jupyter / jupyter/security

Determine the council in charge of each repo

Open
#132 2 comments 1 reaction 0 assignees View on GitHub
Dominant language
Jupyter Notebook
Stars
27
Forks
12
Avg merge
3d 5h
Merged PRs (30d)
3

Description

We have a lot of repos in Jupyter, spread across many organizations. We recently discussed in the security council making it clear which council had authority over which repos. The council is then a point of contact for the repo, can make decisions about the current status of the repo (e.g., archived), can act as a security point of contact, etc.

- [x] Make a [list of orgs and repos](https://docs.google.com/spreadsheets/d/1HghiK38YS5UHPBAps8qJrjtuIqmaDxJSyAS5dCxaZts/edit?gid=0#gid=0) in the Jupyter enterprise org
- [x] Assign "obvious" owners to the orgs that fall under one council
- [ ] [Assign provisional owners](https://docs.google.com/spreadsheets/d/1HghiK38YS5UHPBAps8qJrjtuIqmaDxJSyAS5dCxaZts/edit?gid=0#gid=0) to repos in https://github.com/ipython and https://github.com/jupyter (these historical orgs have a mix of repos owned by different councils)
- [ ] Communicate with the Jupyter community about the new metadata. At least an email to the Union of Councils, and perhaps a blog post?
- [ ] Have a public comment period.
- [x] Create an [enterprise-level repo custom property](https://github.com/enterprises/jupyter/settings/custom-properties) to assign a council to a repo
- [x] Probably single-value select, listing possible councils/committees?
- [ ] Document the values and the contact info and/or public website for each council
- [ ] The property should either allow null/undefined or have an "unknown" value
- [ ] Assign provisional councils via the custom property (probably many will have the null value?)
- [ ] Regularly run a report to find any repo that does not have a council
- [ ] Determine owners for all repos that don't have councils
- [ ] Once we assign every repo, set up alert of some kind for repos that don't have a council (or if possible, enforce repos to have a valid council)

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the linked spreadsheet and the Jupyter enterprise custom-properties settings to review the existing repo list, council values, and completed assignments. Work through the unchecked checklist items, including provisional ownership, documentation, community comment, reporting, and alerts. Done means every repository has a documented council or an explicit unknown value, with a way to find unassigned repositories.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
documentation, tooling
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.