Node.js Coverity project maintainers

Offen
#925 2 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Anfängerfreundlichkeit
20/100
Issue-Typ
Feature
Klarheit
Muss geklärt werden
Aktivitätsstatus
Veraltet
Bereich
devops, security

Rechercherichtung

Beginne mit doc/contributing/offboarding.md sowie dem verknüpften Coverity-Projekt und CI-Scan-Job, um den aktuellen Entfernungsprozess zu verstehen. Prüfe die beiden vorhandenen Kommentare und stelle fest, ob im Issue eine endgültige Entscheidung darüber getroffen wurde, welche Gruppe die Coverity-Mitgliedschaft verwalten soll; abgeschlossen bedeutet eine vereinbarte Richtlinie zur Zuständigkeit und entsprechende Prozessaktualisierungen.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

Currently the offboarding process for nodejs/node collaborators has this:
https://github.com/nodejs/node/blob/e92446536ed4e268c9eef6ae6f911e384c98eecf/doc/contributing/offboarding.md?plain=1#L20-L23

  • Open an issue in the nodejs/build repository titled Remove Collaborator from Coverity asking that the collaborator be removed from the Node.js coverity project if they had access.

This is for Node.js project we have with the static analysis Coverity tool at: https://scan.coverity.com/projects/node-js

There are currently five people with Maintainer/Owner role -- three from the Build WG, one from the TSC and one former Build WG/TSC.

Historically Build have had a maintainer role to be able to download the build tool from Coverity that is run on the CI to upload scans to Coverity.

I think the Coverity project should have other maintainers -- either the @nodejs/tsc or a subset such as the @nodejs/security-wg (since the items flagged by the tool are potentially exploitable) and am opening this issue to discuss if we want to expand/formalize who can manage membership of this account.

Vorherrschende Sprache
JavaScript
Sterne
202
Forks
183
Ø Merge
2 Min.
Gemergte PRs (30 T.)
1

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus nodejs/admin

Alle Issues in nodejs/admin

Ähnliche Issues

Weitere Issues zu JavaScript

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.