Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Reduce admin access to openedx repos #129

Open
nedbat opened this issue Sep 20, 2023 · 2 comments
Open

Reduce admin access to openedx repos #129

nedbat opened this issue Sep 20, 2023 · 2 comments
Assignees
Labels
github Changes to how we use GitHub

Comments

@nedbat
Copy link
Contributor

nedbat commented Sep 20, 2023

From Ed Zarecor:

A topic for our open source process group.

We regularly get requests from 2U teams for admin access to repositories. That level of access is problematic. For example, it allows folks to change who has access to a repo, or delete it.

Axim is on the hook for ensuring the CLA is enforced, so this represents risk for us.

I'd like to have a brief statement that we'll share when such requests are made. Here's my proposal:

https://docs.google.com/document/d/1mwDJ-F51s9KqY6ssifBBN9hbpRj-eXvDtphUNQqiULc/edit

In auditing current admin access I was surprised by how many 2U folks have it. 90 folks have admin on at least one repository.

Previously we had discussed the need for BOM to retain access for routine maintenance and emergencies. What would prevent us from reducing admin access to just the BOM teams immediately?

For non emergency changes, we would continue to use issues in the Axim Engineering project.

Looking forward to discussing.

@nedbat nedbat converted this from a draft issue Sep 20, 2023
@nedbat nedbat self-assigned this Sep 20, 2023
@nedbat nedbat added the github Changes to how we use GitHub label Sep 20, 2023
@nedbat
Copy link
Contributor Author

nedbat commented Sep 20, 2023

Just for clarity: "BOM teams" means arch-bom, arbi-bom and fed-bom?

@robrap
Copy link

robrap commented Oct 20, 2023

On a related note, as a member of arch-bom, I had to work across a variety of repos and could not merge in at least two repos due to the following issues:

What are the resolutions for this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
github Changes to how we use GitHub
Projects
Status: Prioritized
Development

No branches or pull requests

2 participants