RFC: New criteria for commit access

I grant access to literally anyone who asks who is able to follow the instructions in the developer policy: effectively, they provide a github user id and some justification. Many people who ask don’t do this the first time around btw.

I don’t attempt to validate the justification for a variety of reasons, including that I’m not willing to set arbitrary bars based on “my judgement” as suggested upthread.

I do think that having an advocate/nominator/sponsor sort of thing would be a good addition to our process, but I’m not going to check to see the sponsor has commit access already :slight_smile:

can’t we just move our release binaries to a different github repo/org?

As I mentioned in my ^^ post, I don’t see how this matters at all. Why is the person who pushes two patches and disappears a supply chain risk? You’re not addressing the observed problems, and you are introducing new ones. In practicality, I don’t think we can achieve security by reducing access from 1500 people to 500 because we can’t vet 500 people either, particularly as they change affiliations and motivations over the years.

This is my objection to the proposal.

-Chris

11 Likes