I sat down recently and pulled every merged pull request I have authored on GitHub. What started as a simple list turned into a proper audit once I began re-reading each diff. This page is the cleaned up result.
The rules I set were simple. Only pull requests merged into other people’s projects make this list. My own repos and organisations stay out; that work already lives on the projects page. Trivial edits, README formatting, self-listings, link and schedule updates, got dropped. Nobody is served by padding a list like that.
What remains is 66 merged pull requests across 29 projects, between 2013 and 2026. I have not presented them as a flat list because the entries are not equal. A typo fix in Metasploit is still a typo fix. The boxes run in the order I would walk someone through them: the highlights first, with the null community platform work included there, then the Android security work, then the optimisation thread that comes from my sysadmin background.
For the record: 39 of these pull requests still have measurable diffs on GitHub, +1,256 and −1,916 lines across 129 files. The remaining 27 are older merges or squash merges where GitHub no longer serves a diff, so I have described those in words.
Highlights

I run a personal fork of this project and upstream proven features from it (see forks below).
Hardware detection upstreamed: the hardware tab now surfaces Intel and Metal device details. Built and proven in my fork first.
AI/LLM inference is a research area I have recently moved into. Both changes are performance work on the SYCL (Intel GPU) backend, merged September 2026.
Two performance PRs on the SYCL (Intel GPU) backend, merged days apart in September 2026: coalesced softmax memory loads, then extended GLU, rms_norm and ssm_conv fusions for faster token generation. First of a planned series.
null is India’s open security community; I helped establish its Bhopal chapter and have been active in the community for years. This is the platform that runs null.co.in. The work here dates to 2020–2024.
Eleven PRs from my active null years: menu and landing-page work, a persistent event-listing sort bug, three rounds of CI runtime and dependency upgrades, and the null.community domain migration.
Started with one vulnerable npm dependency in the build chain; ended as a three-PR security cleanup.
A three-PR security cleanup: replaced a vulnerable favicon-generator npm plugin (+112/−1389), added a CI build workflow right after my swap broke the build, then dependency housekeeping.
Linux enumeration and privilege escalation is the day job; this batch brought the tool’s checks up to date with LXC, SELinux and loaded-module detection.
One substantial batch PR that expanded the tool’s check catalogue: LXC container detection, adm group listing, SELinux presence, loaded kernel modules, plus cat|grep optimisations (+371/−260 across 3 files).
A big fun community project. A bunch of us were driving it at the time; these are my code fixes from that sprint.
My fixes from the community sprint: modernised the CLI from optparse to argparse and fixed master-script detection, restored the website’s CNAME, and stabilised a round of breaking changes.
Found while building my Vulnerable Docker VM: PHP Meterpreter payloads failed against Suhosin-hardened hosts. I documented the full investigation in Fun with PHP Meterpreter and fixed it across both the framework and the payloads repos.
The staged-payload side of the Suhosin fix: PHP Meterpreter would not run against hardened hosts, and earlier patches only ever covered non-staged payloads.
Companion fix to the framework change above: same investigation, same blog post.
The payloads half of the same fix: replaced the deprecated create_function() call so the PHP webshell payload works on modern PHP, with or without Suhosin.
Android


<pre> tags so the cert info in reports keeps its spacing.
Optimization




And many more such contributions as can be seen from here: the full list of pull requests I have created on GitHub.
