Otto Kekäläinen <[email protected]> writes: > Below is my initial suggestion for the policy regarding team membership, > followed by justifications:
Thanks for writing this! +1 from me. Commenting only on things I think could be improved: > and to draft the packaging under their own Salsa account. To create a new > git repository in the Go team namespace one needs to either be a Go team > member Is that even true? Doesn't 'dh-make-golang create-salsa-project' use some hard-coded token that creates projects by anyone? That seems like a bug to me, since non-Go-team members are able to create projects but are not allowed to push to them. > 3. To be able to merge and push commits to any Go package git repository > one needs to be a Go team member. Could we make an exception for all DD's? I think any DD is expected to be able to inform themselves of our policies and follow them. Excluding DD's from being a Go team member seems counter-productive to me. If a DD make Go-team crap uploads, we can discuss things. later: I see you already made this exception in 7 -- how about moving 7 up before 3? So DD/DM's reading this will be happy earlier. > 6. If a contributor has not utilized their Go team membership and > participated in Go package maintenance during the development cycle of two > consecutive Debian releases, they will be notified about pending membership > expiration. After inactivity of three consecutive Debian release cycles, Go > team membership can be revoked. I think we could just auto-expire Salsa team membership after one or two years of inactivity. Re-applying should be trivial if a person made earlier contributions. > Justifications: > - Current blind trust makes it too easy for a malicious person to > infiltrate. IMHO any policy that makes it impossible for a malicious person will reject substantial number of non-malicious persons, and we are already short on manpower to be in a position to make over-complicated processes. We'll have to deal with incidents when they happen. /Simon
signature.asc
Description: PGP signature
