Skip to content

[repo-status] Daily Status Report – June 6, 2026 #13364

Description

@github-actions

🌟 Apache CloudStack — Daily Status Report

Date: June 6, 2026


🚀 Recent Releases

ReleaseTypeDate
4.22.1.0 (LTS)MaintenanceMay 26, 2026
4.22.0.1 (LTS Security)Security (7 CVEs fixed)May 8, 2026
4.20.3.0 (LTS)MaintenanceApr 17, 2026

The security release fixed critical CVEs including unauthenticated command injection in direct download templates and unauthorized cross-tenant access in the Proxmox extension. Great job, security team! 🔐


📬 Active Pull Requests

🔥 Hot PRs (updated today)

#TitleAuthorStatus
#13363Drain per-host reservation when VM starts on different host@Kukuninneeds review
#13361KVM: apply rbd_default_data_pool for volumes from templates@bhouse-nexthopneeds review
#13022NPE fix in listProjectRoles for removed project@Tonitzppneeds review
#12991Backup: Veeam KVM integration@shwstpprin testing
#12617CLVM enhancements and fixes@Pearl1594in testing

🌱 Major Features in Progress

#FeatureAuthor
#12711🔑 Key Management Service (KMS)@vishesh92
#13032🌐 Network Extension: Orchestrate external network devices@weizhouapache
#13033🔐 Add Keycloak OAuth provider@tazouxme
#13236📊 Quota resource statement API@winterhazel
#12874Cross-zone template registration for Edge Zones@vishesh92

✅ Recently Merged

  • #13320 — Stop role from auto-changing on manual account creation (June 3)
  • #13210 — Convert snapshot command timeouts (June 1)
  • #12053 — WebSocket server framework + logs web session (June 2)
  • #11814 — Extensions: sync & download functionalities (June 2)

🐛 Issues Spotlight

🔒 Security Reports (needs triage)

A batch of 9 security issues was filed by @YLChen-007 on June 5 flagging potential credential/password exposure in logs and exception traces across several components (KVM, OVM3, Baremetal, CIFS, SSH). These deserve prompt attention!

  • #13311 — ApiServlet logs duplicate sensitive query params
  • #13308 — Plaintext password exposure in OVM3 logs
  • #13309 — Script.java command sanitization leak
  • #13297#13306 — Multiple credential exposure issues

🐞 Other Recent Issues

  • #13358 — UI: VNF NIC mapping network dropdown always disabled (PR fix ready: #13359)
  • #13357 — Snapshot revert of ROOT encrypted volume makes VM non-bootable
  • #13355network_rate column type too small (needs DB migration)
  • #13313 — Show VM name in backup events

📊 Project Health Snapshot

AreaActivity
🖥️ KVMActive: CLVM, RBD, Veeam backup, VM migration fixes
🌐 NetworkingNetwork Extension framework, Keycloak OAuth, VNF UI fixes
💾 StorageKMS feature, read-only storage guard, physical size fix
🧰 CI/CDPre-commit workflow improvements by @jbampton
📦 QuotaQuota balance refactor merged; resource statement API incoming
🔐 SecurityCredential leak issues need triage — 9 open reports

🎯 Recommended Next Steps for Maintainers

  1. 🚨 Triage the credential exposure issues from @YLChen-007 — assign severity and owners
  2. 👀 Review#13363 (host reservation drain) and #13361 (RBD pool) — both look well-scoped and ready
  3. 🧪 Help test#12617 (CLVM) and #12991 (Veeam backup) which are awaiting validation
  4. 🔑 Advance#12711 (KMS) — a high-impact feature that would benefit from more review bandwidth
  5. 🗂️ Check#13355 — the network_rate type change needs a DB migration and careful planning

💪 The community is buzzing with activity! A huge shoutout to everyone contributing features, fixes, and reviews. Every PR merged and issue triaged makes CloudStack better for everyone!

Generated automatically on 2026-06-06

Generated by Repo Status · sonnet46 689.8K ·

Add this agentic workflows to your repo

To install this agentic workflow, run

gh aw add githubnext/agentics/workflows/repo-status.md@main

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions