cisagov / cisagov/development-guide

Codify policy for email address and commit signing

Open
#36 0 comments 0 reactions 0 assignees View on GitHub
documentation
Dominant language
Python
Stars
282
Forks
72
PR merge metrics
No merged PRs in 30d

Description

We have a number of preferences for how the core dev team members use GitHub. This issue is to determine how we want to decide and codify these best-practices so they're well-documented and available.

Should we require dev team members to:
- Commit under their CISA or Trio email address?
- Require this to be publicly available, or just to specify setting up the no-reply address for commit signing?
- Sign commits with a GPG key?
- Possibly already codified in PR #35 with the inclusion of the [FISMA-Ready Github guide](https://github.com/fisma-ready/github), which we may want to fork and modify
- Additional resource on [setting up openPGP](https://blog.eleven-labs.com/en/openpgp-almost-perfect-key-pair-part-1/)

Note: Specifically, this policy is for core dev team only, not external contributors, and should be written in a way not to discourage anyone from participating and using our GitHub resources

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.