Node.js Coverity project maintainers

オープン
#925 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
20/100
issue の種類
機能追加
明瞭さ
説明が足りない
活発さ
停滞
領域
devops, security

調査の方向性

doc/contributing/offboarding.md と、リンクされている Coverity プロジェクトおよび CI スキャンジョブから始めて、現在の削除プロセスを理解してください。既存の 2 つのコメントを確認し、Coverity のメンバーシップをどのグループが管理すべきかについて issue で決定が確定しているかどうかを判断してください。完了とは、合意された所有権ポリシーと、それに対応するプロセスの更新があることを意味します。

索引モデルが issue の本文から書いたものです。

説明

Currently the offboarding process for nodejs/node collaborators has this:
https://github.com/nodejs/node/blob/e92446536ed4e268c9eef6ae6f911e384c98eecf/doc/contributing/offboarding.md?plain=1#L20-L23

  • Open an issue in the nodejs/build repository titled Remove Collaborator from Coverity asking that the collaborator be removed from the Node.js coverity project if they had access.

This is for Node.js project we have with the static analysis Coverity tool at: https://scan.coverity.com/projects/node-js

There are currently five people with Maintainer/Owner role -- three from the Build WG, one from the TSC and one former Build WG/TSC.

Historically Build have had a maintainer role to be able to download the build tool from Coverity that is run on the CI to upload scans to Coverity.

I think the Coverity project should have other maintainers -- either the @nodejs/tsc or a subset such as the @nodejs/security-wg (since the items flagged by the tool are potentially exploitable) and am opening this issue to discuss if we want to expand/formalize who can manage membership of this account.

主要言語
JavaScript
スター
202
フォーク
183
平均マージ
2分
マージ済み PR(30日)
1

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

nodejs/admin のほかの issue

nodejs/admin の issue をすべて見る

似ている issue

JavaScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。