
dco-signoff: yes
size/L
needs-ok-to-test
contributor-last
recv
recv-q
unreviewed
896 DO NOT MERGE: Test tools-cache verify-at-use (makefile-modules#710) 19d 19d 19d
dco-signoff: yes
size/L
do-not-merge/hold
do-not-merge/work-in-progress
needs-rebase
commented
contributor-last
draft
recv-q
unreviewed
768 Add unit tests for pkg/tls Provider 5mo 2wk 5mo
dco-signoff: yes
size/L
needs-ok-to-test
needs-rebase
contributor-last
recv
recv-q
unreviewed
890 Expand RELEASE.md with the full v0.17.0 release process 3wk 3wk
dco-signoff: yes
size/L
contributor-last
recv-q
unreviewed
860 feat(chart): expose automountServiceAccountToken in the istio-csr chart 2mo 2mo 2mo
dco-signoff: yes
size/S
needs-ok-to-test
contributor-last
recv
recv-q
similar
unreviewed
852 Replace Istio log package with structured logr in auth.go 2mo 2mo 2mo
dco-signoff: yes
size/XS
needs-ok-to-test
contributor-last
recv
recv-q
unreviewed
1020 chore(deps): update module google.golang.org/grpc to v1.83.2 [security] 1d 1h 1d
dco-signoff: yes
size/XS
ok-to-test
dependencies
contributor-last
recv
recv-q
similar
unreviewed
1021 Bump google.golang.org/grpc from 1.83.1 to 1.83.2 in the go_modules group across 1 directory 1d 1d 1d
dco-signoff: yes
size/XS
needs-ok-to-test
dependencies
go
contributor-last
recv
recv-q
unreviewed
976 feat: add startupapicheck Job to verify webhook readiness 5wk 2d 5wk
dco-signoff: yes
needs-ok-to-test
size/XL
author-last
recv
recv-q
similar
unreviewed
989 Trial hegel-go property-based tests 3wk 18d
dco-signoff: yes
do-not-merge/work-in-progress
needs-rebase
size/XXL
contributor-last
draft
recv-q
similar
unreviewed
937 Document additional pre- and post-release checks in RELEASE.md 2mo 5wk 2mo
dco-signoff: yes
size/L
commented
member-last
new-commits
send
628 Grant cert-manager RBAC to use all policies by default 1y 10mo 10mo
dco-signoff: yes
size/M
commented
contributor-last
recv-q
send
unreviewed
868 feat(annotations): Add annotation-based policy enforcement 5mo 2mo 5mo
dco-signoff: yes
size/L
needs-rebase
contributor-last
recv
recv-q
reviewed-with-comment
1097 chore(deps): update makefile modules to 3802a00 1d 1d 1d
dco-signoff: yes
size/M
ok-to-test
dependencies
skip-review
contributor-last
recv
recv-q
unreviewed
918 add bundle metrics
2
5mo 10d 3mo
dco-signoff: yes
size/XL
ok-to-test
needs-rebase
commented
contributor-last
new-commits
recv
recv-q
946 feat: add keepCertHistory for automatic CA cert retention on rotation 4mo 10d 2mo
dco-signoff: yes
needs-ok-to-test
needs-rebase
size/XXL
commented
contributor-last
recv-q
reviewed-with-comment
send
900 chart: add startupapicheck to ensure trust-manager is ready after install 6mo 14d 6mo
dco-signoff: yes
needs-ok-to-test
size/XL
needs-rebase
contributor-last
recv
recv-q
unreviewed
1064 Trial hegel-go property-based tests 3wk 3wk
dco-signoff: yes
do-not-merge/work-in-progress
needs-rebase
size/XXL
contributor-last
draft
recv-q
similar
unreviewed
395 WIP: feat: inject bundle data into configmap 2y 6wk 7mo
dco-signoff: yes
size/L
do-not-merge/work-in-progress
lifecycle/stale
commented
contributor-last
unreviewed
702 User-facing migration to ClusterBundle
1y 3wk 3wk
dco-signoff: yes
approved
lgtm
do-not-merge/hold
size/XXL
approved
commented
contributor-last
recv-q
654 Add design for trust source plugins
1y 7wk 1y
dco-signoff: yes
size/M
do-not-merge/work-in-progress
lifecycle/stale
commented
contributor-last
draft
reviewed-with-comment
send
948 release: publish trust-manager.crds.yaml as a GitHub Release artifact 4mo 3mo 3mo
dco-signoff: yes
size/M
needs-ok-to-test
needs-rebase
commented
contributor-last
recv-q
send
unreviewed
958 feat: add startupapicheck job to ensure webhook readiness on install 4mo 3mo 4mo
needs-ok-to-test
size/XL
needs-rebase
dco-signoff: no
contributor-last
recv
recv-q
similar
unreviewed
508 Fix certificaterequest denial status 17d 17d 17d
kind/bug
dco-signoff: yes
size/M
needs-ok-to-test
contributor-last
recv
recv-q
similar
unreviewed
497 Property-based-testing trial with hegel-go 3wk 17d
dco-signoff: yes
size/XXL
needs-rebase
do-not-merge/work-in-progress
contributor-last
draft
recv-q
similar
unreviewed
324 [VC-35742] Handle canceled context to prevent extra retries 1y 11mo 11mo
dco-signoff: yes
size/S
do-not-merge/work-in-progress
needs-ok-to-test
commented
draft
member-last
send
unreviewed
188 Remove SetCertificateRequestConditionError
3
2y 6mo 6mo
dco-signoff: yes
size/XXL
commented
member-last
new-commits
similar
186 Remove GetIssuerTypeIdentifier from Issuer API 2y 1y
dco-signoff: yes
needs-rebase
size/L
contributor-last
recv-q
unreviewed
24 Add conformance tests 3y 3y 3y
dco-signoff: yes
size/XXL
approved
needs-rebase
assigned
commented
contributor-last
reviewed-with-comment
746 Parse comma separated volume attributes as CSV 6d 2d 2d
dco-signoff: yes
size/L
needs-ok-to-test
commented
member-last
reviewed-with-comment
send
716 [demo] oci-security-scan: trivy image scanning via makefile-modules 5wk 4wk 5wk
dco-signoff: yes
size/L
do-not-merge/work-in-progress
needs-rebase
commented
contributor-last
draft
recv-q
unreviewed
700 feat(chart): expose automountServiceAccountToken in the csi-driver chart 2mo 2mo 2mo
dco-signoff: yes
size/S
needs-ok-to-test
contributor-last
recv
recv-q
similar
unreviewed
753 chore(deps): update module google.golang.org/grpc to v1.83.2 [security] 1d 1h 1d
dco-signoff: yes
size/XS
ok-to-test
dependencies
contributor-last
recv
recv-q
similar
unreviewed
650 NodePublishSecretRef 3mo 3mo 3mo
size/L
dco-signoff: no
needs-rebase
needs-ok-to-test
contributor-last
recv
recv-q
unreviewed
672 feat(chart): make pod and sidecar securityContext configurable 2mo 2mo 2mo
dco-signoff: yes
size/L
needs-ok-to-test
author-last
commented
recv
unreviewed
642 fix: allow disabling PKCS12 without password 4mo 3mo 3mo
dco-signoff: yes
size/M
ok-to-test
commented
member-last
reviewed-with-comment
send
502 Enable csi-lib metrics 10mo 6mo 6mo
dco-signoff: yes
size/S
needs-rebase
ok-to-test
commented
member-last
reviewed-with-comment
send
251 PoC: Generate SPIFFE identities in csi-driver 2y 2y 2y
dco-signoff: yes
size/S
do-not-merge/work-in-progress
needs-rebase
commented
contributor-last
draft
recv-q
unreviewed
129 Add attribute support for certificate subject
3y 2y 3y
dco-signoff: yes
size/L
needs-rebase
ok-to-test
commented
contributor-last
reviewed-with-comment
send
135 Added options to all containers 3y 2y 3y
dco-signoff: yes
size/L
needs-rebase
ok-to-test
commented
contributor-last
send
unreviewed
607 fix(deps): update module github.com/go-jose/go-jose/v4 to v4.1.5 3d 2d 3d
dco-signoff: yes
size/XS
ok-to-test
dependencies
contributor-last
recv
recv-q
similar
unreviewed
612 chore(deps): update module google.golang.org/grpc to v1.83.2 [security] 1d 1h 1d
dco-signoff: yes
size/XS
ok-to-test
dependencies
contributor-last
recv
recv-q
similar
unreviewed
594 fix(driver): return an error instead of panicking on a non-PEM issued chain 16d 2d 16d
dco-signoff: yes
size/L
needs-ok-to-test
contributor-last
recv
recv-q
reviewed-with-comment
similar
586 Trial hegel-go property-based tests on the SPIFFE approver and driver 3wk 3wk
dco-signoff: yes
size/XL
do-not-merge/work-in-progress
needs-rebase
contributor-last
draft
recv-q
similar
unreviewed
577 [DO NOT MERGE] Demo: oci-security-scan for multi-image repos 5wk 5wk 5wk
dco-signoff: yes
size/L
do-not-merge/work-in-progress
needs-rebase
commented
draft
member-last
unreviewed
564 feat(chart): expose automountServiceAccountToken in the csi-driver-spiffe chart 2mo 2mo 2mo
dco-signoff: yes
size/S
needs-ok-to-test
contributor-last
recv
recv-q
similar
unreviewed
538 feat(chart): make pod and sidecar securityContext configurable 2mo 2mo 2mo
dco-signoff: yes
size/L
ok-to-test
author-last
commented
new-commits
recv
107 Remove csi-driver-spiffe approver 2y 2y
size/XXL
dco-signoff: no
do-not-merge/work-in-progress
needs-rebase
contributor-last
draft
unreviewed
148 limit-namespaces for namespace-scope deployments
2y 5mo 2y
dco-signoff: no
size/S
needs-ok-to-test
contributor-last
recv
recv-q
unreviewed
303 feat: add support for setting private key encoding 9mo 8mo 9mo
dco-signoff: yes
size/L
needs-ok-to-test
recv
recv-q
reviewed-with-comment
117 fill spec.tls.caCertificate in route with intermediate ca certificate…
2y 2y 2y
dco-signoff: yes
size/M
needs-rebase
ok-to-test
commented
contributor-last
new-commits
recv-q
send
288 fix(manager): return an error instead of panicking on a non-PEM issued chain 16d 2d 2d
dco-signoff: yes
size/S
needs-ok-to-test
commented
member-last
reviewed-with-comment
send
similar
279 Trial: hegel-go property-based tests 3wk 11d
dco-signoff: yes
size/XL
do-not-merge/work-in-progress
needs-rebase
contributor-last
draft
recv-q
similar
unreviewed
223 NodePublishSecretRef 3mo 3mo 3mo
dco-signoff: no
size/L
needs-ok-to-test
contributor-last
recv
recv-q
unreviewed
211 Fix: concurrent NodePublishVolume calls could mount volume without certificates 4mo 4mo 4mo
dco-signoff: yes
size/L
needs-ok-to-test
contributor-last
recv
recv-q
unreviewed
71 Refactor filesystem.go and adapt tests to use a real file system 2y 1y 1y
dco-signoff: yes
size/L
commented
member-last
reviewed-with-comment
215 chore(deps): update module google.golang.org/grpc to v1.83.2 [security] 1d 1h 1d
dco-signoff: yes
size/XS
dependencies
ok-to-test
contributor-last
recv
recv-q
similar
unreviewed
587 chore(deps): update module google.golang.org/grpc to v1.83.2 [security] 1d 1h 1d
dco-signoff: yes
size/S
dependencies
ok-to-test
contributor-last
recv
recv-q
similar
unreviewed
88 chore(deps): update terraform google to v7.46.1 2mo 1d 2mo
dco-signoff: yes
size/L
dependencies
ok-to-test
contributor-last
recv
recv-q
unreviewed
90 chore(deps): update terraform google to v8 13d 1d 13d
dco-signoff: yes
size/L
dependencies
ok-to-test
contributor-last
recv
recv-q
unreviewed
1236 Update k8s-infra-prow images as needed 2d 1d 2d
dco-signoff: yes
size/M
contributor-last
recv
recv-q
unreviewed
1160 config: exempt Copilot-authored PRs from DCO requirement in Tide 6mo 5mo 5mo
dco-signoff: no
size/S
do-not-merge/work-in-progress
needs-ok-to-test
commented
draft
member-last
send
unreviewed
739 chore(deps): update renovate/renovate docker tag to v44.65.5 1d 1h 1d
dco-signoff: yes
size/XS
dependencies
ok-to-test
contributor-last
recv
recv-q
unreviewed
740 chore(deps): update module github.com/goreleaser/goreleaser/v2 to v2.18.1 1d 1d 1d
dco-signoff: yes
size/XS
dependencies
ok-to-test
contributor-last
recv
recv-q
similar
unreviewed
723 feat: add make target to upload SBOMs to GitHub releases 10d 2d 10d
dco-signoff: yes
size/S
author-last
recv
recv-q
reviewed-with-comment
710 Verify the tool cache against reviewed hashes at link time 19d 7d 16d
dco-signoff: yes
size/L
needs-rebase
commented
contributor-last
new-commits
recv-q
653 Remove unused olm-bundle module 2mo 10d 2mo
dco-signoff: yes
needs-rebase
size/XL
commented
contributor-last
recv-q
reviewed-with-comment
492 chore(deps): update module github.com/sigstore/cosign/v2 to v3
9mo 13d 13d
dco-signoff: yes
size/S
do-not-merge/hold
dependencies
ok-to-test
commented
contributor-last
recv
similar
unreviewed
625 Add cache validation 3mo 19d 19d
dco-signoff: yes
approved
size/L
commented
member-last
reviewed-with-comment
send
688 oci-build: add oci-security-scan target and scheduled workflow 5wk 3wk 3wk
dco-signoff: yes
size/L
commented
member-last
reviewed-with-comment
651 Add OSSF Scorecard workflow to gh-workflows module 2mo 4wk 4wk
dco-signoff: yes
size/L
commented
member-last
reviewed-with-comment
send
655 Fix 'make verify' command 2mo 2mo 2mo
dco-signoff: yes
size/XS
commented
member-last
reviewed-with-comment
549 WIP: Split (helm) generate-crds target 6mo 2mo 6mo
dco-signoff: yes
size/M
do-not-merge/work-in-progress
commented
draft
member-last
reviewed-with-comment
293 Add Helm chart image baking 1y 1y
dco-signoff: yes
size/S
needs-rebase
contributor-last
recv-q
similar
unreviewed
55 feat: add test module 2y 2y 2y
dco-signoff: yes
size/M
commented
contributor-last
recv
reviewed-with-comment
312 Add YAML merge key (<<) support to the values walk 5wk 5wk 5wk
dco-signoff: yes
size/L
approved
do-not-merge/hold
commented
member-last
reviewed-with-comment
send
104 Add Chart image baking 1y 1y 1y
dco-signoff: yes
size/L
needs-rebase
commented
member-last
reviewed-with-comment
send
similar
69 Add auditing tool for confirming who has access to the cert-manager org 5mo 5mo
dco-signoff: yes
size/XL
contributor-last
recv-q
unreviewed
11 Governance: folks meaningfully contributing to the biweekly can become GitHub Members 3y 9mo
do-not-merge/work-in-progress
dco-signoff: yes
size/S
draft
reviewed-with-comment
64 Add imagePullSecrets to template 2y 3wk 2y
size/XS
dco-signoff: yes
needs-ok-to-test
contributor-last
new-commits
recv
recv-q
147 chore(deps): update module google.golang.org/grpc to v1.83.2 [security] 1d 1h 1d
size/XS
dco-signoff: yes
ok-to-test
dependencies
contributor-last
recv
recv-q
similar
unreviewed
1 Manage the cert-manager GitHub organisation from this repo 2y 2y 2y
dco-signoff: yes
size/XXL
commented
member-last
unreviewed
8 Optionally output a unified diff
9mo 4mo 7mo
dco-signoff: yes
needs-rebase
size/XL
needs-ok-to-test
commented
contributor-last
recv
recv-q
unreviewed
13 Various QA fixes 6mo 6mo 6mo
dco-signoff: yes
size/L
needs-ok-to-test
author-last
commented
new-commits
recv
4 Add support for custom license templates 3y 1y
dco-signoff: yes
size/S
contributor-last
recv-q
unreviewed
562 fix: merge commonLabels as a map to avoid duplicate label keys 6wk 1d 1d
size/S
dco-signoff: yes
commented
member-last
reviewed-with-comment
send
486 feat: propagate Kubernetes metadata to Google CAS labels
4mo 4wk 4mo
size/L
needs-rebase
dco-signoff: yes
commented
contributor-last
recv-q
reviewed-with-comment
send
501 feat: add secondary CA pool failover support for high availability 4mo 4wk 4wk
size/XL
dco-signoff: yes
approved
commented
contributor-last
recv-q
send
553 feat(chart): expose automountServiceAccountToken in the google-cas-issuer chart 2mo 2mo 2mo
size/S
dco-signoff: yes
contributor-last
recv
recv-q
similar
unreviewed
143 feat: allow creating or reusing an existing sa 2y 4mo 2y
needs-rebase
ok-to-test
contributor-last
recv
recv-q
unreviewed
159 Split certificate chain 2y 5mo 2y
needs-rebase
commented
contributor-last
recv-q
reviewed-with-comment
send
141 re-adding required clusterrole permission 2y 2y 2y
size/XS
author-last
recv
unreviewed

Open Issues (371)

Resolution:

Average age: 761.7d, Avg wait: 267.4d
ID Au Desc As Rea Cr Up Re Cmntrs Labels Tags
9296 ingress-shim: certNeedsUpdate ignores ipAddresses, so IP SAN changes never reach existing Certificates 2d 2d
kind/bug
9252 e2e flake: Pebble unreachable for an entire run, failing all ACME conformance tests with 'Failed to register ... context deadline exceeded' 8d 8d
kind/flake
9251 Flaky integration test: TestGeneratesNewPrivateKeyPerRequest fails during test environment startup 8d 8d
kind/flake
9298 Webhook accepts duplicate dnsNames and ipAddresses, which fail ACME issuance with an opaque badCSR error 2d 2d
kind/bug
9246 Flaky test: expirationSeconds notAfter tests fail when elapsed time exceeds 2s tolerance by milliseconds 8d 8d
kind/flake
9242 Flaky unit test: TestDynamicAuthority fails with `secrets "test-secret" not found` 8d 8d
9249 Flaky unit test: certificate-shim Test_controller_Register shuts its queue down on a fixed 50ms timer 8d 8d
kind/flake
pr-unreviewed
9210 ACME HTTP-01 Ingress solver's pathType: Exact is not supported by OpenShift's Ingress-to-Route conversion
12d 4d 4d
commented
member-last
pr-closed
send
9158 Configured Kubernetes API QPS is ignored when APF is enabled 3wk 3wk 3wk
kind/bug
commented
contributor-last
pr-changes-requested
pr-unreviewed
recv
9155 Property-based testing across the cert-manager projects: trial results and findings 3wk 3wk
9237 Release cert-manager v1.21.2
8d 19h 4d
commented
member-last
pr-merged
9266 Enable the race detector in CI: go test -race currently fails in 7 packages
6d 5d
kind/cleanup
area/testing
contributor-last
pr-merged
9123 Automate kubeVersion bump in Chart.template.yaml alongside Kind version updates 4wk 4wk 4wk
kind/feature
recv
9115 Vault SDK v0.25.1 BUSL-licensed files and cert-manager dependency 4wk 3wk 3wk
collaborator-last
commented
send
9103 Support gating pod scheduling on driver registration (startup taint removal) 4wk 3wk 4wk
kind/feature
recv
recv-q
9126 Issuing stalls silently when a CertificateRequest has a failureTime but no Ready condition 4wk 6d 6d
kind/bug
commented
member-last
pr-merged
pr-unreviewed
send
similar
9085 Implement per-Certificate Secret deletion policy
3
6wk 6wk 6wk
kind/feature
recv
9076 Auto-renew leaf TLS certificates when CA certificate rotates (SKI/AKI mismatch prevention) 6wk 6wk 6wk
kind/feature
recv
9066 Improving Roue53 DNS Challenge Presentation to avoid repeated creation of same ChangeRecord
3
6wk 19d 19d
commented
member-last
pr-new-commits
pr-reviewed-with-comment
send
9280 HTTP-01 self-check custom nameservers do not fail over when one server does not respond
4d 3d
kind/bug
area/acme
pr-merged
recv-q
9029 respect owner references 1mo 1mo 1mo
kind/feature
pr-unreviewed
recv
9034 helm chart: add network policy for `startupapicheck` job
2
7wk 7wk 7wk
kind/feature
author-last
recv
9026 Publish webhook ACME API in a distinct go module 1mo 4d 4d
kind/feature
commented
member-last
pr-reviewed-with-comment
pr-unreviewed
send
9021 Support global tolerations and affinity similar to nodeSelector in the Helm Chart
1mo 7wk 7wk
kind/feature
commented
member-last
send
9146 Renewal windows that can never be satisfied pass admission; the Certificate is left permanently Ready=False and renewed outside its windows 3wk 3wk
kind/bug
pr-unreviewed
8929 Post-Quantum Cryptography: Plan ML-DSA certificate support for Go 1.27 2mo 3wk 2mo
pr-unreviewed
recv
recv-q
8960 Concurrent ACME Order finalization failure when issuing identical Certificates with different privateKey algorithms (RSA vs ECDSA) 2mo 2mo 2mo
kind/bug
pr-new-commits
recv
8895 [HELM]: add flag to skip deployment of webhook 2mo 2mo 2mo
kind/feature
pr-unreviewed
recv
8876 cert-manage - random high cpu usage 2mo 2mo 2mo
kind/bug
author-last
recv
8853 Gateway-derived Certificate includes hostnames already covered by wildcard listener, causing ACME Order failure
2
3mo 7wk 2mo
kind/bug
commented
pr-reviewed-with-comment
send
8847 Certificate Stuck In Failed Renewal State 3mo 2mo 3mo
kind/bug
contributor-last
recv
similar
8835 Make signatureAlgorithm configurable 3mo 1mo 3mo
kind/feature
recv
recv-q
8776 When performing DNS challenges, the Describe Domains interface is subject to rate limiting 4mo 2d 4mo
kind/bug
recv
recv-q
8767 Add support for CRLDistributionPoints on Certificate resources
4mo 4mo 4mo
kind/feature
commented
member-last
pr-closed
send
similar
8763 Minimize cert-manager and trust-manager Controller Privileges 4mo 4mo 4mo
kind/feature
recv
9100 Controller panic (nil pointer) at checks.go:316 when a renewal window errors, e.g. windowDuration: 0s 5wk 3wk 3wk
kind/bug
commented
member-last
pr-closed
pr-reviewed-with-comment
pr-unreviewed
8745 helm verify fails due to filename containing a 'v' prefix on the version in the provenance file 4mo 4mo 4mo
kind/bug
author-last
recv
8733 Updates or removal of solver ingress class annotations on ingresses are not propagated to existing certificates
4mo 2d 2d
kind/bug
commented
member-last
pr-merged
pr-reviewed-with-comment
send
8716 Feature Request: Add a CMPv2 issuer for certificate enrollment and renewal (RFC 4210) 4mo 5d 4mo
kind/feature
commented
recv
recv-q
8702 202 Accepted Response - Certificate Request failed - Unexpected status code on TPP Certificate Request. 5mo 3wk 3wk
commented
member-last
send
8679 Allow managing SSH-CA 5mo 2mo 5mo
kind/feature
recv
8659 v1.20.1 release progress tracking 5mo 5mo
8656 v1.20.0 release progress tracking 5mo 5mo
8641 ContribFest KubeCon EU 2026 - Amsterdam (March 24, 2026) 5mo 5mo 5mo
kind/documentation
commented
member-last
8586 Misconfiguration caused hammering of DigitalOcean API 6mo 4d 6mo
kind/bug
lifecycle/stale
contributor-last
pr-unreviewed
recv
8572 Solver ingressTemplate annotations are not applied to existing Ingress resources when acme.cert-manager.io/http01-edit-in-place: 'true' is set
6mo 5mo 6mo
kind/bug
author-last
pr-closed
recv
similar
8530 Allow usage of the new DNS-PERSIST-01 challange for ACME
27
6mo 19d 6mo
kind/feature
lifecycle/stale
contributor-last
recv
similar
8522 Support pulling additional fields from secret when using external account binding
2
6mo 3wk 6mo
kind/feature
lifecycle/stale
contributor-last
recv
recv-q
8512 ArtifactHub install command causes Helm fallback warning due to missing v prefix 6mo 3mo 6mo
recv
8754 Test Flake: TestDynamicAuthorityMulti: authority_test.go:175: Timeout waiting for rotation 4mo 8d 8d
kind/flake
commented
member-last
pr-reviewed-with-comment
send
8499 Add custom labels to be exposed in prometheus metrics 7mo 2mo 2mo
kind/feature
area/monitoring
assigned
assignee-updated
commented
member-last
pr-closed
pr-reviewed-with-comment
send
8479 Subject Key Identifier (SKI) missing on issued certificates by self-signed CA 7mo 5wk 7mo
kind/feature
lifecycle/stale
contributor-last
pr-new-commits
recv
8458 Vault approle configuration
2
7mo 5wk 7mo
kind/feature
lifecycle/stale
contributor-last
recv
8450 Introducing DelayedInformers for CRD check 7mo 5wk 7mo
kind/feature
lifecycle/stale
assigned
assignee-updated
commented
contributor-last
send
9275 e2e flake: kind API server drops mid-run, failing hundreds of specs with EOF / connection reset 5d 5d
8441 Add instrumentation to Vault issuer Sign() operation 7mo 4wk 7mo
good first issue
kind/feature
priority/backlog
lifecycle/stale
assigned
assignee-updated
commented
contributor-last
pr-unreviewed
recv
recv-q
8416 Make Venafi client timeout configurable for slower servers 7mo 5wk 7mo
kind/feature
lifecycle/stale
commented
contributor-last
send
8402 ZeroSSL issues all certs with the same hour (yyyy-mm-ddT15:59:59Z) 7mo 5mo 5mo
kind/feature
priority/important-longterm
author-last
commented
recv
8378 Support `PodCertificateRequest`
3
5
8mo 16d 8mo
kind/feature
commented
send
similar
8434 Allow external account binding (EAB) with ECC keys 7mo 7wk 7wk
good first issue
kind/feature
priority/backlog
commented
member-last
pr-closed
pr-reviewed-with-comment
send
8372 HTTP-01 challenge: support stateless http-01 challenge 8mo 2mo 8mo
kind/feature
lifecycle/stale
contributor-last
recv
8364 Replace Hetzner DNS01 Webhook 8mo 2mo 8mo
lifecycle/stale
commented
contributor-last
send
8340 Top-level: CA Issuer rotation problem 9mo 2mo
lifecycle/stale
cybr
contributor-last
8373 DNS-PERSIST-01 challenge support (planned for late Q1 2026)
8
3
3
205
8mo 4mo 8mo
kind/feature
recv
recv-q
similar
8319 Improve cert-manager's event handler to allow us to selectively skip some reconciliations 9mo 2mo
lifecycle/stale
cybr
contributor-last
8309 Dependency Dashboard
9mo 1h 9mo
pr-merged
recv
8280 Unblocking SSA: Document changes in SSA-by-default 9mo 19d 19d
cybr
commented
member-last
send
8296 HTTP-01 challenge stuck in pending with status code 400 9mo 2mo 8mo
triage/support
lifecycle/stale
commented
contributor-last
send
8277 Unblocking Server Side Apply (SSA) by Default 9mo 19d 19d
cybr
commented
member-last
send
8279 Unblocking SSA: Fix unit tests 9mo 15d
lifecycle/rotten
cybr
contributor-last
8235 Cert-manager support for Issuer-managed keys 10mo 6wk 10mo
kind/feature
lifecycle/stale
commented
recv
recv-q
8209 Add revocation at certificate deletion
3
10mo 3mo 10mo
kind/feature
author-last
recv
similar
8194 Update e2e Documentation - for the make e2e-setup command 10mo 7wk 10mo
kind/feature
lifecycle/rotten
commented
contributor-last
send
8183 Add helm diff output to cert-manager PRs 10mo 3d 3wk
lifecycle/stale
assigned
assignee-updated
commented
send
8121 Support for Creating CertificateRequest from Kubernetes Secret 11mo 5wk 11mo
kind/feature
triage/needs-information
lifecycle/rotten
contributor-last
recv
recv-q
similar
8102 cert-manager-startupapicheck erroring while installation
4
11mo 3mo 9mo
kind/bug
lifecycle/stale
triage/needs-information
commented
contributor-last
send
8094 HTTP-01 challenge returns 502 with App Gateway (works with NGINX ingress controller) 11mo 5wk 11mo
lifecycle/stale
contributor-last
recv
recv-q
8086 ACME ClusterIssuer not recovering after Vault restart 11mo 3wk 3wk
kind/bug
lifecycle/rotten
commented
member-last
send
8082 EOF during self check with Pomerium 11mo 2mo 11mo
lifecycle/rotten
contributor-last
recv
8058 Cert-manager fails to import ECDSA private keys generated by openssl 1y 5d 1y
kind/bug
priority/important-longterm
pr-changes-requested
pr-reviewed-with-comment
recv
recv-q
8939 ACME with let's encrypt: treat 404 statuses as retryable errors
2
2mo 19h 19h
kind/bug
commented
member-last
pr-closed
send
8884 Deprecate and remove HMAC-MD5 and HMAC-SHA1 support from the RFC2136 DNS01 solver 2mo 2mo 2mo
recv
7879 Remove no-op certificate metrics controller 1y 2mo 1y
kind/feature
priority/backlog
lifecycle/rotten
assigned
assignee-updated
commented
contributor-last
7868 Metrics for webhook certificate
3
1y 5wk 1y
kind/feature
lifecycle/rotten
contributor-last
recv
7862 Requesting a certificate from ZeroSSL sometimes takes more than 10 minutes to complete
7
1y 2mo 1y
kind/bug
lifecycle/rotten
contributor-last
recv
7846 ClusterIssuer.Status.Acme.URI disappeared
5
1y 2mo 1y
good first issue
kind/bug
priority/awaiting-more-evidence
area/acme
triage/needs-information
assigned
assignee-updated
commented
send
7845 ClusterIssuer.cert-manager.io "letsencrypt" is invalid: spec.acme.privateKeySecretRef: Required value...
6
1y 6d 6d
kind/bug
priority/awaiting-more-evidence
area/acme
triage/needs-information
lifecycle/rotten
commented
member-last
send
7834 Provide race condition mitigation support 1y 2mo 1y
kind/feature
lifecycle/stale
contributor-last
recv
7828 Cert-manager created multiple CertificateRequests (over 30k) for a valid certificate
1y 4wk 1y
kind/bug
lifecycle/rotten
commented
contributor-last
send
8251 Top-level ticket: ListenerSet
8
9mo 4mo 6mo
cybr
commented
pr-merged
recv-q
send
7821 Request to support AWS ACM Exportable certificates
59
1y 2mo 11mo
kind/feature
commented
send
similar
7788 Be able to default `acme.cert-manager.io/http01-edit-in-place: "true"` behavior in deployment/chart values
5
1y 3mo 9mo
kind/feature
author-last
commented
recv
7822 Tracking: Kubernetes Gateway API follow up tasks
5
1y 3mo 9mo
lifecycle/frozen
commented
contributor-last
pr-merged
send
7779 RevisionHistoryLimit should follow Kubernetes definition
1y 7wk 3mo
commented
pr-closed
recv-q
send
7768 Stuck in a loop with `multiple challenge solver pods found for challenge` 1y 15h 1y
kind/bug
lifecycle/rotten
contributor-last
pr-new-commits
recv
7751 Custom key usage extensions 1y 6mo 7mo
kind/feature
commented
recv
recv-q
7766 Certificate: Let me specify the concatenation order for CombinedPEM output format
1y 6mo 1y
kind/feature
author-last
pr-new-commits
recv
recv-q
7747 [suggestion] Add Kustomize install documentation
5
6
1y 2mo 1y
kind/feature
lifecycle/rotten
commented
contributor-last
recv
recv-q
7699 Adding Helm Unittest to all certmanager projects 1y 4mo 4mo
priority/backlog
assigned
assignee-updated
commented
member-last
send
9295 ingress-shim: alt-names and ip-sans annotations re-introduce duplicate SANs after #8978 2d 2d
kind/bug
7585 Continuous access token requests when using Venafi TPP password/username authentication
2y 4d 4d
kind/bug
lifecycle/rotten
commented
member-last
pr-closed
pr-unreviewed
send
7561 Feature Request RFC: Push notifications from cert-manager to <other service> when certificates are issued 2y 4mo 10mo
kind/feature
author-last
commented
recv
recv-q
7551 Unhelpful log messages 2y 9mo
lifecycle/frozen
contributor-last
pr-reviewed-with-comment
7536 Digicert ACME order is failing due to invalid validity_years
5
2y 8d 8d
good first issue
lifecycle/frozen
kind/feature
priority/backlog
area/acme
commented
member-last
pr-closed
send
7531 punycode issue 2y 3wk 2y
author-last
recv
recv-q
7522 Non standard "cert-manager.io" used in event "Reason" 2y 10mo 1y
lifecycle/frozen
kind/bug
commented
contributor-last
pr-unreviewed
recv
7520 ClusterIssuer read caBundle from Secret
7
2y 6d 1y
kind/feature
lifecycle/rotten
commented
contributor-last
pr-closed
send
7514 Replace some of the webhook functionality with `ValidatingAdmissionPolicy` & CEL
2y 6mo 1y
kind/feature
priority/important-longterm
author-last
commented
recv
7510 Key Size for Acme Account Key
2y 4wk 4wk
kind/feature
commented
member-last
pr-closed
send
7492 `UseCertificateRequestBasicConstraints` should probably add `Critical` for `isCA` 2y 10mo 1y
lifecycle/frozen
commented
contributor-last
recv
7486 `"Unhandled Error" err="ingress '...' in work queue no longer exists"` should be handled (clean up dangling `Certificate`)
6
2y 10mo 2y
lifecycle/frozen
kind/bug
contributor-last
pr-closed
recv
recv-q
7645 Support cross-signed intermediate CAs issued with Vault
5
1y 3wk 3wk
kind/feature
commented
member-last
pr-closed
pr-reviewed-with-comment
pr-unreviewed
send
7476 [Helm Chart] - Wrong handling of image registry and repository
4
2y 5mo 9mo
kind/bug
commented
pr-closed
send
8493 cloudflare DNS01 - Client.Timeout exceeded while awaiting headers
4
11
7mo 5mo 6mo
good first issue
help wanted
kind/bug
assigned
assignee-updated
commented
pr-unreviewed
recv-q
send
7311 helm schema validation should validate `featureGates`
2y 8mo 1y
lifecycle/frozen
kind/feature
priority/backlog
commented
contributor-last
recv
7895 if certificate is already expired, it shown like a True
2
1y 4mo 4mo
help wanted
priority/important-soon
collaborator-last
commented
pr-closed
pr-reviewed-with-comment
pr-unreviewed
send
6969 Should upgrade status managed fields from CSA to SSA when ServerSideApply feature gate enabled 2y 2y 2y
lifecycle/frozen
kind/bug
priority/important-longterm
commented
contributor-last
send
6820 Ongoing dependency evaluation
2y 2y 2y
lifecycle/frozen
priority/important-longterm
contributor-last
recv
6741 ACME account private key and URI are not updated if the path of the ACME server is changed
7
2y 9mo 2y
lifecycle/frozen
kind/bug
priority/important-soon
pr-unreviewed
recv
6716 leader election namespace should default to `.Release.Namespace`, not `kube-system`
3
45
2y 6mo 2y
lifecycle/frozen
kind/bug
triage/not-reproducible
commented
pr-closed
pr-unreviewed
recv-q
send
6709 1.14 Release Review
3
2y 2y 2y
lifecycle/frozen
priority/important-soon
commented
contributor-last
send
7598 More fine-grained control of powerful RBAC permission granted via Helm chart
2
5
2y 4d 4d
kind/feature
priority/important-longterm
assigned
assignee-updated
commented
member-last
pr-merged
pr-unreviewed
send
6470 ingress-shim: allow to impersonate ingress-creator instead of using cert-manager serviceaccount
2
2y 2y 2y
lifecycle/frozen
kind/feature
priority/backlog
commented
contributor-last
send
6472 Create TLSA records automatically
18
2y 4wk 2y
kind/feature
priority/backlog
pr-reviewed-with-comment
recv
recv-q
6224 Option to store certificate history in individual secrets
2
3y 2mo 1y
kind/feature
commented
recv-q
send
6210 Flag to write/sync secrets to a namespace other than the namespace where the Certificate object is created
6
3y 4h 2y
kind/feature
priority/backlog
commented
send
6179 CRDs shouldn't be templated in Helm
5
2
32
3y 2mo 1y
priority/backlog
lifecycle/rotten
commented
recv-q
send
7890 Cluster issuer for HTTP-01 gatewayHTTPRoute should not require a gateway parentRef
28
1y 5mo 5mo
kind/feature
priority/awaiting-more-evidence
area/acme/http01
assigned
assignee-updated
commented
pr-merged
send
6010 Support the ACME Renewal Information (ARI) extension
4
5
21
3y 15d 1y
lifecycle/frozen
kind/feature
commented
pr-merged
recv
recv-q
similar
5959 `ImagePullBackoff` on `cm-acme-http-solver` pod, if using private registries
23
3y 9mo 2y
lifecycle/frozen
kind/bug
priority/important-longterm
commented
contributor-last
recv-q
send
7388 Kid missing in the new order request
2
2y 3wk 2y
kind/bug
lifecycle/rotten
contributor-last
pr-unreviewed
recv
recv-q
6051 Detecting Gateway hostnames based on attached HTTPRoutes
7
35
3y 1y 1y
lifecycle/frozen
kind/feature
priority/important-longterm
commented
pr-merged
send
5917 Waiting for DNS-01 challenge propagation: DNS record for mydomain.com not yet propagated
43
3y 5mo 3y
kind/bug
priority/important-longterm
assigned
assignee-updated
recv
recv-q
5540 Changelog annotations to chart
3y 7mo 3y
kind/feature
priority/backlog
author-last
recv
5298 Complete the Migration Away From Jetstack Names 4y 2y 2y
lifecycle/frozen
kind/cleanup
priority/important-soon
commented
member-last
send
5864 Certmgr allows creating certificates expiring after ca expiration.
4
33
3y 10mo 1y
lifecycle/frozen
kind/bug
cybr
commented
pr-closed
recv-q
send
7234 AWS Route53: Stale/Stuck Challenges should be deleted after a given timeout
5
2y 2d 2y
kind/bug
priority/important-soon
lifecycle/rotten
assigned
assignee-updated
commented
contributor-last
pr-closed
pr-merged
pr-reviewed-with-comment
recv
recv-q
4749 rfc2136 seems to not work with deep subdomains
4y 6wk 4y
kind/bug
lifecycle/rotten
area/acme/dns01
author-last
pr-reviewed-with-comment
recv
recv-q
7473 Create certificate based on HTTPRoute configuration
65
7
102
2y 5mo 5mo
kind/feature
assigned
assignee-updated
commented
pr-closed
pr-merged
send
4191 Setting default values for Pod's "resources"?
7
5y 2y 2y
lifecycle/frozen
priority/important-longterm
commented
contributor-last
recv-q
send
3992 Add non-CRD yaml file
5
5y 3mo 2y
priority/important-soon
area/deploy
author-last
commented
recv
3706 renewal-hooks
4
3
23
5y 3mo 3mo
kind/feature
priority/important-longterm
lifecycle/rotten
author-last
commented
pr-reviewed-with-comment
recv
recv-q
3521 Integration with ExternalDNS
4
55
5y 1y 2y
help wanted
lifecycle/frozen
kind/feature
priority/important-longterm
commented
recv-q
3381 Setup separate package for cert-manager API
6
5y 2y 2y
lifecycle/frozen
kind/feature
priority/important-soon
assigned
assignee-updated
commented
member-last
send
5101 No backoff/delay when failing to create challenge solver pods
9
4y 6d 9mo
kind/bug
priority/important-longterm
triage/needs-information
lifecycle/rotten
commented
contributor-last
pr-unreviewed
send
4950 General flakiness of our end-to-end suite
3
4y 14h 14h
lifecycle/frozen
priority/important-longterm
kind/flake
commented
member-last
pr-closed
pr-merged
send
2930 Mirror to gcr.io or dockerhub
2
29
6y 3mo 2y
lifecycle/frozen
kind/feature
priority/important-soon
area/deploy
assigned
assignee-updated
commented
recv-q
send
2820 Add ability to set `pathlen:0` for CA certs in `X509v3 Basic Constraints`
6y 5mo 5mo
area/api
good first issue
kind/feature
priority/important-longterm
assigned
assignee-updated
commented
pr-closed
pr-merged
recv-q
send
6230 DigitalOcean: cert-manager DDoSes DNS-01 solver - infinite rate limiting
6
3y 9mo 10mo
lifecycle/frozen
kind/bug
priority/critical-urgent
area/acme/dns01
commented
member-last
pr-closed
pr-merged
send
3103 Adding probes to the cert-manager pods
10
6y 2mo 7mo
good first issue
help wanted
kind/feature
priority/important-longterm
area/deploy
commented
pr-closed
pr-unreviewed
recv-q
send
3298 Let's encrypt certificate caching to mitigate rate limits problems
3
5
24
6y 5wk 2y
help wanted
kind/feature
priority/backlog
commented
send
5867 Controller can't handle hitting request rate limits of zerossl ACME API
7
12
31
3y 1y 2y
lifecycle/frozen
kind/bug
priority/important-soon
commented
pr-closed
pr-merged
recv-q
send
2538 cert-manager does not use ingress.class from Ingress annotated with cert-manager.io/cluster-issuer
74
6y 2y 2y
area/api
help wanted
lifecycle/frozen
kind/feature
priority/backlog
commented
send
2478 Allow CA issuer secret rotation
2
71
6y 3mo 3mo
kind/feature
priority/important-longterm
area/ca
commented
member-last
send
4685 Unexpected EOF during watch stream event decoding: unexpected EOF -- possibly due to api server upgrades / restarts
12
4y 10mo 10mo
lifecycle/frozen
kind/bug
priority/important-longterm
commented
contributor-last
recv
2178 Handling 'unregistering' certificates from Venafi TPP
22
7y 2y 2y
lifecycle/frozen
kind/feature
priority/important-longterm
area/venafi
commented
member-last
send
2525 Better support multi-namespace & single-namespace deployments
30
6y 1y 2y
lifecycle/frozen
kind/feature
priority/important-longterm
area/deploy
commented
contributor-last
pr-closed
send
2239 Create a CertificatePreset resource type to allow configurable defaulting
2
4
106
7y 2mo 1y
area/api
kind/feature
priority/backlog
priority/important-soon
commented
pr-closed
pr-unreviewed
recv-q
send
1935 add third party cert-manager-webhook-infomaniak 7mo 7mo 7mo
recv
1874 Dependency Dashboard 9mo 1h 9mo
recv
1806 Tutorial depends on no longer available image of kuard
4
11mo 11mo 11mo
recv
1926 Change the Cert Manager Webhook DNS01 of Hetzner Cloud
7mo 7mo 7mo
author-last
pr-closed
recv
1643 Let's Encrypt Ending Support for Notification Emails 2y 1y 2y
recv
1623 Claim about v1beta1/v1alpha2 support for gateway api is misleading 2y 2y 2y
recv
1620 Cert Manager allows the creation of Illegal wilcard SANs 2y 2y 2y
recv
1715 The ingress annotation `cert-manager.io/secret-template` is not documented
2
1y 1y
contributor-last
pr-unreviewed
similar
1608 Renaming Securing NGINX-ingress to ingress-nginx 2y 2mo 2y
contributor-last
pr-unreviewed
recv
1586 Now that cert-manager 1.16 has been released, `--set config.enableGatewayAPI=true` is now the recommended approach for projects that show instructions on how to enable cert-manager's gateway API support, especially on visible projects like Cilium:
2y 2y
pr-merged
1549 Brand guideline page 2y 2y 2y
priority/backlog
contributor-last
recv
1585 Broken install instructions due wrong cert_manager_latest_version - v1.16.1 2y 2y 2y
recv
1546 Self upgrade PRs don't run checks
2y 10mo 2y
cybr
commented
member-last
1490 GKE tutorial falsely claims it's possible to create LE certificate without domain (only IP) 2y 2y 2y
author-last
recv
1473 Add ArtifactHub packages to website 2y 2y 2y
priority/backlog
recv
1425 The `issuer.vault.spec.caBundleSecretRef` docs are missing 2y 2y
priority/important-soon
pr-reviewed-with-comment
1194 Confusing paragraph - cert-manager integration.
3y 5mo 3y
documentation
priority/important-longterm
commented
contributor-last
pr-merged
send
1186 Document that/why we don't use Helm's CRD installation mechanism 3y 2y 2y
good first issue
priority/important-longterm
kind/documentation
assigned
assignee-updated
commented
member-last
send
1101 Feature request for updating documentation. 3y 2y 2y
priority/backlog
commented
member-last
send
1063 "Securing Ingresses with Venafi" tutorial contains link to missing manifest
4y 2y 4y
priority/important-longterm
author-last
pr-merged
recv
1262 v1.9 to v1.10 upgrade instructions does not mention container name change
3y 2y 2y
priority/backlog
assigned
assignee-updated
commented
member-last
send
975 Some pages do not make it clear what the user should read next 4y 2y
priority/important-longterm
955 Document when the vault pki role required setting `require_cn=false`
2
4y 2y
priority/important-soon
850 Document available cert-manager Prometheus metrics
4y 3y 4y
documentation
good first issue
priority/important-longterm
pr-closed
recv
recv-q
944 Document how to install cert-manager in a different namespace
4
4y 2y 4y
good first issue
pr-unreviewed
recv
recv-q
484 Please add anchor tags to your subheadings
5y 5y 5y
priority/backlog
kind/documentation
commented
contributor-last
pr-merged
recv
802 Spelling errors are unclear in pull request CI results and spell checker is unmaintained
4y 2y
kind/bug
priority/important-soon
contributor-last
pr-merged
414 Explain cert-manager repo structure
2
5y 5y 5y
priority/backlog
kind/documentation
assigned
assignee-updated
commented
member-last
pr-closed
pr-merged
send
401 Bring tutorials up to date 5y 3y 3y
priority/important-longterm
commented
member-last
send
354 DigitalOcean access-token should not be base64-encoded 5y 5y 5y
priority/awaiting-more-evidence
author-last
pr-unreviewed
recv
recv-q
237 docs for ACMEChallengeSolverHTTP01Ingress doesn't specify what `class` values are available
6y 6y 6y
priority/backlog
kind/documentation
contributor-last
pr-closed
recv
320 Document how to install cert-manager using gitops and known issues with particular gitops implementations
5
6y 2y 6y
documentation
help wanted
priority/backlog
commented
pr-merged
recv-q
223 Document wildcard certificate tutorial 6y 6y 6y
priority/important-longterm
kind/documentation
commented
contributor-last
send
234 Backup and Restore Resources
3
6y 5y 5y
priority/backlog
kind/documentation
commented
member-last
pr-merged
send
197 Document ACME account mismatch 6y 2y 6y
good first issue
priority/backlog
kind/documentation
pr-changes-requested
recv
recv-q
174 Add documentation for CRD conversion webhook ca injection 6y 6y 6y
help wanted
priority/important-soon
kind/documentation
commented
member-last
send
155 Add 'unreleased version' & 'old version' warning banner to non-latest versions of docs 6y 6y 6y
kind/feature
priority/backlog
commented
contributor-last
130 FAQ: How does cert-manager handle ingresses with valid TLS secrets? 6y 6y 6y
help wanted
priority/backlog
kind/documentation
contributor-last
recv
76 Upgrading from v0.10 to v0.11 - missing cainjector annotation 6y 6y 6y
priority/backlog
kind/documentation
contributor-last
recv
2224 Content proposal: Certificate rotation beyond the Secret with Gateway API 4wk 4wk 4wk
recv
2009 The flag description "Enable client cert authenticate of apiserver to webhooks." is ungrammatical/unclear 6mo 6mo
2252 Dark theme support 8d 8d 8d
recv
195 Document keystores 6y 3y 6y
priority/important-soon
kind/documentation
commented
contributor-last
send
2 Set up periodic job to publish an experimental release build
6y 5y
priority/backlog
assigned
contributor-last
209 Dependency Dashboard
9mo 1h 9mo
pr-merged
recv
826 feat: add more logs to readiness healthchecks 3mo 3mo 3mo
recv
786 Support explicit TLS min version, cipher suites, and curves for istio-csr
4mo 1mo 4mo
pr-unreviewed
recv
687 Dependency Dashboard 9mo 1h 9mo
recv
501 Error logs not very helpful
2
2y 2y 2y
recv
431 istio-csr pod healthz check fails for long time in v0.11.0 and v0.12.0 2y 2y 2y
recv
recv-q
287 Getting Readiness probe failed when using cert-manager-istio-csr 2y 2y 2y
author-last
recv
recv-q
similar
283 Document / improve that sometimes the issuer needs to set `ca.crt`
2y 2y
244 Populate Subject Fields in Certificate
2y 2y 2y
recv
223 False positive warnings from trivy and dependabot
7
2y 2y
153 It is possible to have several CAs within the same cluster.
3
4y 2y 3y
commented
send
137 Documentation on rotating the root certificate
3
4y 1y 4y
recv
recv-q
130 Document best-practices for minimal vault role configuration for istio-csr 4y 2y 4y
recv
recv-q
84 csr readiness probe failed, istio ingress pod also failed
2
5y 2y 5y
support
recv
recv-q
similar
176 certificateDuration is not used for the Istio CSR generated certificate requests
4y 1y 4y
pr-closed
recv
recv-q
113 Integrating with istio helm chart installs
15
4y 2y 4y
recv
recv-q
803 Request to build images for main
2
7mo 5mo 5mo
commented
member-last
send
761 Dependency Dashboard 9mo 1h 9mo
recv
667 Cannot create secret cert-manager-approver-policy-tls 1y 3mo 4mo
commented
send
782 Ensuring approver-policy is ready to accept CRDs after install 8mo 7mo
good first issue
pr-unreviewed
similar
288 Feature: Take control of approval for the whole cluster
2
2y 2y 2y
commented
member-last
216 Simplify configuration by creating RBAC by default
2
3y 1y 1y
help wanted
commented
contributor-last
pr-merged
pr-unreviewed
recv-q
send
203 Improve CRD fields for specifying key requirements
3
3y 2y 2y
commented
member-last
send
169 Webhook Custom CA 3y 1y 1y
help wanted
commented
contributor-last
recv-q
send
466 Document How to Configure Common Scenarios 2y 2y 2y
recv
452 CRDs in the Release files
3
2y 2y 2y
recv
869 [Feature Request] Support Annotations in Approval Policies 5mo 5mo 5mo
author-last
commented
pr-reviewed-with-comment
recv
recv-q
394 Limit number of SANs by policy
2y 2y 2y
commented
member-last
send
1090 Feature Request: Make webhook TLS curve preferences configurable 7d 7d 7d
kind/feature
contributor-last
recv
1048 Feature request: Support multiple trust namespaces and introduce a namespaced Bundle CRD 6wk 6wk 6wk
recv
886 Allow creating `ClusterRole` aggregations
6mo 3wk 6mo
kind/feature
lifecycle/stale
contributor-last
pr-merged
recv
848 Request for cryptographic mechanisms used in cert-manager-trust-manager 7mo 7wk 7mo
lifecycle/stale
contributor-last
recv
841 Does trust-manager require cluster level permissions to read secrets?
7mo 5mo 5mo
commented
member-last
send
1098 Feature Request: Opt-in mutating webhook to inject trust bundles into Pods via annotations 17h 16h 17h
kind/feature
recv
805 Dependency Dashboard 9mo 1h 9mo
recv
800 When creating a trust bundle with additionalFormats/pkcs12, no pkcs12 is produced
9mo 6wk 6mo
commented
contributor-last
pr-merged
send
778 Add option to use a specific issuer in the helm chart 10mo 7wk 10mo
lifecycle/rotten
contributor-last
recv
837 Ensuring trust-manager is ready to accept CRDs after install 8mo 1mo
good first issue
lifecycle/stale
contributor-last
pr-closed
pr-unreviewed
similar
750 Feat: Emit Events on the controller Pod instead of cluster-scoped Bundle 11mo 2mo 11mo
lifecycle/rotten
commented
contributor-last
recv
742 Add option to disable webhook in Helm chart
1y 3mo 1y
kind/feature
author-last
commented
pr-closed
recv
741 Using an Image Volume to deploy certifiats
1y 2mo 1y
lifecycle/rotten
commented
contributor-last
send
592 Feature: ClusterTrustBundle as Sources
1y 2mo 2mo
assigned
assignee-updated
commented
member-last
send
similar
761 Feat: Add a namespaced trust bundle CRD alongside the cluster-scoped Bundle 11mo 3mo 3mo
commented
member-last
send
591 Feature: ClusterTrustBundle as Target
13
1y 14d 10mo
lifecycle/rotten
commented
pr-merged
send
similar
301 Add support for kubectl installation
2y 2y 2y
lifecycle/frozen
author-last
commented
open-milestone
recv
recv-q
similar
560 Support rotated certificate sources
41
2y 2mo 1y
lifecycle/stale
commented
contributor-last
pr-reviewed-with-comment
recv
recv-q
similar
588 Add ability to monitor validity period for CAs in bundle
5
1y 6mo 7mo
kind/feature
help wanted
assigned
assignee-updated
commented
pr-new-commits
send
243 More flexible and better organized target specification in API
5
2y 8mo 10mo
lifecycle/frozen
commented
pr-merged
205 Allow to select multiple "trust" namespaces
50
2y 4mo 1y
commented
send
142 expose bundles CRD as release artifact
2
12
3y 1mo 1y
help wanted
lifecycle/rotten
commented
contributor-last
pr-unreviewed
recv
recv-q
131 Feature: per namespace trust bundle
9
3y 11mo 1y
lifecycle/frozen
commented
send
242 New version of Bundle API
2
4
2y 2mo 2y
lifecycle/frozen
commented
pr-closed
pr-merged
99 Allow removing Bundles whilst keeping the synced CA certs
5
3y 1y 1y
lifecycle/frozen
commented
member-last
pr-unreviewed
60 overriding trusted namespace
10
18
3y 6mo 1y
commented
recv-q
send
58 Support injection pem into an existing configmap
8
4y 1y 1y
priority/important-longterm
lifecycle/frozen
assigned
assignee-updated
commented
member-last
pr-closed
pr-merged
pr-unreviewed
send
39 Don't sync targets to all namespaces by default
8
4y 1y 1y
lifecycle/frozen
commented
member-last
open-milestone
pr-merged
send
297 Allow all resources to be namespaced
6
2y 2mo 11mo
lifecycle/rotten
priority/backlog
commented
send
245 Split Bundle controller into multiple controllers
2y 2y 2y
lifecycle/frozen
commented
member-last
pr-merged
send
1088 Automate trust package version suffix bumps when the nightly security scan fails 8d 8d
1068 support wildcards in the namespaceselector matchexpressions 3wk 3wk 3wk
recv
63 nit: Rename "Bundle" to "ClusterBundle"
19
3y 1y 1y
lifecycle/frozen
commented
member-last
open-milestone
pr-merged
send
362 Dependency Dashboard 9mo 1h 9mo
recv
279 Persisting identifiers for retry calls to Sign() 1y 7mo 7mo
commented
member-last
send
231 ### Question about Configuring Retries in cert-manager 1y 7mo 7mo
commented
member-last
send
204 clarify SetCAOnCertificateRequest deprecation status 2y 1y 1y
commented
member-last
send
507 Denied-only CertificateRequests do not get a terminal Ready condition 17d 17d 17d
kind/bug
pr-unreviewed
recv
613 Support POD_HOSTNAME as a variable 5mo 5mo 5mo
recv
636 Cert fails to issue, but main container starts anyway 4mo 4mo 4mo
recv
530 Dependency Dashboard 9mo 1h 9mo
recv
521 RFC: Cert-Manager CSI Driver as Secret Store Provider
9mo 9mo 9mo
recv
385 Helm Install of cert-manager-csi-driver Fails on Minikube with /dev/bus/usb Errors 1y 1y 1y
author-last
recv
383 [Feature Request] Adding attributes that available in Certificate CRD to CSI Driver
6
1y 1y 1y
recv
353 mismatch between the key and the certificate signature algorithm
2y 2y 2y
recv
267 Does cert-manager-csi-driver support AWS EKS with AWS Fargate nodes? 2y 2y 2y
recv
264 Certificate renewal doesn't change file 'modified date'
2y 2y 2y
recv
256 Broken comma-separated splitting logic 2y 2y
583 Security Posture improvements 6mo 2mo 2mo
commented
member-last
pr-unreviewed
send
241 Missing cert-manager.io/revision-history-limit volume attributes for CSI-Driver
6
2y 2y 2y
recv
171 E2E Test Cleanup 2y 3mo 2y
good first issue
commented
recv-q
130 JKS support
6
3y 2y 3y
recv
recv-q
45 Unable to mount and read only file error
5
5y 2y 2y
priority/awaiting-more-evidence
commented
send
17 ability to specify pod IP in volume attributes
8
6y 2y 6y
commented
recv
recv-q
41 The default `csiDataDir` value might collide with csi-driver
3y 11mo
contributor-last
pr-merged
recv-q
132 Investigate test timeouts 2y 2y
priority/backlog
129 Increase e2e test timeouts 2y 2y
priority/important-longterm
411 Dependency Dashboard
9mo 1h 9mo
pr-merged
recv
204 Support for creating certificate for wildcard route
1y 9mo 1y
recv
similar
58 certificate cannot be renewed, error message: "key does not match certificate"
4
2y 2y 2y
recv
recv-q
395 Request v0.9.1 release to address Go stdlib CVEs 2mo 2mo 2mo
recv
56 Support for destinationCaCertificate / Reencrypt Routes
3
2y 2y 2y
recv
similar
54 Same certificate in path based Routes
4
2y 2y 2y
pr-closed
recv
295 Dependency Dashboard 9mo 1h 9mo
recv
306 [FEATURE]Enable setting private key encoding via annotation 8mo 8mo 8mo
kind/feature
author-last
pr-reviewed-with-comment
recv
174 Standby Replicas without lease use lots of CPU 1y 1y 1y
recv
116 Release static manifests (no helm) for v0.6.0-alpha.0+
2
2y 2y 2y
recv
38 Route with cert-manager annotations is not created
4
3y 1y 2y
commented
send
70 OLM deployment with ArgoCD is OutOfSync
4y 4y 4y
commented
send
17 Operator prevents passing extraArgs helm value
7
6y 3y 6y
recv
recv-q
46 Cert-manager operator fails to issue certificates 4y 4y 4y
recv
22 Customize the deployment of cert-manager installed via OLM
5
6
5y 2y 4y
commented
recv
recv-q
3 Restrict operator RBAC permissions
6y 2y 6y
priority/backlog
pr-merged
recv
144 Dependency Dashboard 9mo 1h 9mo
recv
74 Consistency issues due to the use of mount binds 2y 4mo 2y
commented
recv
recv-q
40 Optional auto rotating/renewing certificates 3y 2y 3y
contributor-last
recv
recv-q
33 Create e2e test to validate CertificateRequest garbage collection 4y 2y 2y
priority/backlog
assigned
commented
member-last
send
234 Proposal: distinguish gate-pending from issuance-error in the renewal backoff loop
3mo 3mo 3mo
commented
member-last
pr-merged
send
15 Allow data-root to be an absolute path 5y 3y
kind/bug
triage/needs-information
contributor-last
pr-reviewed-with-comment
100 Dependency Dashboard 9mo 1h 9mo
recv
63 Is it possible to only create Issuer and remove the CluserIssuer 1y 1y 1y
recv
62 Limit the controller-manager to access secrets only from specific namespace 1y 1y 1y
recv
56 Struggling to get controller running in local KIND cluster
2y 1y 1y
commented
member-last
send
122 asdf cmctl installer issues
2
2y 2y 2y
author-last
commented
recv
83 As cmctl user, I want to use different kubectl context on command line ( --context='kubectl-context-abc' )
5
2y 2y 2y
priority/important-longterm
recv
361 Dependency Dashboard 9mo 1h 9mo
recv
127 cmctl version reports only the old CRD version if I upgrade cert-manager without including the CRDs 2y 2y
priority/important-soon
65 Dependency Dashboard 9mo 1d 9mo
recv
59 Process regarding worrying emails sent to the maintainers mailing list
1y 1y 1y
commented
member-last
81 Configuring Peribolos for Github org management 8y 2y 2y
priority/backlog
commented
member-last
send
1125 Dependency Dashboard 9mo 6d 9mo
recv
594 Document infra image bumps and versioning 4y 2y 4y
priority/backlog
recv
1181 PR history may show revived ProwJob attempts as duplicate build IDs
3mo 3mo
pr-merged
690 Clean up Presets
4y 2y 4y
priority/backlog
pr-merged
recv
1226 Restore pre-merge Venafi coverage using a vendor-supplied verified fake 4wk 4wk
451 Re-enable testing with specific kubernetes versions in subprojects 10mo 10mo 10mo
cybr
commented
member-last
send
728 kube-api-linter module: ship a shared default KAL config 6d 6d
202 Makefile Modules, Go Versions and Vendoring
2y 19d 19d
commented
member-last
pr-merged
send
3 Migrating all cert-manager projects to "Makefile modules" 2y 9mo 1y
priority/backlog
commented
member-last
295 `make generate-golangci-lint-config` clobbers local exclusions added to the local config. 1y 1y
154 Publish SBOMs 2y 2y 2y
kind/feature
good first issue
commented
member-last
pr-reviewed-with-comment
send
98 Document new release process for all repos 2y 2y
priority/important-longterm
assigned
711 tools: no eviction of superseded Go-toolchain-keyed binaries in the download cache 19d 19d
487 Dependency Dashboard
9mo 1d 9mo
pr-closed
recv
263 helm-tool help should be more helpful 3mo 3mo 3mo
recv
202 Dependency Dashboard 9mo 1d 9mo
recv
26 helm-tool inject adds trailing white space to the generated markdown 2y 2y
kind/bug
25 helm-tool inject sometimes omits the context (prefix) of commented out values in the generated markdown 2y 2y
kind/bug
contributor-last
63 CNCF-paid GitHub Actions runners 10mo 9mo 9mo
commented
member-last
62 Lazy vote: Enhancing the triaging process 10mo 10mo
60 Lazy vote: Zoom for standup meetings to be able to add the standups to the LFX calendar
10mo 9mo 9mo
commented
member-last
43 Allow non-Venafi employee maintainers full release capabilities
3
2y 9mo 9mo
priority/backlog
assigned
assignee-updated
commented
member-last
64 Open Standup: Updating an event didn't send new invitations to already registered people
9mo 9mo 9mo
commented
member-last
send
35 Post-Graduation Suggestion Tracker
2y 2y 2y
commented
member-last
pr-merged
92 Dependency Dashboard 9mo 1h 9mo
recv
80 How to deal with K8s timelimit in 30s ? 2y 2y 2y
recv
72 readyz and healthz api 2y 2y 2y
recv
46 Code reference a pull request to be merged, but the pull request was closed by a robot 3y 4wk 4wk
commented
member-last
send
38 Set repository to be a GitHub template repository
4y 2y 4y
priority/important-longterm
recv
37 Add logging example
4y 2y 4y
pr-closed
recv
3 Make unit testing easier/make examples work
7y 2y 4y
priority/important-longterm
commented
member-last
pr-closed
send
2 Set up basic e2e test that deploys the webhook and ensures we can POST a challenge
7y 11mo
contributor-last
pr-closed
recv-q
81 How to enable leader election in the webhook? 2y 2y 2y
recv
74 Why cert-manager looks for a CNAME record instead of a TXT record? 2y 2y 2y
recv
27 failed with: OpenAPI spec does not exist
2
6
5y 2y 2y
priority/critical-urgent
commented
pr-closed
pr-unreviewed
send
24 Dependency Dashboard 9mo 5d 9mo
recv
8 Find solution for automatically disabled GitHub Actions 2y 2y
22 Dependency Dashboard 9mo 1d 9mo
recv
18 Feature: Git bundles? 2y 2y
7 Dependency Dashboard 9mo 6d 9mo
recv
197 Kubectl One-line Installation Support 2y 2y 2y
commented
member-last
send
similar
500 Feature Request: Support for Failover / Secondary CA Pool in GoogleCASIssuer 4mo 4mo 4mo
recv
487 Helm chart `image` named template conflicts with cert-manager 1.20.x
2
4mo 4mo 4mo
commented
pr-closed
recv-q
send
102 certificate renewal does not work in due to auth issue to privatecaapi end point 3y 2y 3y
recv
53 Support crlDistributionPoints & ocspServers 5y 4y 5y
triage/support
commented
send
similar
133 Allow to use a custom Service Account
5
2y 2y 2y
pr-unreviewed
recv
485 [Feature Request] Propagate Kubernetes Metadata to Google Cloud CAS Labels 4mo 4mo 4mo
pr-reviewed-with-comment
recv
375 Dependency Dashboard
9mo 1h 9mo
pr-merged
recv
162 Issue: Broken config when using commonLabels 2y 2y 2y
recv
148 Certificate chain is not split correctly
5
2y 2y 2y
author-last
pr-reviewed-with-comment
recv
recv-q
28 Certificate revocation from CAS Console 5y 5y 5y
triage/support
commented
member-last
send
similar
Triage Party v1.4.0