Skip to content

Draft formal policy on what Core Committers are allowed to do and not do #263

@maxime-rainville

Description

@maxime-rainville

CISO has asked us to nail down this part of the process a bit.

Related (possible duplicate)

Acceptance criteria

  • A formal core committer policy is drafted and covers what action core committer are allowed to perform. use existing documentation per discussion in comments below
  • Core committers are required to attest that they have read the policy and agreed to it.
  • Core committers are required to re-read the policy on a regular basis.
  • The access to the security repo process is folded back into this policy.
  • Policy is short enough not to dissuade core committers from reading.
  • CISO is satisfied that the policy meet our ISO27K obligations.
  • Silverstripe has a defined process for recording and storing proof that core committers have read the policy.

Notes

  • We'll have a chat with the core committers about having a formal policy for removing people off if they haven't done something in a while.

Draft policy

This is no longer in consideration.

https://docs.google.com/document/d/1aywYhAxj6k6X3G3xuMf7wFWYq6jSftgsjDGEmWOmvTo/edit

This is a draft policy for Core Committers - that word "draft" is important, it's by no means official at this stage.

Please read through it and suggest any changes you think are appropriate (more detail, additional sections, ask for clarification, etc).

My primary concern while writing this has been the principle of least privilege - not giving admin access to everyone when nobody is really using it, but still keeping access to the wealth of knowledge of the core committers and doing what we can to ensure the community at large has some amount of say in the future of Silverstripe CMS

PRs

The current thinking is that once a year, Core Committers should submit a PR updating the below and update the date by their name, indicating that they have read the linked pages.
The product owner will be responsible for sending an annual reminder.

Metadata

Metadata

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions