nodejs / nodejs/admin

Node.js Coverity project maintainers

Open
#925 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
JavaScript
Stars
202
Forks
183
Avg merge
2m
Merged PRs (30d)
1

Description

Currently the offboarding process for nodejs/node collaborators has this:
https://github.com/nodejs/node/blob/e92446536ed4e268c9eef6ae6f911e384c98eecf/doc/contributing/offboarding.md?plain=1#L20-L23

  • Open an issue in the nodejs/build repository titled Remove Collaborator from Coverity asking that the collaborator be removed from the Node.js coverity project if they had access.

This is for Node.js project we have with the static analysis Coverity tool at: https://scan.coverity.com/projects/node-js

There are currently five people with Maintainer/Owner role -- three from the Build WG, one from the TSC and one former Build WG/TSC.

Historically Build have had a maintainer role to be able to download the build tool from Coverity that is run on the CI to upload scans to Coverity.

I think the Coverity project should have other maintainers -- either the @nodejs/tsc or a subset such as the @nodejs/security-wg (since the items flagged by the tool are potentially exploitable) and am opening this issue to discuss if we want to expand/formalize who can manage membership of this account.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with doc/contributing/offboarding.md and the linked Coverity project and CI scan job to understand the current removal process. Review the two existing comments and determine whether the issue has a settled decision about which group should manage Coverity membership; done means an agreed ownership policy and corresponding process updates.

Written by the indexing model from the issue text.

Assessment

Domain
devops, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.