Open Source Contributions

2026/09/29

I sat down recently and pulled every merged pull request I have authored on GitHub. What started as a simple list turned into a proper audit once I began re-reading each diff. This page is the cleaned up result.

The rules I set were simple. Only pull requests merged into other people’s projects make this list. My own repos and organisations stay out; that work already lives on the projects page. Trivial edits, README formatting, self-listings, link and schedule updates, got dropped. Nobody is served by padding a list like that.

What remains is 66 merged pull requests across 29 projects, between 2013 and 2026. I have not presented them as a flat list because the entries are not equal. A typo fix in Metasploit is still a typo fix. The boxes run in the order I would walk someone through them: the highlights first, with the null community platform work included there, then the Android security work, then the optimisation thread that comes from my sysadmin background.

For the record: 39 of these pull requests still have measurable diffs on GitHub, +1,256 and −1,916 lines across 129 files. The remaining 27 are older merges or squash merges where GitHub no longer serves a diff, so I have described those in words.

Highlights

I run a personal fork of this project and upstream proven features from it (see forks below).

Hardware detection upstreamed: the hardware tab now surfaces Intel and Metal device details. Built and proven in my fork first.

The merged PR →

AI/LLM inference is a research area I have recently moved into. Both changes are performance work on the SYCL (Intel GPU) backend, merged September 2026.

Two performance PRs on the SYCL (Intel GPU) backend, merged days apart in September 2026: coalesced softmax memory loads, then extended GLU, rms_norm and ssm_conv fusions for faster token generation. First of a planned series.

merged PRs →

null is India’s open security community; I helped establish its Bhopal chapter and have been active in the community for years. This is the platform that runs null.co.in. The work here dates to 2020–2024.

Eleven PRs from my active null years: menu and landing-page work, a persistent event-listing sort bug, three rounds of CI runtime and dependency upgrades, and the null.community domain migration.

merged PRs →

Started with one vulnerable npm dependency in the build chain; ended as a three-PR security cleanup.

A three-PR security cleanup: replaced a vulnerable favicon-generator npm plugin (+112/−1389), added a CI build workflow right after my swap broke the build, then dependency housekeeping.

merged PRs →

Linux enumeration and privilege escalation is the day job; this batch brought the tool’s checks up to date with LXC, SELinux and loaded-module detection.

One substantial batch PR that expanded the tool’s check catalogue: LXC container detection, adm group listing, SELinux presence, loaded kernel modules, plus cat|grep optimisations (+371/−260 across 3 files).

The merged PR →

A big fun community project. A bunch of us were driving it at the time; these are my code fixes from that sprint.

My fixes from the community sprint: modernised the CLI from optparse to argparse and fixed master-script detection, restored the website’s CNAME, and stabilised a round of breaking changes.

merged PRs →

Found while building my Vulnerable Docker VM: PHP Meterpreter payloads failed against Suhosin-hardened hosts. I documented the full investigation in Fun with PHP Meterpreter and fixed it across both the framework and the payloads repos.

The staged-payload side of the Suhosin fix: PHP Meterpreter would not run against hardened hosts, and earlier patches only ever covered non-staged payloads.

The merged PR →

Companion fix to the framework change above: same investigation, same blog post.

The payloads half of the same fix: replaced the deprecated create_function() call so the PHP webshell payload works on modern PHP, with or without Suhosin.

The merged PR →
A small change with a wide audience: OKHttp’s CertificatePinner joined the module’s SSL pinning bypass list, tested against OkHttp 2.5.
The merged PR →

Android

Dependency upgrades for Google’s bytecode viewer, taken to the highest versions that still compile cleanly.
The merged PR →
Four documentation-infrastructure fixes from validating my local setup: corrected build instructions, fixed CI link-check failures, aligned local checks with GitHub Actions, and added Visual Studio App Center to the tools reference.
merged PRs →
Added a CLI entry point so the APK verification gem can be driven directly with an APK path.
The merged PR →
Two early contributions to the standard: preface fixes as PR #1 of the repository, and a document-generation fix so tables span the page in the DOCX release.
merged PRs →
Added a Gradle wrapper so the platform builds without a local Gradle install, and removed committed build output.
The merged PR →
Certificate details wrapped in <pre> tags so the cert info in reports keeps its spacing.
The merged PR →

Optimization

Slimmed the pentest Docker image using my own published OVA-size-reduction methodology: shallow clones, no redundant files.
The merged PR →
Documented the non-obvious build steps, then added URL encoding/decoding as a utility.
merged PRs →
Docker build restructure: pinned Python 2.7.15 and kept the .git folder out of the shipped image.
The merged PR →
Reworked the Linux build to ship a desktop icon and menu entry. Took a second attempt and a 16-comment review to land.
The merged PR →
Added the missing configparser dependency and installs stopped breaking.
The merged PR →
Switched the plugin’s JavaScript to HTTPS so the redirect widget stops throwing mixed-content warnings.
The merged PR →
Thirteen cask updates across 2015–2016: security tooling (Tor, Charles Proxy, OWASP ZAP, Hopper Disassembler) plus a long run of Chromium bumps. The Charles fix moved the dependency to native Java after Apple abandoned theirs.
merged PRs →
Five installer and setup fixes from my early-adopter years: correct tool paths on Kali, a path-independent setup script, wget retry limits, and installer reordering so OWTF installs on any distro, not just Kali.
merged PRs →
Disabled rdoc/ri generation during gem install; same result, far less time and disk.
The merged PR →

And many more such contributions as can be seen from here: the full list of pull requests I have created on GitHub.