Comments (4)
the releasers to more specific organizations
Releasers are per organization already!
or even repositories/packages?
That would help you, with eslint-mdx
. True. A couple of other people also request similar things.
In my experience, typically, those people aren’t very active for very long. You’re an exception here!
With 500+ repos, it is very hard to get security right. I strongly believe that the best way to manage security, is as few people and tools as possible that have access.
Over the years, many tools we have used have had security problems: Coveralls for example. GitHub a couple of times. These services and many more leaked tokens.
This didn’t affect really us, because we don’t give tools publish access.
Having different people with different access per repo makes it hard to understand who does what: who has credentials? Who is responsible?
I also hope that working on orgs instead of repos brings a different level of commitment: that maintainers care for the whole group of things rather than one project.
I’d love to have more people on different organizations, solving issues, fixing PRs, cutting releases!
from collective.
Added. Within the next 24 hours, tooling will add you with the correct permissions to each of the above orgs.
On releasing, see: https://github.com/unifiedjs/collective/blob/main/members.md#request-to-become-a-releaser.
Note that releasers have a lot of rights. On GitHub. On npm. (See: https://github.com/unifiedjs/collective/blob/main/permissions.md). This group should remain small. I am not sure it is a good idea.
from collective.
OK then, let's just keep it as-is.
Also, are we considering splitting the releasers to more specific organizations or even repositories/packages?
from collective.
I just realized that I want to be a releaser of eslint-mdx
/vscode-mdx
, etc. Should I post a new nomination for myself afterwards or it can just be included here?
cc @wooorm
from collective.
Related Issues (20)
- Nominating @jamesknelson as a member of @mdx-js HOT 2
- Project onboarding process HOT 5
- Nominating @Jarred-Sumner as a member of @mdx-js HOT 2
- Nominating @BarryThePenguin as a member of @remarkjs, @syntax-tree HOT 2
- Triage and maintain roles HOT 1
- Security policy HOT 1
- Nominating @kmck as a member of @remarkjs, @rehypejs, @syntax-tree HOT 2
- Inactive team member review (July) HOT 9
- Nominating @sidharthachatterjee as a member of @mdx-js HOT 4
- Move `unifiedjs/governance` to `unifiedjs/collective` HOT 12
- Add expenses/invoices/fund policy HOT 5
- GitHub sponsors HOT 19
- Add `funding` fields to packages HOT 6
- Nominating @laurieontech as a member of @mdx-js HOT 4
- Nominating @remcohaszing as a contributor of @remarkjs, @rehypejs, @syntax-tree HOT 2
- Bad links on npm - tracking only HOT 2
- Motion to archive "ideas" repos and migrate them to GitHub discussions HOT 2
- Nominating @remcohaszing as a contributor of @unifiedjs, @vfile HOT 3
- Revoke some release permissions in case npm supports package based publish permission token now HOT 5
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from collective.