Implement an Activity Policy
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 25/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Da chiarire
- Stato di attività
- Ferma
- Stack tecnologico
- github
- Ambito
- authorization, security
Direzione di ricerca
Inizia esaminando i segnali di attività proposti di GitHub e i limiti della GitHub API, quindi analizza come viene attualmente gestita l’appartenenza all’organizzazione nel repository nodejs/admin. L’issue richiede una policy definita e un ambito di implementazione stabilito prima che il lavoro possa iniziare; sarebbe considerata completata quando includesse un registro verificabile delle decisioni relative all’appartenenza e un processo definito per il reinserimento.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
I'd like to recommend that we introduce an Activity Policy for organization membership to reduce the manual workload of maintaining organization membership and attempt to reduce the surface area for potential issues caused by escalated privileges.
I think we can probably be incredibly lenient in what we consider "activity". I'd consider the following "activity", in the nodejs, pkgjs, and nodejs-private orgs:
- Creating an Issue, PR, or Discussion (ex.
org:nodejs author:bnb created:>2021-01-01) - Commenting on an Issue, PR, or Discussion (ex.
org:nodejs commenter:bnb created:>2021-01-01) - Reviewing a PR (ex
org:nodejs reviewed-by:bnb created:>2021-01-01)
I would also include "reacting to an Issue, PR, or Discussion" but it doesn't seem like GitHub has an API that would surface that information. If people think of more things to check programmatically that could be added, I'm wholly onboard with that. I believe our goal should be to consume as many signals as possible, and given that we've consistently decided to centralize on GitHub I think using every available signal is a reasonable way to parse "has this person engaged with the project".
In terms of "what is the scope and approach":
- I'd recommend checking for checking the past year. I don't know of a point in history where an "active" member of the project didn't engage in some way in GitHub at one point or another within the previous 365 days.
- I'd recommend this be instant rather than moving to a temporary hold group before being released. In CommComm I pretty consistently noticed a pattern where when asked people would say yes but not return, creating an artificial inflation of the number of members despite a majority being in this limbo state.
- I'd recommend committing "decisions" in a repo, so we have an easy log that we can audit.
- This could include a snapshot of their membership, allowing us to easily reinstate that.
- I'd recommend that we take a similar approach to how some groups have implemented Emeritus, where a simple request to be re-added (perhaps after some period of renewed activity, like a week or a month?) is all that's required. Perhaps this could also be automatic.
Would love to hear thoughts on this.
- Lingua principale
- JavaScript
- Stelle
- 202
- Fork
- 183
- Merge medio
- 13g 12h
- PR unite (30g)
- 2
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di nodejs/admin
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
-
tsc-agenda
Difficoltà 5/5 Più di una settimana Idoneità per principianti 30/100
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 30/100
Tutte le issue di nodejs/admin
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
-
area-deployment area-integrations triage:bot-seen
Difficoltà 2/5 Mezza giornata Idoneità per principianti 86/100
-
Issue-Bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
sugarlabs/musicblocks#8924 ·
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
ArduPilot/ardupilot_wiki#8088 ·
-
[BUG] createTool tools cannot be registered with Mastra when exactOptionalPropertyTypes is enabled Apertacustomer-eng status: needs triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100